Best for
- Use when the user wants to configure API keys for the CTI skills pack, asks "how do I set up keys", "configure VirusTotal", "add my Shodan key", or runs /cti-setup.
Liberty91LTD/cti-skills/skills/cti-setup/SKILL.md
Use when the user wants to configure API keys for the CTI skills pack, asks "how do I set up keys", "configure VirusTotal", "add my Shodan key", or runs /cti-setup. Walks through API key configuration inside Claude Code without needing to run a shell script. Also handles re-running setup, adding individual keys, and verifying that configured keys work.
Decision brief
In-chat configuration of API keys for the threat-intel integrations bundled with this pack. Use this when the user is in Claude Code and doesn't want to drop to a shell to run ./scripts/setup.sh.
Compatibility matrix
| Platform | Status | Evidence | What to check |
|---|---|---|---|
| Codex | Not declared | No explicit evidence | Portability before use |
| Claude Code | Declared | Source record | Install path and trigger |
| Cursor | Not declared | No explicit evidence | Portability before use |
| Gemini CLI | Not declared | No explicit evidence | Portability before use |
Installation
The source command is displayed only when detected. A safe inspection prompt is always available so your agent can explain every action before execution.
npx skills add https://github.com/Liberty91LTD/cti-skills --skill "skills/cti-setup"Inspect the Agent Skill "cti-setup" from https://github.com/Liberty91LTD/cti-skills/blob/97d66b3687ba6d32b316a7df3391beb3e2de88de/skills/cti-setup/SKILL.md at commit 97d66b3687ba6d32b316a7df3391beb3e2de88de. List every install step, command, network request, credential, file read/write, external action, and rollback step. Explain whether it fits my task. Do not install or execute anything until I approve.
Workflow
The file is .claude/settings.local.json. It is gitignored. Do not overwrite it — read, merge the env block, write back. Use the bundled setup script which handles this safely:
User asks "how do I set up keys", "configure my API keys", "add a VirusTotal key", etc.
1. Check current state. Read .claude/settings.local.json. If it's missing or has no env block, the user has zero keys configured. If it has some, list which are present and which are missing. 2. Tell the user the menu. Present the services in a table with: name, env variable, fr…
If the user has a Liberty91 account, configure LIBERTY91APIKEY first — it is the pack's first-party source and /lookup-liberty91 runs before third-party lookups, so it saves other services' quota. Keys are l91live (production) or l91test (development); an empty scope list on the…
If the user wants to verify, run:
Permission review
The documentation asks the agent to run terminal commands or scripts.
In-chat configuration of API keys for the threat-intel integrations bundled with this pack. Use this when the user is in Claude Code and doesn't want to drop to a shell to run `./scripts/setup.sh`.The documentation asks the agent to create, modify, or delete local files.
**Write the merged file.** Use the non-destructive merge below — preserve every other field in `settings.local.json`.The documentation asks the agent to run terminal commands or scripts.
**Offer to verify.** Ask if they want you to dry-run each configured key against its CLI to confirm it's wired up.The documentation includes network, browsing, or remote request actions.
| Microsoft Sentinel | `SENTINEL_TENANT_ID` + `SENTINEL_CLIENT_ID` + `SENTINEL_CLIENT_SECRET` + `SENTINEL_WORKSPACE_ID` | your Azure tenancy (query API is free; 200 queries/30s) | Azure portal — Entra ID app registration + Log Analytics ReaThe documentation asks the agent to create, modify, or delete local files.
## How to write the fileThe documentation includes network, browsing, or remote request actions.
-misp-url=https://misp.example.org \The documentation asks the agent to read local files, directories, or repositories.
try { cur = JSON.parse(fs.readFileSync(path, 'utf8')); } catch(e) {}Evidence record
| Signal | Value | Evidence type | Meaning |
|---|---|---|---|
| Quality score | 84/100 | Computed | Documentation, specificity, maintenance, and trust rules |
| Repository stars | 11 | Source | Repository attention, not individual Skill quality |
| Compatibility | 1 platforms | Source | Declared in the catalog source record |
| Usage guide | automated source guide | Editorial | Generated or reviewed according to the visible evidence level |
Pinned source
In-chat configuration of API keys for the threat-intel integrations bundled with this pack. Use this when the user is in Claude Code and doesn't want to drop to a shell to run ./scripts/setup.sh.
