Agent skill

Operationalizing Misp Threat Feeds

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Stand up MISP, enable and cache curated threat feeds (CIRCL, abuse.ch, Feodo Tracker), apply warninglists to suppress false positives, query indicators with PyMISP, and export attributes as…

Apache-2.0Auto-check: notesSecurity

Install Operationalizing Misp Threat Feeds

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill operationalizing-misp-threat-feeds -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills operationalizing-misp-threat-feeds --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/operationalizing-misp-threat-feeds .claude/skills/operationalizing-misp-threat-feeds && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
operationalizing-misp-threat-feeds
GitHub stars
34k
Token cost
~2.6k tokens
SKILL.md length
792 words
Files
5 (incl. scripts, references)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

Stand up MISP, enable and cache curated threat feeds (CIRCL, abuse.ch, Feodo Tracker), apply warninglists to suppress false positives, query indicators with PyMISP, and export attributes as…

  • Works in 10 steps: Add and enable a feed → Cache enabled feeds for real-time… → Enable warninglists to reduce false… → …
  • Maturing a MISP instance to actively drive detection
  • SKILL.md covers Overview, When to Use, Prerequisites and Objectives, plus 4 more sections
  • Runs Python scripts from its folder; calls pip, curl and git; reaches github.com and circl.lu

What it does

Operationalizing Misp Threat Feeds is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Stand up MISP, enable and cache curated threat feeds (CIRCL, abuse.ch, Feodo Tracker), apply warninglists to suppress false positives, query indicators with PyMISP, and export attributes as auto-generated Suricata/Sigma/Wazuh detection rules. Use when maturing a MISP instance to actively drive detection, curating threat feeds with quality controls, or automating IOC-to-detection pipelines for the SIEM/IDS.

Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including scripts and reference files (for example `references/api-reference.md`, `references/standards.md` and `scripts/agent.py`).

It sits in Security, covering Security operations and Meeting notes and agendas. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Maturing a MISP instance to actively drive detection
  • Curating threat feeds with quality controls
  • Automating IOC-to-detection pipelines for the SIEM/IDS

Example prompts

  • “/operationalizing-misp-threat-feeds”

Requirements

  • Python 3
  • Docker
  • A credential in YOUR_AUTH_KEY

Workflow steps

10 steps, taken from the step headings in SKILL.md.

  1. Add and enable a feed
  2. Cache enabled feeds for real-time correlation
  3. Enable warninglists to reduce false positives
  4. Authenticate and search for fresh IOCs
  5. Export Suricata/Snort rules via the REST API
  6. Deploy the Suricata rules
  7. Generate Wazuh CDB lists from IOCs
  8. Generate Sigma rules from MISP intelligence
  9. Convert and deploy Sigma to your SIEM backend
  10. Schedule the pipeline and run the bundled helper

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • pip
    • curl
    • git
    • docker
    • python

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com
    • circl.lu

    Also links to:

    • misp-project.org
    • documentation.wazuh.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Operationalizing Misp Threat Feeds loads about 2.6k tokens when it runs, and up to ~3.6k if it reads all its reference files. Until then it costs about 111 tokens; SKILL.md has 792 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~111
When it runs · the whole SKILL.md, loaded when a task matches
~2.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:48
    cd misp-docker && cp template.env .env

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 792 words, ~2,639 tokens.

Download SKILL.mdSave it as .claude/skills/operationalizing-misp-threat-feeds/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
operationalizing-misp-threat-feeds
description
Stand up MISP, enable and cache curated threat feeds (CIRCL, abuse.ch, Feodo Tracker), apply warninglists to suppress false positives, query indicators with PyMISP, and export attributes as auto-generated Suricata/Sigma/Wazuh detection rules. Use when maturing a MISP instance to actively drive detection, curating threat feeds with quality controls, or automating IOC-to-detection pipelines for the SIEM/IDS.
domain
cybersecurity
subdomain
threat-intelligence
tags
threat-intelligence, misp, pymisp, threat-feeds, ioc, suricata, sigma, detection-engineering
version
1.0
author
mahipal
license
Apache-2.0
nist_csf
ID.RA-02
mitre_attack
T1589

Operationalizing MISP Threat Feeds

Note: This skill covers a defensive threat-intelligence platform. Handle ingested intelligence according to its Traffic Light Protocol (TLP) marking and your sharing agreements. Treat ingested IOCs as potentially sensitive.

