CtrlK
BlogDocsLog inGet started
Tessl Logo

building-threat-actor-profile-from-osint

Build threat actor profiles by collecting OSINT from vendor reports, paste sites, dark web forums, social media, and code repos, correlating indicators, mapping adversary infrastructure with tools like Maltego and SpiderFoot, and producing structured dossiers of motivations, capabilities, infrastructure, and TTPs. Use when performing attribution or building an adversary dossier from open-source intelligence.

66

Quality

83%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Low

Low-risk findings worth noting

SKILL.md
Quality
Evals
Security

Quality

Content

63%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body delivers a well-sequenced, mostly executable five-step workflow with real API/STIX/ATT&CK code and a validation checklist, but it is dragged down by boilerplate sections, a non-functional correlation function, an OTX endpoint inconsistent with its own bundle reference, and complete failure to link the bundled references/api-reference.md and scripts/agent.py.

Suggestions

Link the existing bundle files from the body (e.g., under References: "OTX/ATT&CK API details: see references/api-reference.md; full collector script: scripts/agent.py") and move the inline API/tactic tables and endpoint details there to resolve the OTX URL contradiction and shrink SKILL.md.

Fix or remove Step 4's correlate_infrastructure — it initializes ip_to_domains/domain_to_ips but never populates them, so shared_ips is always empty; either implement the correlation or drop the dead logic. Also add attackcti to Prerequisites.

Cut the generic "When to Use" boilerplate ("When deploying or configuring building threat actor profile from osint capabilities..."), the description-duplicating Overview, and the Known-concepts recitation in Key Concepts; replace the hardcoded APT29 prose with a short placeholder.

DimensionReasoningScore

Conciseness

Mostly efficient — the bulk is domain-specific executable code that earns its tokens — but several sections pad it: the Overview restates the frontmatter description, "When to Use" is auto-generated boilerplate ("When deploying or configuring building threat actor profile from osint capabilities in your environment"), "Key Concepts" recites frameworks Claude already knows (Diamond Model, ACH), and Step 2 embeds a large hardcoded APT29 prose description as sample data. Not 2 because the padding is a minority of the content and the code blocks themselves are not verbose; not 4 because the boilerplate and dead code (Step 4's never-populated sets) are clearly trimmable.

3 / 5

Actionability

Four of the five workflow steps give concrete, largely executable code (real OTX/VirusTotal/Shodan requests, STIX 2.1 object construction, attackcti TTP extraction, dossier generation), which meets "mostly executable guidance with minor gaps". The gaps: Step 4's correlate_infrastructure initializes ip_to_domains/domain_to_ips but never adds members, so shared_ips is always empty (dead logic for the core correlation claim); the OTX URL ("/api/v1/search/pulses") conflicts with the bundled api-reference.md ("/api/v1/pulses/search"); and the attackcti dependency used in Step 3 is absent from Prerequisites. Not 3 because the majority of code is genuinely copy-paste runnable; not 5 because these are real defects a user would hit.

4 / 5

Workflow Clarity

A clearly sequenced five-step pipeline (collect → structure in STIX → map TTPs → correlate infrastructure → generate dossier) with a terminal "Validation Criteria" checklist (6 explicit criteria). Not 5 because there are no per-step validation checkpoints or error-recovery loops — API calls silently return on non-200, no rate-limit/failure handling — so checkpoints are end-loaded rather than inline. Not 3 because the sequence is explicit, each step names its inputs/outputs, and a concrete validation checklist does exist (well above "checkpoints missing or implicit"). No destructive/batch cap applies.

4 / 5

Progressive Disclosure

The bundle contains references/api-reference.md and scripts/agent.py, but the SKILL.md body never signals either — the "References" section lists only external URLs, so the bundle files are orphaned and the api-reference content (OTX endpoints, ATT&CK tactic IDs) is instead partially duplicated inline (with a conflicting OTX URL). Structure itself is decent (## sections, numbered steps), matching "some structure but references present but not clearly signaled; content that should be separate is inline". Not 2 because the body is well-sectioned, not an unstructured wall; not 4 because zero of the provided bundle files are navigable from the body.

3 / 5

Total

14

/

20

Passed

Description

96%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: concrete, multi-action capability statement with named tools, an explicit "Use when..." trigger clause with natural synonyms, and a clearly demarcated niche. The only minor weakness is that broad OSINT-collection phrasing slightly overlaps with generic OSINT/recon skills.

DimensionReasoningScore

Specificity

The description enumerates multiple concrete actions with named tools and outputs: "collecting OSINT from vendor reports, paste sites, dark web forums, social media, and code repos", "correlating indicators", "mapping adversary infrastructure with tools like Maltego and SpiderFoot", and "producing structured dossiers of motivations, capabilities, infrastructure, and TTPs". It matches the anchor for multiple specific concrete actions with comprehensive coverage, and uses third-person/infinitive verb voice throughout.

5 / 5

Completeness

It explicitly answers "what" (collect from named source types, correlate indicators, map infrastructure with Maltego/SpiderFoot, produce structured dossiers) and "when" with a concrete trigger clause: "Use when performing attribution or building an adversary dossier from open-source intelligence." This matches the anchor for clearly answering both what AND when with concrete trigger phrases.

5 / 5

Trigger Term Quality

Natural trigger phrases a user would say are comprehensively covered: "threat actor profiles", "OSINT", "attribution", "adversary dossier", "open-source intelligence", plus tool names ("Maltego", "SpiderFoot") and "TTPs". Synonyms for both the activity (profiling/attribution/dossier) and the method are present; no file extensions are relevant to this domain.

5 / 5

Distinctiveness Conflict Risk

The attribution/dossier framing and tool names (Maltego, SpiderFoot) establish a clear niche distinct from adjacent threat-intel or defensive skills, but the broad OSINT collection scope ("social media, and code repos") leaves minor overlap risk with a general OSINT/reconnaissance skill. It sits between "mostly distinct; minor overlap risk" and "clear niche with minimal conflict risk" — not 5 because generic OSINT-collection triggers could pull it in for non-attribution recon tasks, and well above 3 because the dossier/attribution triggers are unambiguous.

4 / 5

Total

19

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
mukul975/Anthropic-Cybersecurity-Skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.