CtrlK
BlogDocsLog inGet started
Tessl Logo

building-ioc-enrichment-pipeline-with-opencti

Build an automated IOC enrichment pipeline on OpenCTI (STIX 2.1 native threat intel platform) using its internal enrichment connectors to pull context from VirusTotal, Shodan, AbuseIPDB, and GreyNoise, correlate indicators with known actors/campaigns, and score them for analyst prioritization. Use when deploying OpenCTI or automating enrichment and confidence scoring of newly ingested indicators.

65

Quality

82%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Low

Low-risk findings worth noting

SKILL.md
Quality
Evals
Security

Quality

Content

57%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is concrete and executable with solid domain-specific Key Concepts, but it is token-heavy due to a large inline code block, omits validation checkpoints for batch OpenCTI updates, and fails to signal the bundled reference/script/asset files that accompany it.

Suggestions

Move the ~140-line inline connector into scripts/ and keep only a short excerpt in SKILL.md, linking to the full file, to cut token bloat (conciseness / progressive disclosure).

Add explicit pointers to the existing bundle — references/api-reference.md, standards.md, workflows.md, scripts/process.py, and assets/template.md — which are currently not referenced anywhere in the body (progressive disclosure).

Insert validation checkpoints into the workflow (verify the connector registered, confirm enrichment landed on the observable, dry-run before bulk score/label updates) since bulk enrichment mutates OpenCTI state (workflow_clarity).

DimensionReasoningScore

Conciseness

Mostly efficient, but the ~140-line inline Python connector and generic 'When to Use' boilerplate add bulk, and the inline code overlaps with the orphaned scripts/ files rather than pointing to them.

3 / 5

Actionability

Provides executable docker-compose with pinned image tags and a complete connector example, but the custom connector's docstring promises AbuseIPDB context yet implements only GreyNoise, and it relies on SecurityTrails (not named in the description).

4 / 5

Workflow Clarity

A two-step sequence is present but lacks validation checkpoints; because bulk enrichment updates OpenCTI scores and labels (a batch/state-changing operation), the rubric caps this dimension at 3.

3 / 5

Progressive Disclosure

A real bundle exists (references/, scripts/, assets/) but the body links to none of it, and the large connector code is inlined instead of being referenced from scripts/.

3 / 5

Total

13

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

An excellent description: third-person voice, concrete multi-action scope, named sources, and an explicit 'Use when' clause covering both what and when. No fluff or over-claims.

DimensionReasoningScore

Specificity

Lists multiple concrete actions — build an enrichment pipeline, pull context from four named sources (VirusTotal, Shodan, AbuseIPDB, GreyNoise), correlate with actors/campaigns, and score for prioritization — giving comprehensive coverage.

5 / 5

Completeness

Explicitly answers both what (build/score an enrichment pipeline) and when ('Use when deploying OpenCTI or automating enrichment and confidence scoring of newly ingested indicators') with concrete trigger phrases.

5 / 5

Trigger Term Quality

Includes the natural terms users actually say — 'OpenCTI', 'IOC enrichment', 'threat intel', the four source names, 'indicators', 'confidence scoring' — with strong synonym coverage.

5 / 5

Distinctiveness Conflict Risk

Occupies a clear OpenCTI-specific niche with distinct triggers (OpenCTI, IOC enrichment, named TI sources), minimizing overlap with other skills.

5 / 5

Total

20

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
mukul975/Anthropic-Cybersecurity-Skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.