Overview

MISP (Malware Information Sharing Platform) is the de-facto open-source threat-intelligence platform for storing, correlating, and sharing structured indicators (IOCs), events, galaxies (threat-actor/technique knowledge), and objects. Running a MISP instance is only the first step; the value comes from operationalizing it — curating high-quality feeds, suppressing false positives with warninglists, and pushing the resulting IOCs into detection tooling so intelligence actually drives blocking and alerting.

A feed in MISP is a remote source (another MISP, a CSV/freetext list, or a structured collection) that you enable and optionally cache. Caching pulls the feed's IOCs into the instance's Redis-backed cache so values can be correlated and looked up in real time (e.g., a SIEM asking "have you seen this domain?") without importing every event. Curation matters: enabling every public feed produces noise and false positives, so you select reputable feeds (CIRCL OSINT, abuse.ch, Feodo Tracker, etc.), apply warninglists (known-good ranges like RFC1918, Alexa/Tranco top sites, public DNS resolvers) to flag non-actionable indicators, and use taxonomies/tags (TLP, confidence) to scope what gets exported.

The detection-engineering payoff comes from MISP's export formats and PyMISP. MISP can render matching attributes directly as Suricata and Snort rules via the REST API, and PyMISP lets you script extraction of fresh IOCs to generate Sigma rules and Wazuh CDB lists / rules on a schedule. This skill walks the full lifecycle: feed enablement and caching, warninglist-based FP reduction, PyMISP-driven search, and automated generation of Suricata, Sigma, and Wazuh detections.

When to Use

  • Standing up or maturing a MISP instance into a feed that drives detection, not just a repository.
  • Curating and caching public/commercial threat feeds with quality controls.
  • Reducing IOC false positives with warninglists before they reach the SIEM/IDS.
  • Automating generation of Suricata/Sigma/Wazuh detections from MISP attributes.
  • Integrating MISP with a SOC so DNS/IP/hash lookups can be enriched against current intel.

Prerequisites

  • A running MISP instance (the maintained container images are the fastest path):
    bash
    git clone https://github.com/MISP/misp-docker.git
    cd misp-docker && cp template.env .env
    docker compose up -d
    # Web UI on https://localhost; default admin: admin@admin.test / admin
  • A MISP Auth Key (UI: Administration -> List Auth Keys -> Add).
  • PyMISP:
    bash
    pip install pymisp
  • Target detection tooling reachable: Suricata, a Sigma toolchain (pip install sigma-cli), and/or Wazuh manager.

Objectives

  • Enable and cache curated threat feeds in MISP.
  • Apply warninglists to suppress known-good / non-actionable indicators.
  • Authenticate and query MISP with PyMISP to pull fresh, scoped IOCs.
  • Export matching attributes as Suricata/Snort rules via the REST API.
  • Generate Sigma rules and Wazuh CDB lists from MISP attributes on a schedule.
  • Validate that generated detections load and fire in the target tooling.

