Source profileQuality 85/100

Liberty91LTD/cti-skills/skills/cti-orchestrator/SKILL.md

cti-orchestrator

Use as the default entry point for any CTI request that doesn't name a specific skill. Activates when a user asks to investigate an indicator, profile a threat actor, write an assessment, enrich IOCs, or build detection rules. Routes to the right investigation or analysis skill, then auto-applies rigor skills (source rating, TLP, confidence, likelihood) on the output.

Source repository stars
11
Declared platforms
0
Static risk flags
0
Last source update
2026-08-04
Source checked
2026-08-04

Decision brief

What it does—and where it fits

You are the default entry point for the cti-skills pack. When a user's request doesn't name a specific skill, activate here. Your job is to:

Best for

    Not for

    • Tasks that require unconfirmed production actions or broad system permissions.
    • Environments where the pinned source and install steps cannot be inspected.

    Compatibility matrix

    Platform support, with evidence labels

    PlatformStatusEvidenceWhat to check
    CodexNot declaredNo explicit evidencePortability before use
    Claude CodeNot declaredNo explicit evidencePortability before use
    CursorNot declaredNo explicit evidencePortability before use
    Gemini CLINot declaredNo explicit evidencePortability before use
    Open the compatibility checker

    Installation

    Inspect first. Install second.

    The source command is displayed only when detected. A safe inspection prompt is always available so your agent can explain every action before execution.

    Source-detected install commandSource
    npx skills add https://github.com/Liberty91LTD/cti-skills --skill "skills/cti-orchestrator"
    Safe inspection promptEditorial

    Inspect the Agent Skill "cti-orchestrator" from https://github.com/Liberty91LTD/cti-skills/blob/97d66b3687ba6d32b316a7df3391beb3e2de88de/skills/cti-orchestrator/SKILL.md at commit 97d66b3687ba6d32b316a7df3391beb3e2de88de. List every install step, command, network request, credential, file read/write, external action, and rollback step. Explain whether it fits my task. Do not install or execute anything until I approve.

    Workflow

    What the source asks the agent to do

    1. 01

      When to activate

      Activate on any of these user intents:

      Activate on any of these user intents:If the request is ambiguous, ask one clarifying question. Don't guess.
    2. 02

      Routing logic

      For investigation-shaped requests:

      For investigation-shaped requests:For analytical or production-shaped requests:
    3. 03

      Auto-rigor pipeline

      After the primary skill(s) complete, apply these rigor skills to the output without asking the user. They're non-negotiable for any intelligence product.

      /source-assessment — assign Admiralty Scale ratings (source reliability A-F, information credibility 1-6) to each piece of collected intelligence. Use the defaultsourcereliability + defaultinformationcredibility declare…/tlp-guide — mark every output with a TLP designation (CLEAR / GREEN / AMBER / AMBER+STRICT / RED). Default to AMBER for investigative findings unless the user specifies otherwise or content is inherently public (OSINT…/confidence-levels — attach a MISP confidence score (0-100) to every analytical judgment. Justify based on source ratings and corroboration.
    4. 04

      PIR awareness

      If data/pirs/active/ exists and contains files, read them first. When the request aligns with an active PIR, note the PIR ID in the output header. When the product satisfies a PIR, update the PIR's lastsatisfied field and suggest refreshing the PIR list.

      If data/pirs/active/ exists and contains files, read them first. When the request aligns with an active PIR, note the PIR ID in the output header. When the product satisfies a PIR, update the PIR's lastsatisfied field a…
    5. 05

      Knowledge cell updates

      After significant new intelligence is collected, consider whether a knowledge cell should be updated:

      IP/domain attributed to a known actor → update that actor's cellNew campaign observed → update the relevant regional or malware-family cellTTP observed in the wild → update the matching threat area (e.g., /ransomware-ecosystem)

    Permission review

    Static risk signals and limitations

    No configured static risk pattern was detected

    This is not proof of safety. Runtime behavior, indirect dependencies, and hidden external systems are outside the static scan.

    Evidence record

    Why each signal appears

    EvidenceSourceComputedTestedEditorial
    SignalValueEvidence typeMeaning
    Quality score85/100ComputedDocumentation, specificity, maintenance, and trust rules
    Repository stars11SourceRepository attention, not individual Skill quality
    Compatibility0 platformsSourceDeclared in the catalog source record
    Usage guideautomated source guideEditorialGenerated or reviewed according to the visible evidence level

    Pinned source

    Provenance and original SKILL.md

    Repository
    Liberty91LTD/cti-skills
    Skill path
    skills/cti-orchestrator/SKILL.md
    Commit
    97d66b3687ba6d32b316a7df3391beb3e2de88de
    License
    MIT
    Collected
    2026-08-04
    Default branch
    main
    View the original SKILL.md

    cti-orchestrator

    You are the default entry point for the cti-skills pack. When a user's request doesn't name a specific skill, activate here. Your job is to:

    1. Classify the request
    2. Invoke the right downstream skill(s)
    3. Auto-apply rigor skills on the result
    4. Return a source-rated, confidence-marked product

    You do NOT query external APIs directly. Compose other skills — especially the lookup-* skills — to do the work.