/cti-setuplookup-* skill failed because a key is missing and you want to offer to add it/plugin marketplace add or npx (no shell setup ran).claude/settings.local.json. If it's missing or has no env block, the user has zero keys configured. If it has some, list which are present and which are missing.your VirusTotal key or the masked tail …<last 4 chars>).settings.local.json./ip-investigation 8.8.8.8" or similar concrete next command.| Service | Env variable | Free tier | Signup |
|---|---|---|---|
| Liberty91 (first-party) | LIBERTY91_API_KEY (optional LIBERTY91_API_URL) | per-key rate limit + monthly credits on your plan | Liberty91 platform → user menu → API Access (Owner/Admin only; the secret is shown once) |
| VirusTotal | VIRUSTOTAL_API_KEY | 4/min, 500/day | virustotal.com → profile → API key |
| URLScan.io | URLSCAN_API_KEY | 100 scans/day | urlscan.io → user settings |
| Shodan | SHODAN_API_KEY | 1 req/sec | account.shodan.io |
| AbuseIPDB | ABUSEIPDB_API_KEY | 1000 checks/day | abuseipdb.com → account → API |
| GreyNoise | GREYNOISE_API_KEY | 50 req/day (community) | viz.greynoise.io → account |
| AlienVault OTX | OTX_API_KEY | 10k req/hour | otx.alienvault.com → settings |
| Censys | CENSYS_PAT | 250 queries/month | accounts.censys.io → settings → personal-access-tokens |
| MISP | MISP_URL + MISP_API_KEY | self-hosted / org-provided | your MISP instance → My Profile → Auth keys |
| OpenCTI | OPENCTI_URL + OPENCTI_TOKEN | self-hosted / org-provided | your OpenCTI instance → profile → API access (token) |
| Ransomware.live | RANSOMWARE_LIVE | 3000 req/day (PRO) | my.ransomware.live → free PRO key |
| ReversingLabs A1000 | REVERSINGLABS_USER + REVERSINGLABS_PASSWORD (optional REVERSINGLABS_HOST) | undocumented; 429+Retry-After | licensed product — issued by your RL admin or RL account team |
| CrowdStrike Falcon Intelligence | CROWDSTRIKE_CLIENT_ID + CROWDSTRIKE_CLIENT_SECRET (optional CROWDSTRIKE_BASE_URL) | per-tenant; 429+Retry-After | licensed product — Falcon console → Support and resources → API clients and keys (assign Intel read scopes) |
| Microsoft Sentinel | SENTINEL_TENANT_ID + SENTINEL_CLIENT_ID + SENTINEL_CLIENT_SECRET + SENTINEL_WORKSPACE_ID | your Azure tenancy (query API is free; 200 queries/30s) | Azure portal — Entra ID app registration + Log Analytics Reader role; walkthrough in tools/integrations/sentinel.md |
If the user has a Liberty91 account, configure LIBERTY91_API_KEY first — it is the pack's first-party source and /lookup-liberty91 runs before third-party lookups, so it saves other services' quota. Keys are l91_live_ (production) or l91_test_ (development); an empty scope list on the key grants all read scopes, which is the right default for enrichment. Set LIBERTY91_API_URL only to point at a non-production host.
A starter set of VirusTotal + OTX + URLScan + AbuseIPDB covers most IP/domain/URL/hash investigations. Shodan and GreyNoise add value for IP-focused work. Censys is optional (very tight rate limit). MISP requires both a base URL and an auth key — point it at your org's instance. OpenCTI likewise takes a base URL plus an API token and powers /lookup-opencti (two-way: query your knowledge base + push vetted intel back). Ransomware.live powers the lookup-ransomwarelive and ransomware-ecosystem skills (victim/group tracking). ReversingLabs is a licensed product — only configure if your organisation has a Spectra Analyze (A1000) account. CrowdStrike Falcon Intelligence is a licensed subscription — it powers /lookup-crowdstrike for IOC reputation AND threat-actor / TTP / report intelligence; configure if your org has a Falcon Intelligence licence with Intel API scopes. Microsoft Sentinel takes four values and powers /lookup-sentinel (hunt your own workspace: IOC exposure sweeps + ATT&CK TTP hunts, read-only). All four come from the Azure portal: create an Entra ID app registration (→ tenant id + client id), add a client secret (shown once), grant the app Log Analytics Reader on the Sentinel workspace, and copy the Workspace ID from the workspace Overview blade — the step-by-step is in tools/integrations/sentinel.md. No extra licence is needed beyond the workspace itself.
