CtrlK
BlogDocsLog inGet started
Tessl Logo

building-threat-intelligence-feed-integration

Builds automated threat intelligence feed integration pipelines connecting STIX/TAXII feeds, open-source threat intel, and commercial TI platforms into SIEM and security tools for real-time IOC matching and alerting. Use when SOC teams need to operationalize threat intelligence by automating feed ingestion, normalization, scoring, and distribution to detection systems.

61

Quality

77%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Low

Low-risk findings worth noting

Fix and improve this skill with Tessl

tessl review fix ./skills/building-threat-intelligence-feed-integration/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

57%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The skill delivers a clear, mostly executable six-step pipeline with real feeds and real APIs, but it pads token budget with a Key Concepts/Tools glossary of things Claude already knows, omits validation checkpoints for its batch SIEM/MISP pushes, and — most notably — never links its own bundle files (references/api-reference.md, scripts/agent.py), leaving a scripts/ implementation undiscoverable.

Suggestions

Add a navigation section linking the existing bundle files (e.g., "Full implementation: scripts/agent.py; API details: references/api-reference.md") so the SKILL.md body acts as an overview rather than inlining all six code examples.

Add validation checkpoints around the batch SIEM/MISP pushes in Step 5 — check HTTP response codes, confirm IOC counts landed, and define the fix-and-retry path for failed pushes.

Remove or drastically trim the "Key Concepts" and "Tools & Systems" sections, which define STIX/TAXII/MISP/OTX concepts Claude already knows.

DimensionReasoningScore

Conciseness

The workflow steps and code are dense and useful, but the "Key Concepts" table (defining STIX 2.1, TAXII, TIP) and the "Tools & Systems" section re-explain concepts and platforms Claude already knows. This matches the anchor "mostly efficient but includes some unnecessary explanation or could be tightened" rather than score 4, where over-explanation would be only minor.

3 / 5

Actionability

Six concrete, near-executable code blocks (TAXII 2.1 ingestion, URLhaus, OTX pulses, Feodo, STIX normalization/dedup, Splunk and MISP pushes) cover the common cases with real endpoints and parameters. Minor gaps keep it below fully copy-paste ready: `all_collected_iocs` is never defined, `os`/`splunk_token` are missing in Step 5, and `indicator.get("x_source_feed")` treats STIX objects as dicts.

4 / 5

Workflow Clarity

The six-step sequence is clearly ordered and easy to follow, but bulk IOC pushes to SIEM/MISP are batch operations with no validation checkpoints: no response checking, error handling, retry guidance, or confirmation that pushes succeeded. Per the rubric's cap, a batch workflow without validation cannot score above 3 even though the sequence itself is clear.

3 / 5

Progressive Disclosure

The body is well-sectioned, but the actual bundle is ignored: `references/api-reference.md` and `scripts/agent.py` exist yet are never mentioned or linked anywhere in the body, and the six full ingestion code examples inline content that partly belongs in those files. This fits "references present but not clearly signaled" (score 3); it is above score 2 because the document itself has clear structure and headers, not a monolithic wall.

3 / 5

Total

13

/

20

Passed

Description

88%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: third-person voice, concrete multi-action capability statement, and an explicit "Use when" trigger clause aimed at SOC teams. Trigger keyword coverage is good with a few natural synonyms missing, and the broad "SIEM and security tools" phrasing introduces only minor conflict risk.

Suggestions

Add one or two natural trigger synonyms users actually say, such as "MISP", "threat feeds", or "IOC enrichment", to strengthen trigger matching.

Narrow the tail phrase "into SIEM and security tools" to named targets (e.g., "into Splunk, Elastic, or Sentinel") to reduce overlap with generic SIEM-administration skills.

DimensionReasoningScore

Specificity

"Builds automated threat intelligence feed integration pipelines connecting STIX/TAXII feeds... into SIEM and security tools for real-time IOC matching and alerting" plus "automating feed ingestion, normalization, scoring, and distribution" lists multiple specific concrete actions with comprehensive coverage of the pipeline lifecycle. It exceeds the score-4 anchor (which allows minor coverage gaps) and contains no vague filler.

5 / 5

Completeness

It explicitly answers both questions: the "what" is "builds automated... pipelines connecting STIX/TAXII feeds... into SIEM... for real-time IOC matching and alerting", and the "when" is the explicit trigger clause "Use when SOC teams need to operationalize threat intelligence by automating feed ingestion, normalization, scoring, and distribution to detection systems".

5 / 5

Trigger Term Quality

Natural terms are well covered — "threat intelligence feed", "STIX/TAXII", "SIEM", "IOC matching", "SOC" — including the synonym pair "threat intel"/"threat intelligence". A few natural phrases users would say are missing (e.g., MISP, "threat feeds", IOC enrichment), which keeps it just below the comprehensive score-5 anchor.

4 / 5

Distinctiveness Conflict Risk

The STIX/TAXII feed-pipeline niche is clearly distinguishable from adjacent skills, but the broad tail "into SIEM and security tools" leaves minor overlap risk with generic SIEM-configuration or SOC-automation skills. It is more distinctive than the score-3 anchor but does not fully meet the minimal-conflict bar of score 5.

4 / 5

Total

18

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
mukul975/Anthropic-Cybersecurity-Skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.