    When to activate

    Activate on any of these user intents:

    User says something like...Route to
    "Investigate 8.8.8.8" / "check this IP"/ip-investigation
    "What's this domain doing" / "investigate example.com"/domain-investigation
    "Check this hash" / "is d41d8cd98f... malicious"/hash-investigation
    "Scan this URL" / "what does this link do"/url-investigation
    "Profile APT28" / "tell me about this actor"/threat-actor-profiling
    "Track this campaign"/campaign-tracking
    "Analyze this malware sample"/malware-analysis
    "Write a threat assessment on X"/threat-assessment + /writing-assessments + /intelligence-writing
    "Enrich this IOC list"/ioc-enrichment-workflow → appropriate lookup-* skills → /ioc-export
    "Write detection rules for X"/sigma-writing / /yara-writing / /kql-writing
    "Did this IOC hit our environment" / "hunt for X in our Sentinel" / "search our logs for T1059"/lookup-sentinel (exposure sweep / TTP hunt against the org's own workspace)
    "What's the current X landscape"relevant knowledge cell (e.g., /ransomware-ecosystem) + /horizon-scanning
    "Run ACH" / "hypothesis analysis"/ach
    Direct invocation /skill-namebypass this orchestrator, invoke directly

    If the request is ambiguous, ask one clarifying question. Don't guess.

    Routing logic

    For investigation-shaped requests:

    user request
      ↓ classify indicator type (IP / domain / hash / URL / actor / campaign / sample / topic)
      ↓
    invoke the matching investigation or analysis skill
      ↓
    that skill may chain multiple /lookup-<api> skills in parallel
      ↓
    on completion → auto-apply rigor (see next section)
      ↓
    return to user
    

    For analytical or production-shaped requests:

    user request
      ↓ check active PIRs (if present under data/pirs/active/) for priority alignment
      ↓
    invoke the relevant analytical skill(s): /threat-assessment, /ach, /structured-analytic-techniques, /red-team-analysis, /key-assumptions-check, /horizon-scanning
      ↓
    if writing a product: /intelligence-writing, /writing-assessments
      ↓
    apply /quality-control before presenting
      ↓
    auto-apply rigor
      ↓
    return to user
    

    Auto-rigor pipeline

    After the primary skill(s) complete, apply these rigor skills to the output without asking the user. They're non-negotiable for any intelligence product.

    1. /source-assessment — assign Admiralty Scale ratings (source reliability A-F, information credibility 1-6) to each piece of collected intelligence. Use the default_source_reliability + default_information_credibility declared in each lookup skill's frontmatter as starting points; adjust based on content.
    2. /tlp-guide — mark every output with a TLP designation (CLEAR / GREEN / AMBER / AMBER+STRICT / RED). Default to AMBER for investigative findings unless the user specifies otherwise or content is inherently public (OSINT aggregations → CLEAR).
    3. /confidence-levels — attach a MISP confidence score (0-100) to every analytical judgment. Justify based on source ratings and corroboration.
    4. /likelihood-language — use probability-yardstick language for any forward-looking statement ("Remote" / "Unlikely" / "Even Chance" / "Likely" / "Almost Certain" with numeric bands).

    If the user explicitly says "skip rigor" or "just give me the raw data," honor that.

    PIR awareness

    If data/pirs/active/ exists and contains files, read them first. When the request aligns with an active PIR, note the PIR ID in the output header. When the product satisfies a PIR, update the PIR's last_satisfied field and suggest refreshing the PIR list.

    Knowledge cell updates

    After significant new intelligence is collected, consider whether a knowledge cell should be updated:

    • IP/domain attributed to a known actor → update that actor's cell
    • New campaign observed → update the relevant regional or malware-family cell
    • TTP observed in the wild → update the matching threat area (e.g., /ransomware-ecosystem)

    Use /feedback-loops to log the update if non-trivial.

    Lookup catalog

    Authoritative list of /lookup-* skills available in this pack. Keep this list in sync when a new lookup is added (a hook reminds when skills/lookup-*/SKILL.md is touched). When routing an investigation, ensure the downstream skill chains every applicable lookup from this list — don't trust that downstream skill bodies are current.

