CtrlK
BlogDocsLog inGet started
Tessl Logo

building-threat-feed-aggregation-with-misp

Deploy MISP via Docker and configure feeds from sources like abuse.ch, AlienVault OTX, and CIRCL to aggregate, correlate, and distribute threat intelligence, including automated feed synchronization and STIX/TAXII-based integration with Splunk, Elasticsearch, and SOAR platforms. Use when standing up centralized IOC management or wiring multi-source threat feeds into a SIEM.

63

Quality

79%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Low

Low-risk findings worth noting

Fix and improve this skill with Tessl

tessl review fix ./skills/building-threat-feed-aggregation-with-misp/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

57%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body delivers concrete, largely executable guidance through a well-sequenced deploy-configure-export workflow. Its main weaknesses are duplicated/generic prose, missing inter-step validation for batch feed operations, and an orphaned bundle (references/api-reference.md and scripts/agent.py) that is never surfaced from SKILL.md.

Suggestions

Add inline validation checkpoints between workflow steps — e.g., after deployment verify the API responds (`curl -H "Authorization: $KEY" https://misp.../feeds/index`) before enabling feeds, and check each feed's fetch result or event count before exporting — turning the end-state Validation Criteria into a feedback loop.

Link the existing bundle files from the body: replace the inlined PyMISP API details with pointers to `references/api-reference.md` for the full feed-source table and configuration fields, and reference `scripts/agent.py` as a ready-made correlation/reporting tool.

Trim the Overview paragraph (it repeats the frontmatter description verbatim) and replace the generic 'When to Use' bullets with MISP-specific triggers, and fix the Step 4 snippet to import `os` and handle HEC error responses.

DimensionReasoningScore

Conciseness

The Overview paragraph duplicates the frontmatter description nearly verbatim ('This skill covers deploying MISP via Docker, configuring feeds from sources like abuse.ch, AlienVault OTX, and CIRCL...'), and the 'When to Use' bullets are generic template filler with awkward phrasing ('When deploying or configuring building threat feed aggregation with misp capabilities in your environment'). This is more than the 'minor instances of over-explanation' of a 4 but the bulk is still efficient working material, fitting the 'mostly efficient but includes some unnecessary explanation or could be tightened' anchor.

3 / 5

Actionability

The body provides a complete docker-compose.yml and mostly executable PyMISP classes covering feed listing, enabling, adding, fetching, searching, and Splunk HEC export — largely copy-paste ready. Minor gaps keep it below fully executable: Step 4 uses `os.environ` without importing `os`, HEC POST responses are counted but errors are never handled, and `MISPFeed()` object construction does not match the PyMISP API used in the bundle's own reference (`misp.add_feed(name=..., provider=..., url=...)`).

4 / 5

Workflow Clarity

Steps 1–4 are clearly sequenced (deploy → configure feeds → search/correlate → export) and a Validation Criteria checklist exists, but checkpoints between steps are absent and there are no error-recovery loops. Enabling and fetching all feeds are batch operations with no verify-success feedback ('Enabled N feeds' prints a count but never checks fetch results), which caps this at 3 per the batch-operation guideline — it fits 'steps listed but validation gaps; checkpoints missing or implicit' rather than the 4 anchor's 'most checkpoints present'.

3 / 5

Progressive Disclosure

The bundle contains `references/api-reference.md` and `scripts/agent.py`, but the body never references or links either — its 'References' section lists only external web URLs while ~150 lines of Python are inlined that overlap the orphaned reference file. This matches 'references present but not clearly signaled; content that should be separate is inline' — the section structure itself is good, so it is above the 'minimal structure' of a 2 but below the clear one-level-deep signaling of a 4.

3 / 5

Total

13

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description that clearly and concisely states both capabilities and explicit 'Use when' triggers, with specific named sources, protocols, and target platforms. Keyword coverage is good but misses a few natural synonyms a user might say.

DimensionReasoningScore

Specificity

The description lists multiple concrete actions with named tools and sources — 'Deploy MISP via Docker and configure feeds from sources like abuse.ch, AlienVault OTX, and CIRCL to aggregate, correlate, and distribute threat intelligence, including automated feed synchronization and STIX/TAXII-based integration with Splunk, Elasticsearch, and SOAR platforms' — covering deployment, configuration, aggregation, correlation, distribution, synchronization, and integration comprehensively with no coverage gaps, matching the anchor for multiple specific concrete actions rather than the 'minor gaps' of a 4.

5 / 5

Completeness

It explicitly answers both questions: the 'what' is concrete (deploy, configure feeds, aggregate/correlate/distribute, synchronize, integrate via STIX/TAXII with named SIEMs) and the 'when' is an explicit trigger clause — 'Use when standing up centralized IOC management or wiring multi-source threat feeds into a SIEM' — matching the anchor that clearly and explicitly answers both with concrete trigger phrases.

5 / 5

Trigger Term Quality

Good natural keyword coverage: 'MISP', 'threat feeds', 'SIEM', 'IOC management', 'Splunk', 'Elasticsearch', 'SOAR', 'STIX/TAXII', 'Docker', 'abuse.ch'. A few natural terms users might say are missing (e.g., 'threat intel', 'indicators of compromise', 'blocklist'), which places it at 'good keyword coverage; a few natural terms missing' rather than the comprehensive synonym coverage of a 5.

4 / 5

Distinctiveness Conflict Risk

The description is anchored to a specific named platform (MISP) with distinct triggers (IOC management, threat feed wiring into a SIEM, abuse.ch/OTX/CIRCL feeds, STIX/TAXII). It occupies a clear niche with minimal conflict risk against other skills, matching the 5 anchor rather than the 'minor overlap with closely related skills' of a 4.

5 / 5

Total

19

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
mukul975/Anthropic-Cybersecurity-Skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.