CtrlK
BlogDocsLog inGet started
Tessl Logo

threat-intelligence

Use for authorized OSINT and cyber threat intelligence that enriches IOCs, campaigns, impersonation, scams, or threat actors from public sources. Includes bounded X/Twitter search through Xquik, source preservation, corroboration, and evidence handoff.

64

Quality

75%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

Fix and improve this skill with Tessl

tessl review fix ./skills/threat-intelligence/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

75%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured, security-aware skill body with a clear multi-stage workflow, concrete commands and templates, validation checkpoints, and a real one-level-deep reference. It sits just below top marks due to minor structural repetition and some procedural rather than fully executable steps.

DimensionReasoningScore

Conciseness

The body is lean and procedural, assuming Claude's competence without explaining what OSINT or IOCs are, though the repeated five-stage '阶段出口' exit blocks add some structural verbosity that could be tightened.

4 / 5

Actionability

It provides executable bootstrap commands (PowerShell and bash), concrete data templates (UNTRUSTED_PUBLIC_SOURCE blocks, E-TI/F-TI/P-TI IDs) and tables, but some workflow steps remain procedural description rather than exact commands.

4 / 5

Workflow Clarity

Five clearly sequenced stages each carry explicit '阶段出口' checkpoints plus a final completion self-check checklist and independent-corroboration validation, satisfying the validation requirement for batch/read-sensitive operations; not a 5 because feedback loops are 'pause and review' rather than strict validate-fix-retry.

4 / 5

Progressive Disclosure

Sections are well organized and the detail layer is offloaded to a single, clearly signaled, one-level-deep reference (`references/x-public-intelligence.md`, verified to exist), though the ~160-line body carries more workflow detail inline than a pure overview.

4 / 5

Total

16

/

20

Passed

Description

75%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, specific description that pairs a clear 'Use for' trigger with a concrete capability list and a distinctive tool anchor (Xquik). It stops just short of the top anchor because the trigger phrasing and keyword synonyms could be more exhaustive.

DimensionReasoningScore

Specificity

The description names the domain and lists several concrete actions — 'enriches IOCs, campaigns, impersonation, scams, or threat actors', 'bounded X/Twitter search through Xquik, source preservation, corroboration, and evidence handoff' — giving comprehensive but slightly abstract coverage rather than fully concrete operations.

4 / 5

Completeness

It answers both 'what' (enrichment, search, preservation, corroboration, handoff) and 'when' via the explicit 'Use for authorized OSINT and cyber threat intelligence' clause, but the trigger conditions could be more explicit with concrete phrasing.

4 / 5

Trigger Term Quality

Natural domain keywords a user would say are well covered — 'OSINT', 'cyber threat intelligence', 'IOCs', 'impersonation', 'scams', 'threat actors', 'X/Twitter' — though a few common synonyms such as 'phishing' or 'malware' are absent.

4 / 5

Distinctiveness Conflict Risk

The niche is clear — authorized public-source OSINT anchored on Xquik/X-Twitter — with minimal conflict risk, though broad 'threat intelligence' framing allows minor overlap with adjacent security skills like threat-hunting.

4 / 5

Total

16

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
zhaoxuya520/reverse-skill
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.