    SkillIndicator typesDefault AdmiraltyNotes
    /lookup-liberty91ip, domain, hash, url, actor, malware, CVE, occurrencenative AdmiraltyFirst-party — check before spending third-party quota. Deduplicated Threat Events (occurrences with every source, each source's reliability grade, the occurrence's credibility band and verification stage), canonical threat library with ATT&CK TTPs, IOC lookup, alert matches, per-organization relevance. Two-way: also ingests reports and generates intelligence packages (writes need user confirmation). Use the platform's own reliability/credibility rather than a default rating.
    /lookup-virustotalip, domain, hash, urlB2Crowd-sourced AV aggregate; default first call
    /lookup-otxip, domain, hash, urlC3AlienVault community pulses; cheap and unconstrained
    /lookup-abuseipdbipB2Abuse-report history; IP-only
    /lookup-greynoiseipB2Internet-noise classifier; use to short-circuit on benign scanners
    /lookup-shodanip, domainB2Host fingerprint, ports, services, vulns
    /lookup-censysip, cert searchB2Deep host + certificate recon; 250/month free quota — use sparingly
    /lookup-urlscanurl, domainB2Live scan + existing-scan search
    /lookup-reversinglabsip, domain, url, hashA2Spectra Analyze (A1000) — vendor-authoritative classification, MITRE ATT&CK, sandbox, sample fan-out. Use whenever credentials are configured — independent of VT and stronger than crowd AV.
    /lookup-crowdstrikeip, domain, hash, url, actor, reportA2Falcon Intelligence — IOC reputation (malicious confidence, linked actors/malware) AND finished intel: threat-actor profiles, actor search by origin/target, MITRE ATT&CK TTPs, intel reports. Use whenever credentials are configured — the primary vendor feed for actor/report/TTP questions, not just IOC lookups.
    /lookup-mispanyB2Internal correlation against your own MISP catalogue
    /lookup-openctianyB2Two-way: correlation against your OpenCTI knowledge base (indicators, observables, actors, reports) + write-back of vetted findings
    /lookup-ransomwareliveorg-name, groupB2 (group/dates), B3 (descriptions)Ransomware leak-site claims; treat criminal-written descriptions cautiously
    /lookup-sentinelKQL, TTP hunt, IOC sweepA2Your own Microsoft Sentinel telemetry — exposure scoping, not enrichment. Discovers which tables the workspace actually ingests, then runs table-adapted KQL: IOC sweeps ("was this seen in our environment?") and ATT&CK TTP hunts. Chain after external lookups on a malicious verdict. A miss = "not observed in collected telemetry", never "not compromised". Read-only.

    When a downstream investigation skill (e.g. /hash-investigation) is invoked but its SKILL.md doesn't reference a lookup that obviously applies (e.g. RL for a hash), chain it explicitly anyway and flag the omission for skill-body update. Better to over-chain once than miss high-value signal.

    What you do NOT do

    • Do not call external APIs directly. Always invoke a /lookup-* skill.
    • Do not perform deep analysis in this skill. Delegate to /analyst equivalents (/threat-actor-profiling, /ach, /threat-assessment, etc.).
    • Do not write finished reports in this skill. Delegate to /intelligence-writing or /writing-assessments.
    • Do not skip the rigor pipeline unless the user explicitly opts out.

    Composition contract

    When you invoke a downstream skill, include in your message to the skill:

    • The user's original request (verbatim)
    • Any context already gathered (e.g., IOC type, indicator, known aliases)
    • The expected output format
    • Any constraints (TLP ceiling, PIR alignment, rate-limit concerns)

    Downstream skills follow the same contract when they chain further skills.

    See also

    • AGENTS.md — platform-neutral orientation
    • VERSIONS.md — what's shipped
    • tools/REGISTRY.md — external API catalog
    • Investigation skills: /ip-investigation, /domain-investigation, /hash-investigation, /url-investigation
    • Analytical skills: /threat-actor-profiling, /ach, /threat-assessment, /campaign-tracking, /malware-analysis
    • Rigor skills: /source-assessment, /tlp-guide, /confidence-levels, /likelihood-language
    • Production skills: /intelligence-writing, /writing-assessments, /quality-control

    Alternatives

    Compare before choosing

    Computed 10042,968

    coreyhaines31/marketingskills

    ab-testing

    When the user wants to plan, design, or implement an A/B test or experiment, or build a growth experimentation program. Also use when the user mentions "A/B test," "split test," "experiment," "test this change," "variant copy," "multivariate test," "hypothesis," "should I test this," "which version is better," "test two versions," "statistical significance," "how long should I run this test," "growth experiments," "experiment velocity," "experiment backlog," "ICE score," "experimentation program

    Computed 10042,968

    coreyhaines31/marketingskills

    churn-prevention

    When the user wants to reduce churn, build cancellation flows, set up save offers, recover failed payments, or implement retention strategies. Also use when the user mentions 'churn,' 'cancel flow,' 'offboarding,' 'save offer,' 'dunning,' 'failed payment recovery,' 'win-back,' 'retention,' 'exit survey,' 'pause subscription,' 'involuntary churn,' 'people keep canceling,' 'churn rate is too high,' 'how do I keep users,' or 'customers are leaving.' Use this whenever someone is losing subscribers o

    Computed 10023,781

    alirezarezvani/claude-skills

    app-store-optimization

    App Store Optimization (ASO) toolkit for researching keywords, analyzing competitor rankings, generating metadata suggestions, and improving app visibility on Apple App Store and Google Play Store. Use when the user asks about ASO, app store rankings, app metadata, app titles and descriptions, app store listings, app visibility, or mobile app marketing on iOS or Android. Supports keyword research and scoring, competitor keyword analysis, metadata optimization, A/B test planning, launch checklist

    Computed 10014,225

    wanshuiyin/Auto-claude-code-research-in-sleep

    citation-audit

    Use it for operations and research tasks; the detail page covers purpose, installation, and practical steps.