MITRE ATT&CK Mapping

Technique IDTechnique NameRelevance
T1589Gather Victim Identity InformationFeeds capture adversary reconnaissance indicators; operationalizing them detects/contextualizes such activity.
T1071.001Application Layer Protocol: Web ProtocolsC2 domain/URL IOCs from feeds become Suricata/Sigma detections for malicious HTTP(S).
T1071.004Application Layer Protocol: DNSMalicious-domain IOCs feed DNS-based detection (Wazuh/Suricata).
T1105Ingress Tool TransferFile-hash IOCs from feeds detect known malicious payload delivery.
Show full SKILL.md (295 more words)Show less

Workflow

1. Add and enable a feed

Register a reputable source and turn it on.

python
# add_feed.py (PyMISP) — register the CIRCL OSINT feed
from pymisp import PyMISP, MISPFeed
misp = PyMISP("https://localhost", "YOUR_AUTH_KEY", ssl=False)
feed = MISPFeed()
feed.name = "CIRCL OSINT Feed"
feed.provider = "CIRCL"
feed.url = "https://www.circl.lu/doc/misp/feed-osint"
feed.source_format = "misp"
feed.input_source = "network"
feed.enabled = True
print(misp.add_feed(feed, pythonify=True))
2. Cache enabled feeds for real-time correlation

Caching loads feed IOCs into Redis so lookups are instant.

python
# Cache all enabled feeds (equivalent to "Enable caching" in the UI)
print(misp.cache_all_feeds())
# Or fetch a single feed's events into the instance by feed id:
print(misp.fetch_feed(1))
3. Enable warninglists to reduce false positives

Turn on known-good lists so non-actionable indicators are flagged.

python
# Enable the common false-positive warninglists
for wl in misp.warninglists(pythonify=True):
    if wl.name in ("List of RFC 1918 CIDR blocks",
                   "Top 1000 website from Cisco Umbrella",
                   "List of known public DNS resolvers"):
        misp.toggle_warninglist(warninglist_id=wl.id, force_enable=True)
4. Authenticate and search for fresh IOCs

Pull recently published, TLP-scoped, to-IDS attributes only.

python
from pymisp import PyMISP
misp = PyMISP("https://localhost", "YOUR_AUTH_KEY", ssl=False)
# Only export attributes flagged to_ids=1, published, last 7 days, IP/domain/url/hash
attrs = misp.search(
    controller="attributes",
    type_attribute=["ip-dst", "domain", "url", "md5", "sha256"],
    to_ids=True, published=True, last="7d",
    enforce_warninglist=True,   # drop warninglisted (known-good) values
    pythonify=True,
)
print(f"{len(attrs)} actionable IOCs")
5. Export Suricata/Snort rules via the REST API

MISP renders matching attributes directly as IDS rules.

bash
# Suricata rules for all to_ids network IOCs (NIDS export)
curl -s -k -H "Authorization: YOUR_AUTH_KEY" -H "Accept: application/json" \
  "https://localhost/attributes/restSearch/returnFormat:suricata/to_ids:1/type:domain%7Cip-dst%7Curl" \
  -o misp_suricata.rules

# Snort equivalent
curl -s -k -H "Authorization: YOUR_AUTH_KEY" -H "Accept: application/json" \
  "https://localhost/attributes/restSearch/returnFormat:snort/to_ids:1" -o misp_snort.rules
6. Deploy the Suricata rules

Load and reload.

bash
cp misp_suricata.rules /etc/suricata/rules/
suricata -T -c /etc/suricata/suricata.yaml   # validate config + rules
suricatasc -c reload-rules                    # hot reload
7. Generate Wazuh CDB lists from IOCs

Convert MISP domains/IPs into a Wazuh CDB lookup list referenced by a rule.

python
# Build a Wazuh CDB list (key:value per line) from the searched attributes
with open("misp_iocs.cdb", "w") as fh:
    for a in attrs:
        if a.type in ("domain", "ip-dst"):
            fh.write(f"{a.value}:\n")
# On the Wazuh manager: place under /var/ossec/etc/lists/, reference in ossec.conf:
#   <list>etc/lists/misp_iocs</list>
# then compile and restart:
#   /var/ossec/bin/wazuh-control restart
8. Generate Sigma rules from MISP intelligence

Emit a Sigma rule matching the exported domains.

