Agent skill

Producing Threat Intelligence

by trilwu in trilwu/secskills

Produce cyber threat intelligence by pivoting on indicators to find related infrastructure, tracking actors and campaigns, enriching and contextualizing IOCs, applying attribution discipline and…

MITAuto-check passedSecurity

Install Producing Threat Intelligence

skills CLI
$ npx skills add trilwu/secskills --skill producing-threat-intelligence -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install trilwu/secskills producing-threat-intelligence --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/secskills-defense/skills/producing-threat-intelligence .claude/skills/producing-threat-intelligence && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
producing-threat-intelligence
GitHub stars
157
Token cost
~4.4k tokens
SKILL.md length
2,138 words
Files
1
Skills in repo
50
Repo updated
First seen
Licence
MIT

At a glance

Produce cyber threat intelligence by pivoting on indicators to find related infrastructure, tracking actors and campaigns, enriching and contextualizing IOCs, applying attribution discipline and…

  • Pivoting from a domain
  • SKILL.md covers When to Use, When NOT to Use, The Intelligence Lifecycle and Indicator Pivoting, plus 9 more sections
  • Calls curl and jq; reaches crt.sh and defuddle.md
  • Certificate to related infrastructure

What it does

Producing Threat Intelligence is an agent skill from trilwu/secskills. Produce cyber threat intelligence by pivoting on indicators to find related infrastructure, tracking actors and campaigns, enriching and contextualizing IOCs, applying attribution discipline and analytic confidence, and packaging finished intel products tied to a consumer's decision. Covers the intelligence lifecycle, the Diamond Model and Pyramid of Pain, STIX/MISP/OpenCTI storage, TLP sharing, and passive enrichment via passive DNS, crt.sh, Shodan, Censys, GreyNoise, and VirusTotal. Use when pivoting from a…

Its SKILL.md is about 4.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering OSINT and Threat modeling. The repository describes itself as: Transform Claude Code into your personal security engineer. The licence is MIT.

When your agent uses it

  • Pivoting from a domain
  • Certificate to related infrastructure
  • Tracking a threat actor
  • Enriching raw indicators

Example prompts

  • “/producing-threat-intelligence”

What it can do on your machine

Read from SKILL.md and the folder at commit ca53957. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl
    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • crt.sh
    • defuddle.md

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Producing Threat Intelligence loads about 4.4k tokens when it runs. Until then it costs about 204 tokens; SKILL.md has 2,138 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~204
When it runs · the whole SKILL.md, loaded when a task matches
~4.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from trilwu/secskills at commit ca53957, republished under its MIT licence (© trilwu). 2,138 words, ~4,357 tokens.

Download SKILL.mdSave it as .claude/skills/producing-threat-intelligence/SKILL.md (or your agent's skills folder).
name
producing-threat-intelligence
description
Produce cyber threat intelligence by pivoting on indicators to find related infrastructure, tracking actors and campaigns, enriching and contextualizing IOCs, applying attribution discipline and analytic confidence, and packaging finished intel products tied to a consumer's decision. Covers the intelligence lifecycle, the Diamond Model and Pyramid of Pain, STIX/MISP/OpenCTI storage, TLP sharing, and passive enrichment via passive DNS, crt.sh, Shodan, Censys, GreyNoise, and VirusTotal. Use when pivoting from a domain, IP, hash, or certificate to related infrastructure, tracking a threat actor or campaign, enriching raw indicators, writing a finished intel report, assessing an external report's relevance to your org, or building a threat model of adversaries that matter to you.
verified
2026-07-27

Producing Threat Intelligence

Intelligence is not a pile of indicators — it is analysis that reduces a decision-maker's uncertainty. An IOC with no context, no confidence, and no recommended action is data, not intelligence. Attribution is a claim you must be able to defend from evidence, not a guess dressed in a threat-actor name. The test of a finished product is simple: did someone decide something differently because of it?

