CTI Expert

A cyber threat intelligence and OSINT skill: structured investigations, domain and breach recon, analyst-grade reports

Skill

High risk

We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.

Why this level

  • A recon and OSINT tool: use only on your own assets or with explicit authorization, not against others' resources or people
  • It runs Python, installs tools and reaches many external services
All reasons and checks

7onez/cti-expert

Install

In your terminal, with SkillFoxx CLI

npx skillfoxx add skills/cti-expert

Detects the agents on your machine, checks the risk and pins the version.

Other ways to install

Run in a terminal in the project folder

npx skills add 7onez/cti-expert --skill cti-expert -a claude-code -y

The skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.

Run in a terminal in the project folder

npx skills add 7onez/cti-expert --skill cti-expert -a cursor -y

The skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.

Run in a terminal in the project folder

npx skills add 7onez/cti-expert --skill cti-expert -a github-copilot -y

The skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.

Run in a terminal in the project folder

npx skills add 7onez/cti-expert --skill cti-expert -a codex -y

The skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.

Run in a terminal in the project folder

npx skills add 7onez/cti-expert --skill cti-expert -a gemini-cli -y

The skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.

Run in a terminal in the project folder

npx skills add 7onez/cti-expert --skill cti-expert -a cline -y

The skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.

Run in a terminal in the project folder

npx skills add 7onez/cti-expert --skill cti-expert -a roo -y

The skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.

A fork of Roo Code, same .roo folders.

Run in a terminal in the project folder

npx skills add 7onez/cti-expert --skill cti-expert -a opencode -y

The skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.

You will need: Node.js

Checked against the repository on Sep 25, 2026, commit e05f986.

Text for your agent

Install as a plugin: /plugin marketplace add 7onez/cti-expert, then /plugin install cti-expert. Run it only in an environment with a real local shell and network.

Other ways from the author
/plugin marketplace add 7onez/cti-expert
/plugin install cti-expert

Installs the skill with commands, MCP tools and hooks.

This is third-party code. Review the repository files before installing.

What it does

The skill turns the agent into a cyber threat intelligence and OSINT analyst with a clear working cycle. It builds precise search queries, runs a case through collection and enrichment phases and recursively expands discovered identifiers into a link graph. The set covers domain, subdomain, DNS and certificate recon, infrastructure pivoting, enumeration by name, email and phone, breach and log triage, image forensics and geolocation. Results are shaped into structured reports with cited sources and trust scoring. The core works without keys or paid subscriptions, while separate connectors add external services.

Who it is for. For security and investigation specialists who run authorized OSINT and threat analysis.

Good fit when

  • You run an authorized investigation of a domain, infrastructure or incident
  • You need to review your own organization's digital footprint and exposure
  • You need a structured report with sources and trust scoring

Not a fit when

  • You have no authorization to investigate the target: use it only on your own assets or with the owner's permission
  • The goal is stalking a person or collecting data without a lawful basis
  • You need substantive fact-checking rather than recon of footprint and traces

Example request

Review my domain's external exposure and compile a report on subdomains and certificates

Limitations

The skill is execution-heavy: it runs Python via uv, installs OSINT tools, writes reports in several formats and reaches many external sites, so it needs a real local shell with network access, not an ephemeral cloud sandbox. Some connectors and services require their own keys, and the reachability of external sources from your network is worth checking. The tool provides material for analysis; legal and ethical responsibility for its use stays with the operator.

How to disable. Uninstall the plugin via /plugin or remove the cti-expert folder from your agent's skills directory. Disable the added hooks in client settings.

Security check

  • A recon and OSINT tool: use only on your own assets or with explicit authorization, not against others' resources or people
  • It runs Python, installs tools and reaches many external services

README in short

The README describes CTI Expert as a cyber threat intelligence and OSINT skill for Claude Code and Codex that runs a case lifecycle with collection and enrichment phases. It lists dozens of commands and techniques, recursive pivoting on discovered identifiers and reports built to analytic standards with cited sources. The core needs no keys, while separate connectors add external services. It has safeguards: hooks that fail open and confirmation rules for sensitive actions. It installs as a plugin via a marketplace or by cloning into the skills directory.

SKILL.md

---
name: cti-expert
description: "Cyber threat intelligence and OSINT analysis toolkit. Runs structured investigations and delivers analyst-grade intelligence products with sourced, trust-scored findings. Use for OSINT and CTI cases, digital-footprint and exposure review, domain/subdomain/DNS/certificate recon, web-infrastructure pivoting, username/email/phone enumeration, breach and infostealer-log triage, image forensics, geolocation, and structured reporting."
version: "2.12"
author: "Hieu Ngo - chongluadao.vn"
---

# CTI Expert

Cyber threat intelligence and open-source intelligence skill. Turns Claude into a trained CTI/OSINT analyst. Generates precision search queries, interprets public data, builds case timelines, and delivers structured intelligence products, no API keys, no paid subscriptions.

> Runs anywhere. Works in Claude Code (Desktop and CLI) and in OpenAI Codex / ChatGPT and other AGENTS.md-aware agents. Throughout this file, $SKILL_DIR is the directory containing this SKILL.md. Resolve it by locating SKILL.md, never hard-assume ~/.claude.

## 1. Quick Start

```bash
/case target.com
/flow person
/brief
```

## 2. AEAD Case Lifecycle

Every investigation follows four phases: Acquire, Enrich, Analyze, Deliver. Acquire and Enrich iterate, not run once.

FAQ

Are paid APIs required?

Core commands work without keys or subscriptions. Separate connectors add external services that have their own keys and limits.

Where should it run?

The author recommends a CLI or a local desktop agent with a real shell and open network; an ephemeral cloud sandbox does not fit.

Editors’ pick

A code security audit skill by Cloudflare: the agent runs recon, coverage-led hunting and independent verification of findings, then produces a structured repor

SkillMedium riskNo VPN needed22.6KRepository stars
Editors’ pick

NVIDIA's open stack for running OpenClaw, Hermes and LangChain Deep Agents in OpenShell sandboxes with network policy and managed inference

CLIHigh risk22.6KRepository stars
Editors’ pick

Security scanner for agent skills and MCP servers: finds prompt injection, data exfiltration and supply chain risks before install

CLIMedium riskNo VPN needed18.5KRepository stars
Official

Static code analysis with rules that look like source code, plus a built-in MCP server for AI agents

CLIMedium risk16.8KRepository stars
Foxx AICTI Expert

I am Foxx AI and I have already vetted this tool. Ask about install, setup or anything else, and I will keep it simple.