python
import yaml
domains = [a.value for a in attrs if a.type == "domain"]
sigma = {
    "title": "MISP feed malicious domain contact",
    "status": "experimental",
    "logsource": {"category": "dns"},
    "detection": {"selection": {"query|contains": domains}, "condition": "selection"},
    "level": "high",
    "tags": ["attack.command_and_control", "attack.t1071.004"],
}
with open("misp_domains.yml", "w") as fh:
    yaml.safe_dump(sigma, fh, sort_keys=False)
9. Convert and deploy Sigma to your SIEM backend

Use sigma-cli to compile to the target backend (Splunk, Elastic, etc.).

bash
sigma convert -t splunk -p splunk_windows misp_domains.yml > misp_domains.spl
sigma convert -t elasticsearch misp_domains.yml > misp_domains.eql
10. Schedule the pipeline and run the bundled helper

agent.py searches MISP and writes Suricata/Sigma/Wazuh artifacts in one pass; schedule it via cron.

bash
python scripts/agent.py --url https://localhost --key YOUR_AUTH_KEY \
  --last 7d --outdir ./detections --insecure
# crontab: 0 * * * * /usr/bin/python /path/scripts/agent.py ... >> /var/log/misp_pipeline.log 2>&1

Tools and Resources

ToolPurposeSource
MISPThreat-intelligence platformhttps://www.misp-project.org/
misp-dockerMaintained container deploymenthttps://github.com/MISP/misp-docker
PyMISPPython client for the MISP REST APIhttps://github.com/MISP/PyMISP
MISP warninglistsKnown-good lists for FP reductionhttps://github.com/MISP/misp-warninglists
MISP automation docsREST API + export formatshttps://www.circl.lu/doc/misp/automation/
sigma-cliSigma rule conversionhttps://github.com/SigmaHQ/sigma-cli
Wazuh CDB listsIOC lookup lists for Wazuhhttps://documentation.wazuh.com/

Validation Criteria

  • MISP instance reachable and an Auth Key created.
  • At least one reputable feed enabled and cached.
  • Relevant warninglists enabled and enforce_warninglist applied to searches.
  • PyMISP search returns scoped, to_ids, non-warninglisted IOCs.
  • Suricata/Snort rules exported via REST and validated with suricata -T.
  • Wazuh CDB list generated and loaded by the manager.
  • Sigma rule generated and converted to the SIEM backend.
  • Generated detections confirmed to load (and fire on a test IOC).
  • Pipeline scheduled and logging successfully.

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references) in skills/operationalizing-misp-threat-feeds of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • references/api-reference.md
  • references/standards.md
  • scripts/agent.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Operationalizing Misp Threat Feeds next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Operationalizing Misp Threat Feeds compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Operationalizing Misp Threat Feeds this skillmukul975/Anthropic-Cybersecurity-Skills34k—~2.6kAutomated safety check: NotesApache-2.0
Security Alert Triageelastic/agent-skills5921 repos~3.5kAutomated safety check: NotesApache-2.0
Kubernetes Network Security Auditkubeshark/kubeshark12k—~7.3kAutomated safety check: NotesApache-2.0
Security Detection Rule Managementelastic/agent-skills5921 repos~3.9kAutomated safety check: NotesApache-2.0
Chaitin CLIchaitin/chaitin-cli115—~15kAutomated safety check: NotesGPL-3.0
GatesNebulock-Inc/agentic-threat-hunting-framework388—~12kAutomated safety check: PassMIT

Similar skills

  • Security Alert Triage

    elastic/agent-skills

    Official

    Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.

    592 GitHub starsUsed in 1 repo~3.5k tokens
    SecurityAuto-check: notes
  • Hunts for compromised workloads and malicious traffic in a Kubernetes cluster by sweeping network data through Kubeshark MCP, mapped to MITRE ATT&CK.

    12k GitHub stars~7.3k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Official

    Create, tune, and manage Elastic Security detection rules (SIEM and Endpoint).