When to Use

  • Pivoting from a domain, IP, hash, TLS certificate, or registrant to related infrastructure
  • Tracking a threat actor or campaign over time
  • Enriching and contextualizing raw indicators into usable intelligence
  • Producing a finished intelligence product for a defined consumer
  • Assessing whether an external vendor or government report is relevant to your organization
  • Building and curating a threat model of the adversaries that actually matter to you

When NOT to Use

  • Searching your OWN telemetry for the activity — use hunting-threats
  • Reversing a specific sample — use analyzing-malware
  • Resolving an ATT&CK technique ID to a skill — use mapping-attack-techniques
  • An active, confirmed incident — use responding-to-incidents
  • Turning intel into deployed detection rules — use engineering-detections

The Intelligence Lifecycle

Every product moves through the same loop. Naming the stages is not bureaucracy — it is where you catch the two failures that make CTI worthless.

1. Direction     — whose decision, which question (a PIR)
2. Collection    — gather against the requirement, not everything reachable
3. Processing     — normalize, deduplicate, translate, enrich
4. Analysis      — assess, weigh hypotheses, assign confidence
5. Dissemination — deliver in a form the consumer can act on
6. Feedback      — did it help; refine the next requirement

The two failures that account for most wasted CTI effort are at the ends of the loop, not the middle:

  • Skipping direction produces intelligence nobody asked for. Without a Priority Intelligence Requirement (PIR) naming the consumer and the decision, you collect what is easy and report what is interesting, and it lands on no one's desk. Start from the question, not the feed.
  • Skipping dissemination produces analysis that never reaches a decision. A brilliant assessment sitting in a wiki nobody reads changed nothing. The product is not done when it is written; it is done when it is in front of the person who acts on it, in the form and at the time they need it.

Write the PIR before collecting. Examples: "Which ransomware crews target our sector and what is their initial-access tradecraft?" "Is the actor in last week's incident likely to return?" "Does this vendor report describe a threat to us?" Each names a consumer and a decision.

Indicator Pivoting

Pivoting expands one observable into an infrastructure picture. The discipline is to stay passive first — every pivot below reads third-party data or historical records, none of it touches the adversary's live infrastructure.

Start fromPivot viaFinds
Domain / IPPassive DNS (PDNS)Historical resolutions, sibling domains on an IP, IPs a domain used
DomainWHOIS / registration historyRegistrant email, registrar, creation date, name-server reuse
Domain / IPCertificate transparency (crt.sh)Other hostnames on the same cert, SAN reuse, issuance timeline
IP / serviceTLS fingerprints — JARM (server), JA3/JA3S (client/server handshake)Hosts running the same C2 or framework default TLS stack
Web serviceFavicon hash (Shodan http.favicon.hash, Censys)Other servers serving the identical panel or login page
IP / hostShodan / Censys bannersOpen ports, product versions, response bodies, self-signed cert CNs

A worked pivot chain: a phishing domain resolves (PDNS) to an IP; crt.sh shows the cert's SANs cover four more lookalike domains; the IP's JARM matches a known Cobalt Strike default; Shodan's favicon hash for the panel returns nine more IPs serving the same interface. One indicator became a cluster of ten, none of which required contacting the adversary.

# Certificate transparency — all certs/SANs seen for a domain
curl -s "https://crt.sh/?q=%25.example.com&output=json" | jq -r '.[].name_value' | sort -u

# Shodan: everything serving an identical favicon
shodan search "http.favicon.hash:-247388890"

# Censys: hosts presenting a given JARM fingerprint.
# Censys Platform (CenQL) prefixes every parsed field with its dataset:
censys search "host.services.jarm.fingerprint: <jarm_hash>"
# Legacy Search used the unprefixed form below. It is deprecated as of
# September 2026, so treat any older query you find as needing conversion:
#   services.jarm.fingerprint: <jarm_hash>

Do not tip off the adversary. Do not curl the live C2, resolve its domain from a network attributable to you, submit the still-active sample to a public multi-scanner, or scan the infrastructure directly — each of those tells the operator you are watching and invites rotation or a burn of your visibility. Prefer passive datasets. If active interaction is genuinely required, route it through infrastructure that is not attributable to you and make it a deliberate, logged decision.

