CtrlK
BlogDocsLog inGet started
Tessl Logo

building-ioc-defanging-and-sharing-pipeline

Build an automated pipeline that ingests raw IOCs (URLs, IPs, domains, emails), normalizes and deduplicates them, then produces defanged renderings for safe human reading alongside canonical STIX 2.1 bundles distributed via TAXII servers, MISP, or email reports. Use when preparing indicators of compromise for safe analyst sharing or automating threat intel distribution to TAXII/MISP feeds.

63

Quality

79%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/building-ioc-defanging-and-sharing-pipeline/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

57%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

Executable, well-sequenced code drives the skill, but it is padded with concept explanations Claude already knows, lacks in-workflow validation gates for batch distribution, and ignores its own bundle files. Tightening prose, adding validation checkpoints, and linking the reference/script bundles would lift the weakest dimensions.

Suggestions

Trim the 'Key Concepts' explanations of defanging/normalization/STIX to essentials Claude doesn't already know, and replace the generic 'When to Use' boilerplate with domain-specific triggers.

Add explicit validation checkpoints inside the workflow (e.g., verify extraction counts, validate the STIX bundle with stix2 before, and confirm a dry-run/test event before pushing to production MISP/TAXII feeds) so the batch/distribution path has feedback loops.

Reference the existing bundle files from the body — point detailed defanging rules and regex patterns to references/api-reference.md and the full implementation to scripts/agent.py — instead of inlining that material in 'Key Concepts'.

DimensionReasoningScore

Conciseness

The 'Key Concepts' section explains defanging, normalization, and STIX patterns at length — concepts Claude largely already knows — and 'When to Use' is generic boilerplate, so it is mostly efficient but includes unnecessary explanation that could be tightened.

3 / 5

Actionability

Four largely complete, executable code blocks cover extraction, defanging, STIX conversion, and MISP/TAXII distribution, but minor gaps (Step 4 uses `os` without importing it; `taxii2client` is not listed in prerequisites) keep it just below fully copy-paste ready.

4 / 5

Workflow Clarity

Steps 1–4 are clearly sequenced, but this batch/distribution workflow has no embedded validation checkpoints or feedback loops before pushing to MISP/TAXII feeds — only a post-hoc 'Validation Criteria' list — so the destructive/batch cap of 3 applies.

3 / 5

Progressive Disclosure

Bundle files references/api-reference.md and scripts/agent.py exist but are never referenced from the body, and API-reference material is inlined in 'Key Concepts' duplicating the reference file, so structure is present but references are not signaled and inline content should be split out.

3 / 5

Total

13

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, specific description that clearly conveys both capability and trigger conditions with good domain keyword coverage. Slight room only in colloquial trigger-term variants.

DimensionReasoningScore

Specificity

Lists multiple concrete actions — 'ingests raw IOCs (URLs, IPs, domains, emails)', 'normalizes and deduplicates', 'produces defanged renderings', 'STIX 2.1 bundles distributed via TAXII servers, MISP, or email reports' — with comprehensive coverage, matching the top anchor.

5 / 5

Completeness

Clearly states what the skill does (full ingestion→defang→STIX→distribution pipeline) and gives an explicit 'Use when preparing indicators of compromise... or automating threat intel distribution' trigger clause, satisfying both what and when.

5 / 5

Trigger Term Quality

Strong natural-term coverage ('IOCs', 'defanged', 'STIX 2.1', 'TAXII', 'MISP', 'indicators of compromise', 'threat intel') including synonyms, but a few colloquial variations a user might say are absent, so it sits just below the comprehensive anchor.

4 / 5

Distinctiveness Conflict Risk

The defanging-plus-STIX/TAXII/MISP sharing combination is a clear niche with distinct triggers and minimal overlap risk with generic threat-intel skills.

5 / 5

Total

19

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
mukul975/Anthropic-Cybersecurity-Skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.