    592 GitHub starsUsed in 1 repo~3.9k tokens
    SecurityAuto-check: notes
  • Chaitin CLI

    chaitin/chaitin-cli

    A skill your agent uses when running chaitin-cli commands to manage Chaitin security products: SafeLine WAF (site management, IP blocking, ACL, policy rules, attack logs), X-Ray vulnerability…

    115 GitHub stars~15k tokensUpdated 11 days ago
    SecurityAuto-check: notes
  • Gates

    Nebulock-Inc/agentic-threat-hunting-framework

    GATES method validation for hunt-derived detections. An agent skill from Nebulock-Inc/agentic-threat-hunting-framework.

    388 GitHub stars~12k tokensUpdated 2 days ago
    SecurityAuto-check passed
  • Elasticsearch Audit

    aspectrr/deer

    Enable, configure, and query Elasticsearch security audit logs.

    405 GitHub stars~1.7k tokensUpdated 5 mo ago
    SecurityAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Operationalizing Misp Threat Feeds

What does Operationalizing Misp Threat Feeds do?

Stand up MISP, enable and cache curated threat feeds (CIRCL, abuse.ch, Feodo Tracker), apply warninglists to suppress false positives, query indicators with PyMISP, and export attributes as…. Operationalizing Misp Threat Feeds is an agent skill from mukul975/Anthropic-Cybersecurity-Skills.ch, Feodo Tracker), apply warninglists to suppress false positives, query indicators with PyMISP, and export attributes as auto-generated Suricata/Sigma/Wazuh detection rules.

When should I use Operationalizing Misp Threat Feeds?

Operationalizing Misp Threat Feeds fits situations like: maturing a MISP instance to actively drive detection; curating threat feeds with quality controls; automating IOC-to-detection pipelines for the SIEM/IDS.

How do I install Operationalizing Misp Threat Feeds in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill operationalizing-misp-threat-feeds -a claude-code`. Or copy the skill folder (skills/operationalizing-misp-threat-feeds in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/operationalizing-misp-threat-feeds in your project. Claude Code loads it when a task matches its description.

How do I install Operationalizing Misp Threat Feeds in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill operationalizing-misp-threat-feeds -a codex`. Or copy the skill folder (skills/operationalizing-misp-threat-feeds in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/operationalizing-misp-threat-feeds in your project. Codex loads it when a task matches its description.

Can I use Operationalizing Misp Threat Feeds in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill operationalizing-misp-threat-feeds -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/operationalizing-misp-threat-feeds, .gemini/skills/operationalizing-misp-threat-feeds, .github/skills/operationalizing-misp-threat-feeds and .opencode/skills/operationalizing-misp-threat-feeds in your project.

What does Operationalizing Misp Threat Feeds need to run?

Going by SKILL.md and its folder, Operationalizing Misp Threat Feeds needs Python for the scripts in its folder and the command-line tools its instructions call (pip, curl, git, docker and python). Our summary lists: Python 3; Docker; A credential in YOUR_AUTH_KEY.

Does Operationalizing Misp Threat Feeds access the network?

SKILL.md names 4 domains. In commands or code: github.com and circl.lu; the agent is likely to contact these when it follows the instructions. As links in the text: misp-project.org and documentation.wazuh.com. This is read from the text; nothing was executed.

Is Operationalizing Misp Threat Feeds safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Operationalizing Misp Threat Feeds use?

Operationalizing Misp Threat Feeds is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Operationalizing Misp Threat Feeds use?

About 2.6k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 996 tokens, read only when the agent opens those files.

What are the alternatives to Operationalizing Misp Threat Feeds?

Skills that share tags, products or a category with Operationalizing Misp Threat Feeds: Security Alert Triage (elastic/agent-skills, 592 stars), Kubernetes Network Security Audit (kubeshark/kubeshark, 12k stars), Security Detection Rule Management (elastic/agent-skills, 592 stars) and Chaitin CLI (chaitin/chaitin-cli, 115 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Operationalizing Misp Threat Feeds?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 34,116 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.