Frameworks for Prioritizing What to Track

Diamond Model

Every intrusion event has four connected features: adversary, capability (malware, tooling, exploits), infrastructure (C2, staging, redirectors), and victim. Any feature leads to another — a capability points to the adversary who wields it; infrastructure points to other victims. Pivoting is literally traversing the edges of the diamond. Record findings against these four vertices so a partial picture composes with the next one.

Pyramid of Pain

Not all indicators cost the adversary the same to change. The higher you track, the more it hurts them and the longer your intelligence survives.

TTPs             ← hardest to change — track these
Tools
Network/Host artifacts
Domain names
IP addresses
Hash values      ← trivial to change — useful now, dead tomorrow

Hashes and IPs are cheap for the adversary to rotate, so intelligence built on them decays in days. Tooling and TTPs force real redevelopment. Prioritize collection and tracking toward the top of the pyramid; treat the bottom as perishable and time-stamp it accordingly.

Attribution Discipline

Attribution is the most abused word in CTI. Keep two operations strictly separate:

  • Clustering groups activity by shared observables (infrastructure patterns, tooling, TTPs, tradecraft, timing). It is defensible from evidence and it is what you should do most of the time.
  • Naming asserts that a cluster IS a known actor. It inherits that actor's history, motivation, and geopolitical baggage — and it is frequently wrong.

Use temporary, non-committal labels for clusters you have not confirmed: UNC-style uncategorized designators, or your own internal CLUSTER-####. Only promote a cluster to a named actor when the evidence supports it, and state what evidence. "Same TTPs" is weak grounds: shared tooling, shared exploit kits, and public tradecraft mean two operators can look identical.

Analytic confidence is a separate axis from the claim. State it explicitly:

  • High — consistent, corroborated evidence from multiple independent sources; few plausible alternatives.
  • Moderate — credible evidence, but gaps or single-source dependence leave room for alternatives.
  • Low — fragmentary or uncorroborated; the assessment is a working hypothesis.

Confidence is not the same as how strongly you feel it. It is a function of the evidence and the number of surviving alternative explanations.

Analysis of Competing Hypotheses (ACH): when attribution or intent is contested, enumerate the plausible hypotheses first, then list the evidence, and score each item by how well it is consistent with each hypothesis. The goal is to find evidence that disconfirms — the hypothesis left standing after you try to break it is stronger than the one you set out to prove.

Cognitive-bias traps to name and resist:

  • Mirror-imaging — assuming the adversary reasons, prioritizes, and operates the way you would.
  • Confirmation bias — collecting and weighting evidence that supports the answer you already reached, discounting what contradicts it.
  • Anchoring — locking onto the first attribution offered (often a vendor's) and adjusting insufficiently as new evidence arrives.

Structured Storage and Standards

Free-text notes do not compose, correlate, or feed automation. Store intelligence in a structured model from the start.

  • STIX 2.1 — the interchange grammar. Objects (SDOs) include indicator, malware, threat-actor, campaign, intrusion-set, infrastructure, identity, and attack-pattern; relationships (SROs) like uses, targets, indicates, attributed-to connect them. A STIX indicator carries a pattern, valid-from/until, and confidence — context the bare IOC lacks.
  • MISP — event-centric sharing platform. Events hold attributes (the indicators) with types, categories, and per-attribute IDS flags; galaxies attach actor, tooling, and ATT&CK context; correlation across events surfaces overlap between your data and partners'.
  • OpenCTI — a knowledge graph that ingests STIX, links objects across reports, and lets you query relationships (which campaigns use this malware, which infrastructure this actor reuses) rather than re-deriving them.
  • TLP — the sharing classifier. Tag every product: TLP:RED (named recipients only), TLP:AMBER / TLP:AMBER+STRICT (their org, or their org only), TLP:GREEN (community), TLP:CLEAR (no restriction). The tag travels with the data; downgrading it is the sharer's call, never the recipient's.
Show full SKILL.md (895 more words)Show less

Enrichment Sources

Enrichment converts a bare observable into something with context and confidence. Match the source to the question.

