CtrlK
BlogDocsLog inGet started
Tessl Logo

building-threat-intelligence-enrichment-in-splunk

Build automated IOC enrichment pipelines in Splunk Enterprise Security by ingesting threat feeds into KV Store collections and correlating them against security events via lookup tables, modular inputs, and the Threat Intelligence Framework. Use when wiring threat intel into Splunk correlation searches to flag IOC matches and cut SOC triage time.

63

Quality

79%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Low

Low-risk findings worth noting

Fix and improve this skill with Tessl

tessl review fix ./skills/building-threat-intelligence-enrichment-in-splunk/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

57%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

Technically rich and largely copy-paste executable, with a sensible source-to-detection progression. The main weaknesses are the complete absence of validation/verification steps for the batch ingestion pipeline and a progressive-disclosure failure: the skill ships reference, script, and asset files that the body never points to, while inlining material that belongs there.

Suggestions

Add pointers to the existing bundle files in the body (e.g., 'Full KV Store REST API details: see references/api-reference.md', 'Feed standards (STIX/TAXII/OpenIOC): see references/standards.md', 'End-to-end integration workflow: see references/workflows.md') so the detailed material is discoverable.

Insert validation checkpoints into the pipeline: after configuring a feed, verify ingestion with '| inputlookup ip_threat_intel_lookup | stats count' before enabling correlation searches, and show how to test a correlation search manually before scheduling it.

Trim the Overview paragraph and the four generic 'When to Use' bullets, and reconcile the OTX script's output fields with the KV Store collection schema (or add the transforms/field-mapping step that connects them).

DimensionReasoningScore

Conciseness

The body is mostly efficient config/SPL blocks, but the Overview paragraph re-explains what Splunk's Threat Intelligence Framework does and the four 'When to Use' bullets are generic boilerplate ('When deploying or configuring building threat intelligence enrichment in splunk capabilities in your environment') that could be trimmed.

3 / 5

Actionability

Mostly executable guidance: complete inputs.conf/collections.conf/transforms.conf stanzas, a full OTX modular-input Python script, and runnable SPL. Minor gaps remain — the OTX script's output fields ('indicator', 'type') never map to the KV Store collection fields ('ip', 'threat_type'), and asset_lookup/geo_ip_lookup/whois_lookup are used without definition.

4 / 5

Workflow Clarity

The architecture diagram and section ordering imply a sequence (sources -> collections/lookups -> correlation -> dashboards), but there are no validation checkpoints — no inputlookup verification that feeds populated KV Store, no test-before-enable step for correlation searches. Feed ingestion is a batch operation, so the rubric caps this at 3.

3 / 5

Progressive Disclosure

The body has clear sections, but none of the bundle files (references/api-reference.md, references/standards.md, references/workflows.md, scripts/agent.py, scripts/process.py, assets/template.md) are referenced anywhere — the References section lists only external URLs. The detailed material is undiscoverable and content that belongs in those files is inlined.

3 / 5

Total

13

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: concrete, multi-action capability statement paired with an explicit 'Use when' trigger clause and a distinct Splunk ES niche. Only minor keyword variants are missing, keeping trigger term quality just below perfect.

DimensionReasoningScore

Specificity

The description lists multiple concrete actions — 'ingesting threat feeds into KV Store collections', 'correlating them against security events via lookup tables, modular inputs, and the Threat Intelligence Framework' — giving comprehensive coverage of the pipeline steps rather than a minor-gap list.

5 / 5

Completeness

It explicitly answers both: the 'what' (build IOC enrichment pipelines by ingesting feeds into KV Store and correlating via lookups) and the 'when' ('Use when wiring threat intel into Splunk correlation searches to flag IOC matches and cut SOC triage time').

5 / 5

Trigger Term Quality

Good natural keyword coverage ('Splunk Enterprise Security', 'threat intel', 'IOC', 'correlation searches', 'SOC triage'), but a few plausible user terms like 'SIEM', the spelled-out 'indicator of compromise', or common feed names (MISP, OTX) are absent.

4 / 5

Distinctiveness Conflict Risk

It carves out a clear niche — Splunk Enterprise Security threat-intelligence enrichment via KV Store lookups — with trigger terms that would not plausibly fire for unrelated skills.

5 / 5

Total

19

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
mukul975/Anthropic-Cybersecurity-Skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.