Repository profile

cti-skills

Review Skills in Liberty91LTD/cti-skills, with license, maintenance context, and source paths.

Skills
6
Repository stars
11
Identity status
Source-linked

Provenance

Source and identity

Source-linked
Profile type
Repository
Canonical name
cti-skills
Public sources
1
License context
MIT

Source entries

Agent Skills from cti-skills

Repository stars and maintenance signals provide context, but do not automatically become an individual Skill's quality score.

Computed 8511

Liberty91LTD/cti-skills

cti-orchestrator

Use as the default entry point for any CTI request that doesn't name a specific skill. Activates when a user asks to investigate an indicator, profile a threat actor, write an assessment, enrich IOCs, or build detection rules. Routes to the right investigation or analysis skill, then auto-applies rigor skills (source rating, TLP, confidence, likelihood) on the output.

Computed 8411

Liberty91LTD/cti-skills

cti-setup

Use when the user wants to configure API keys for the CTI skills pack, asks "how do I set up keys", "configure VirusTotal", "add my Shodan key", or runs /cti-setup. Walks through API key configuration inside Claude Code without needing to run a shell script. Also handles re-running setup, adding individual keys, and verifying that configured keys work.

Computed 9011

Liberty91LTD/cti-skills

darkweb-collection

Dark web intelligence collection methodology — vendor-first access posture, sourced reference lists for 35+ underground forums and 30+ Telegram channels, OPSEC primer, passive-monitoring strategy, and bundled Python CLIs for onion-indexer search, Telegram channel monitoring, and local keyword matching. Use when the user wants to design or run dark-web collection, build a selector list, pick a vendor, or set up monitoring infrastructure.

Computed 9011

Liberty91LTD/cti-skills

kql-writing

Use when the user asks for a KQL query, a Microsoft Sentinel / Defender / Azure Log Analytics detection or hunt, or wants to translate a finding from `/hash-investigation` / `/malware-analysis` into KQL. Format spec + writing guide.

Computed 8911

Liberty91LTD/cti-skills

lookup-censys

Use when you need deep host + certificate reconnaissance for an IP or need to run a Censys search query. Returns services, TLS certificates, ASN, and location. Free tier is severely limited (250 queries/month) — use sparingly. Retrieval only.

Computed 8911

Liberty91LTD/cti-skills

lookup-opencti

Use when you need to query an OpenCTI instance — is this IOC already known, what entities/reports/campaigns exist for an actor — or push new intel into it — creating indicators/observables, labelling, TLP markings, relationships, or importing a STIX 2.1 bundle. Two-way integration. Commonly invoked by /ip-investigation and friends to check whether an indicator is already in your knowledge base, and by analytical skills that want to publish their findings back to OpenCTI. Reads $OPENCTI_URL and $

Pinned paths

Every entry links to a specific source path and commit when available.

Repository context

Activity, license, and repository-level popularity are shown as context.

Open the source

Inspect the public repository