SourceAnswers
VirusTotalDetections, relationships (contacted domains, dropped files, siblings), first/last seen, community context
Passive DNS (Farsight/DNSDB, SecurityTrails, Circl)Resolution history, co-hosted domains, infrastructure reuse over time
Shodan / CensysExposed services, banners, certs, JARM, favicon hashes — the internet-facing view without touching the target directly
GreyNoiseWhether an IP is mass-scanning the whole internet (background noise) versus activity aimed at you
URLScanWhat a URL actually serves — page content, redirects, resources, screenshot — without you browsing it

GreyNoise earns its place by subtraction. Most flagged IPs are internet background radiation — opportunistic scanners hitting everyone. GreyNoise tells you whether an indicator is that noise or something targeted, so you stop burning analyst hours enriching a Shodan crawler and focus on what is aimed at your organization.

Producing the Finished Product

The report is the product; everything upstream is inventory. Structure it for a decision-maker, not for an analyst admiring the work.

  • BLUF (bottom line up front) — the assessment and its "so what" in the first two sentences. If the reader stops after the first paragraph, they should still have the answer.
  • Confidence and sourcing — state analytic confidence on each key judgment, and separate what you observed from what you assess. Attribute claims to their evidence; distinguish single-source from corroborated.
  • So what / recommended action — tie the analysis to the consumer's decision. What should they do, block, hunt for, or prioritize, and why now? An assessment with no recommended action leaves the reader to reinvent the implication, and most will not.

Write to the audience: an executive needs the risk and the decision; a SOC lead needs the detections and the pivots. The same underlying intelligence becomes two different products.

CTI in the Defensive Loop

Threat intelligence is not a terminal deliverable — it is the fuel for the rest of the defensive program, and it consumes their output in return.

  • It feeds detection: TTPs and tooling become deployed rules via engineering-detections. Hand over behaviors and tiered indicators, not a raw feed.
  • It feeds hunting: an intel report's described behavior (not its dead IOCs) becomes a hypothesis in hunting-threats run against your telemetry.
  • It consumes ATT&CK mappings: resolve techniques through mapping-attack-techniques so your products speak the same taxonomy as detection and hunting, and coverage gaps become visible.

Intelligence that does not flow into detection, hunting, or a decision is a research hobby, not a capability.

Rationalizations to Reject

  • "More indicators is better intelligence." No. Unprioritized IOCs are noise that buries the few that matter. Volume is not value; a ranked handful with context beats a feed of ten thousand.
  • "It's the same actor — the TTPs match." TTP overlap is shared tooling as often as shared operator. Public kits and leaked frameworks make unrelated crews look identical. Cluster on the evidence; do not name.
  • "The vendor report attributes it, so it's confirmed." A vendor's attribution is one source with its own biases and incentives. Read their evidence, weigh it, and assign your own confidence — do not inherit theirs.
  • "We should scan the C2 to learn more." You just told the operator you are watching, and they rotate. Passive datasets first; active interaction only from non-attributable infrastructure as a deliberate decision.
  • "High confidence — it feels right." Confidence must be defensible from evidence and the count of surviving alternatives, not from conviction. If you cannot show the evidence, it is not high confidence.
  • "We produced the report, the job's done." Undisseminated intelligence changed no decision. The lifecycle does not end at analysis; it ends when the consumer has acted — or told you why they did not.
  • "This report is about someone else's sector, so it's irrelevant." Relevance is a judgment you make against your own threat model, not an assumption. The TTPs may transfer even when the target does not.

Reading External Sources

Fetch public advisories, specifications, and vendor reports as Markdown:

bash
curl -sL "https://defuddle.md/<url>"      # scheme in the path is optional

This strips page boilerplate — roughly 78% fewer tokens on a prose page — and returns the full text rather than a summary, so you can grep it and trust a negative result.