The file is .claude/settings.local.json. It is gitignored. Do not overwrite it — read, merge the env block, write back. Use the bundled setup script which handles this safely:
./scripts/setup.sh --non-interactive \
--liberty91=USER_PROVIDED_KEY \
--virustotal=USER_PROVIDED_KEY \
--shodan=USER_PROVIDED_KEY \
--misp-url=https://misp.example.org \
--misp=USER_PROVIDED_KEY \
--opencti-url=https://opencti.example.org \
--opencti=USER_PROVIDED_TOKEN \
--ransomwarelive=USER_PROVIDED_KEY \
--reversinglabs-user=USER_PROVIDED_USERNAME \
--reversinglabs-password=USER_PROVIDED_PASSWORD \
--reversinglabs-host=https://a1000.reversinglabs.com
(Pass only the flags for keys the user actually shared. Available flags: --liberty91, --liberty91-url, --virustotal, --urlscan, --shodan, --abuseipdb, --greynoise, --otx, --censys, --misp-url, --misp, --opencti-url, --opencti, --ransomwarelive, --reversinglabs-user, --reversinglabs-password, --reversinglabs-host, --crowdstrike-client-id, --crowdstrike-client-secret, --crowdstrike-base-url, --sentinel-tenant-id, --sentinel-client-id, --sentinel-client-secret, --sentinel-workspace-id.)
If scripts/setup.sh is not present (e.g. plugin-only install), do the merge yourself with this Node one-liner. Replace KEY=VAL pairs with the user's input:
node -e "
const fs = require('fs');
const path = '.claude/settings.local.json';
let cur = {};
try { cur = JSON.parse(fs.readFileSync(path, 'utf8')); } catch(e) {}
cur.env = cur.env || {};
Object.assign(cur.env, {
VIRUSTOTAL_API_KEY: 'USER_PROVIDED_KEY',
SHODAN_API_KEY: 'USER_PROVIDED_KEY',
});
fs.mkdirSync('.claude', { recursive: true });
fs.writeFileSync(path, JSON.stringify(cur, null, 2) + '\n');
"
After writing, confirm to the user:
If the user wants to verify, run:
./scripts/setup.sh --verify
This dry-runs each lookup CLI and reports OK/fail per service without making a real API call. If setup.sh is unavailable, dry-run each CLI individually:
node tools/clis/virustotal.js ip 8.8.8.8 --dry-run
Exit code 0 = key present and CLI invocation OK. Exit code 2 = missing key.
To remove a key, edit .claude/settings.local.json and delete the entry from the env block (or set its value to ""). To rotate, just re-run setup with the new value — the merge overwrites that key only.
.claude/settings.local.json (already gitignored at repo root)./cti-setup with the new value.--dry-run invocations of the local CLIs)../scripts/download-mitre.sh (the /mitre-attack skill self-heals on first use).env block of settings.local.json.Alternatives
narrative-io/narrative-skills-marketplace
Translate a fuzzy analytical question into a rigorous investigation plan. Interrogates the ask, grounds the plan in the available data dictionary, applies analytical best practices, and produces a structured brief of query specifications for a downstream query-writing skill. Plans, does not write SQL. Use when: "why did X drop", "is there a relationship between A and B", "who are our highest-value customers", "what's driving the change in Y", "investigate this trend", "design an analysis for", "
luongnv89/claude-howto
Comprehensive Claude Code self-assessment and learning path advisor. Runs a multi-category quiz covering 10 feature areas, produces a detailed skill profile with per-topic scores, identifies specific gaps, and generates a personalized learning path with prioritized next steps. Use when asked to "assess my level", "take the quiz", "find my level", "where should I start", "what should I learn next", "check my skills", "skill check", or "level up".
PramodDutta/qaskills
Generate optimized test combinations using pairwise (all-pairs) testing algorithms to achieve maximum coverage with minimum test cases across multiple input parameters
PramodDutta/qaskills
Gate RAG pipelines in CI with versioned golden eval sets, per-metric thresholds, baseline drift detection, and a build that fails when retrieval or answer quality regresses.