Three things it is not for. Fetch JSON and API responses raw, because readability extraction mangles structured data. Fetch authenticated or JavaScript-rendered pages directly, because it retrieves them anonymously. And never route adversary infrastructure (phishing links, C2, malware hosting), client-owned hosts, or engagement URLs through it — the request leaves your machine to a third party, and for live adversary infrastructure it also tips off the operator.

Some sites block the extractor and return an error blob rather than the page — {"error":"Failed to fetch: 418 I'm a teapot"} from freedesktop.org, for instance. That is the fetch being refused, not the source saying the thing does not exist. Re-fetch the URL directly before drawing any conclusion from it.

References

  • hunting-threats — running intel-derived hypotheses against your own telemetry
  • analyzing-malware — sample-derived config, capability, and IOCs that feed intel
  • engineering-detections — converting tracked TTPs into deployed rules
  • mapping-attack-techniques — resolving and standardizing ATT&CK references
  • responding-to-incidents — the consumer and source during an active event
  • reporting-security-findings — structure and language for the finished written product
  • MISP, OpenCTI — structured storage, correlation, and sharing platforms
  • STIX 2.1 — the object and relationship model for interchange
  • crt.sh — certificate transparency search for infrastructure pivoting
  • Shodan, Censys — internet-wide service, banner, JARM, and favicon search
  • GreyNoise — separating internet background noise from targeted activity
  • VirusTotal — detection, relationship, and enrichment context

© trilwu, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in secskills-defense/skills/producing-threat-intelligence of trilwu/secskills.

Open the folder on GitHubat commit ca53957

Compare with similar skills

Producing Threat Intelligence next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Producing Threat Intelligence compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Producing Threat Intelligence this skilltrilwu/secskills157—~4.4kAutomated safety check: PassMIT
Osint Methodologyelementalsouls/Claude-OSINT2.8k—~8.7kAutomated safety check: NotesMIT
Analysing Attacktsale/awesome-dfir-skills323—~1.4kAutomated safety check: PassApache-2.0
Implementing Attack Surface Managementmukul975/Anthropic-Cybersecurity-Skills34k—~1.8kAutomated safety check: PassApache-2.0
Recon Osinthypnguyen1209/offensive-claude388—~2.2kAutomated safety check: PassMIT
Wiki ReconEncod3d-Sec/TORCH329—~1.3kAutomated safety check: PassMIT

Similar skills

  • Osint Methodology

    elementalsouls/Claude-OSINT

    Comprehensive OSINT methodology for external red-team operations and authorized attack-surface assessments.

    2.8k GitHub stars~8.7k tokensUpdated 1 mo ago
    SecurityAuto-check: notes
  • Analysing Attack

    tsale/awesome-dfir-skills

    Analyse Mitre ATT&CK tactics, techniques and sub-techniques.

    323 GitHub stars~1.4k tokensUpdated 4 mo ago
    SecurityAuto-check passed
  • Implementing Attack Surface Management

    mukul975/Anthropic-Cybersecurity-Skills

    Implements external attack surface management (EASM) using Shodan, Censys, and ProjectDiscovery tools (subfinder, httpx, nuclei) for asset discovery, subdomain enumeration, service fingerprinting…

    34k GitHub stars~1.8k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Recon Osint

    hypnguyen1209/offensive-claude

    A skill your agent uses when mapping a target's external attack surface or gathering OSINT — subdomain enumeration, attack-surface mapping (httpx/katana/JS secrets), subdomain takeover…

    388 GitHub stars~2.2k tokensUpdated 12 days ago
    SecurityAuto-check passed
  • Wiki Recon

    Encod3d-Sec/TORCH

    External recon and OSINT pipeline - subdomain enum, live host discovery, URL crawl, JS analysis, nuclei scan.

    329 GitHub stars~1.3k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Hardens code against vulnerabilities. An agent skill from penpot/penpot.

    61k GitHub starsUsed in 6 repos~4.7k tokens
    SecurityAuto-check: notes

More from trilwu/secskills

All 50 skills in this repo
  • Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis.

    157 GitHub stars~3.2k tokensUpdated 1 mo ago
    Auto-check passed
  • Perform OSINT, subdomain enumeration, port scanning, web reconnaissance, email harvesting, and cloud asset discovery for initial access.

    157 GitHub stars~3.1k tokensUpdated 1 mo ago
    Auto-check: notes
  • Securing AI Systems

    trilwu/secskills

    Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP…

    157 GitHub stars~2.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyzing Binaries

    trilwu/secskills

    Reverse engineer compiled binaries, firmware, and mobile app packages using triage, static disassembly, decompilation, and dynamic instrumentation.

    157 GitHub stars~2.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyzing Go Binaries

    trilwu/secskills

    Reverse engineer Go binaries by recovering function names and types from pclntab and moduledata using GoReSym, redress, and IDA/Ghidra Go plugins, and by reading Go's non-standard calling…

    157 GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyzing iOS Binaries

    trilwu/secskills

    Analyze iOS applications at the binary level — decrypting FairPlay-protected IPAs with frida-ios-dump or bagbak, inspecting Mach-O load commands, recovering Objective-C headers with class-dump, and…

    157 GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Producing Threat Intelligence

What does Producing Threat Intelligence do?

Produce cyber threat intelligence by pivoting on indicators to find related infrastructure, tracking actors and campaigns, enriching and contextualizing IOCs, applying attribution discipline and…. Producing Threat Intelligence is an agent skill from trilwu/secskills. Produce cyber threat intelligence by pivoting on indicators to find related infrastructure, tracking actors and campaigns, enriching and contextualizing IOCs, applying attribution discipline and analytic confidence, and packaging finished intel products tied to a consumer's decision.

When should I use Producing Threat Intelligence?

Producing Threat Intelligence fits situations like: pivoting from a domain; certificate to related infrastructure; tracking a threat actor; enriching raw indicators.

How do I install Producing Threat Intelligence in Claude Code?

Run `npx skills add trilwu/secskills --skill producing-threat-intelligence -a claude-code`. Or copy the skill folder (secskills-defense/skills/producing-threat-intelligence in trilwu/secskills) into .claude/skills/producing-threat-intelligence in your project. Claude Code loads it when a task matches its description.

How do I install Producing Threat Intelligence in Codex?

Run `npx skills add trilwu/secskills --skill producing-threat-intelligence -a codex`. Or copy the skill folder (secskills-defense/skills/producing-threat-intelligence in trilwu/secskills) into .agents/skills/producing-threat-intelligence in your project. Codex loads it when a task matches its description.

Can I use Producing Threat Intelligence in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trilwu/secskills --skill producing-threat-intelligence -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/producing-threat-intelligence, .gemini/skills/producing-threat-intelligence, .github/skills/producing-threat-intelligence and .opencode/skills/producing-threat-intelligence in your project.

What does Producing Threat Intelligence need to run?

Going by SKILL.md and its folder, Producing Threat Intelligence needs the command-line tools its instructions call (curl and jq).

Does Producing Threat Intelligence access the network?

SKILL.md names 2 domains. In commands or code: crt.sh and defuddle.md; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Producing Threat Intelligence safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Producing Threat Intelligence use?

Producing Threat Intelligence is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Producing Threat Intelligence use?

About 4.4k tokens (SKILL.md is roughly 17k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Producing Threat Intelligence?

Skills that share tags, products or a category with Producing Threat Intelligence: Osint Methodology (elementalsouls/Claude-OSINT, 2.8k stars), Analysing Attack (tsale/awesome-dfir-skills, 323 stars), Implementing Attack Surface Management (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Recon Osint (hypnguyen1209/offensive-claude, 388 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Producing Threat Intelligence?

trilwu (a GitHub user) maintains it in trilwu/secskills, which has 157 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on September 4, 2026.

Source: trilwu/secskills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.