AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified MIT Self-run

Cti Domain Research

skill-security-phoenix-demo-security-skills-claude-code-cti-search-skill · by Security-Phoenix-demo

>

No reviews yet
0 installs
14 views
0.0% view→install

Install

$ agentstack add skill-security-phoenix-demo-security-skills-claude-code-cti-search-skill

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets Used
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-security-phoenix-demo-security-skills-claude-code-cti-search-skill)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
3mo ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Cti Domain Research? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

CTI Domain Research

Structured threat intelligence search across 300+ curated security domains with optional NotebookLM ingestion.


Customization

Configure these settings to personalize your CTI research workflow. All are optional — the skill works with sensible defaults.

| Setting | Description | Default | How to Set | |---------|-------------|---------|------------| | Search provider | Which search API to use | Brave Search | SEARCH_PROVIDER=brave in .env | | Brave API key | Your Brave Search API key | — (required) | BRAVE_SEARCH_API_KEY=... in .env | | SerpAPI key | Alternative search provider | — | SERPAPI_KEY=... in .env | | Google CSE key + ID | Alternative search provider | — | GOOGLE_CSE_KEY=... + GOOGLE_CSE_ID=... in .env | | NotebookLM notebook ID | Target notebook for --notebooklm flag | — | NOTEBOOKLM_NOTEBOOK_ID=... in .env or --notebook-id flag | | Default result count | Results per tier | 10 | --count N flag per query | | Default recency | How far back to search | 90 days | --since DAYS flag per query | | Custom domains | Add your own security sources | 595 built-in | Edit data/domains.txt and data/tier-map.json |

Setup steps:

  1. Copy .env.example to .env in the plugin directory
  2. Add your search API key (Brave recommended — 2,000 free requests/month)
  3. Optionally set your NotebookLM notebook ID
  4. Restart Claude Code
cd ~/.claude/plugins/cti-search-plugin
cp .env.example .env
# Edit .env with your API keys

Adding custom domains:

# Add a domain (one per line)
echo "your-security-blog.com" >> data/domains.txt

# Add tier mapping
# Edit data/tier-map.json and add:
# "your-security-blog.com": { "tier": 3, "authority": 70 }

Workflow

1. Parse query + flags
2. Select domain tier(s) based on query type
3. Execute scoped web searches (site: operator per domain batch)
4. Deduplicate + rank results by recency and source authority
5. Extract: title, source, date, summary, key IOCs/TTPs/CVEs mentioned
6. [Optional] Push findings to NotebookLM via connector plugin
7. Return structured CTI brief

Query Parsing

Accept free-text queries. Extract:

  • Subject: CVE ID, actor name, malware family, technique (MITRE ATT&CK), product name
  • Time filter: default = last 90 days; honour "last week / month / year" if stated
  • Depth: default = top 10 results; --count N overrides
  • Output format: default = brief table + bullets; --full = long-form brief; --json = raw JSON
  • NotebookLM push: --notebooklm flag triggers the connector (see NotebookLM section below)

Domain Tiers

Load the full domain list from references/domains.txt. Apply tier routing:

| Tier | When to use | Examples | |------|-------------|---------| | Tier 1 — Authoritative | CVEs, advisories, govt alerts | cisa.gov, nvd.nist.gov, msrc.microsoft.com, access.redhat.com, support.apple.com, cert.europa.eu, ncsc.gov.uk | | Tier 2 — Vendor Research | Deep technical analysis | unit42.paloaltonetworks.com, blog.talosintelligence.com, securelist.com, research.checkpoint.com, thedfirreport.com, blog.google, mandiant.com, secureworks.com, sentinelone.com, crowdstrike.com | | Tier 3 — News + Community | Situational awareness | bleepingcomputer.com, krebsonsecurity.com, therecord.media, thehackernews.com, arstechnica.com, reddit.com/r/cybersecurity, news.ycombinator.com | | Tier 4 — Specialised | Malware, PoC, OSINT | any.run, otx.alienvault.com, vulncheck.com, attackerkb.com, greynoise.io, hunt.io, packetstormsecurity.com |

Routing logic:

  • CVE query → Tier 1 first, then Tier 2
  • Threat actor / malware → Tier 2 first, then Tier 4
  • Situational / news → Tier 3 first, then Tier 2
  • PoC / exploit → Tier 4 + Tier 2
  • General → all tiers, ranked by authority score

Search Execution

Use the web search tool with site: scoping. Batch domains to maximise coverage per call:

# Example batch query construction
query = f'"{subject}" site:bleepingcomputer.com OR site:krebsonsecurity.com OR site:therecord.media'

# For CVEs, always include NVD and MSRC
query = f'{cve_id} site:nvd.nist.gov OR site:msrc.microsoft.com OR site:cisa.gov'

Run multiple searches in parallel when --full is specified:

  1. Tier 1 batch
  2. Tier 2 batch
  3. Tier 3 + 4 batch

Result Schema

For each result, extract:

{
  "title": "...",
  "source": "domain.com",
  "url": "https://...",
  "published": "YYYY-MM-DD",
  "authority_tier": 1,
  "summary": "1-2 sentence distillation",
  "tags": ["CVE-XXXX", "ransomware", "RCE", "MITRE:T1190"],
  "iocs": ["hash", "IP", "domain"],
  "severity": "Critical|High|Medium|Low|Info"
}

Output Formats

Default — CTI Brief (table + bullets)

## CTI Brief:  — 

### Key Findings
- [Critical]  —  ()
- [High] ...

### Source Table
| Source | Title | Date | Tags |
|--------|-------|------|------|
| bleepingcomputer.com | ... | ... | ransomware, RCE |

### IOC Summary
IPs: ...  Hashes: ...  Domains: ...

### Next Steps
- Patch priority: ...
- Detection: MITRE T-IDs to hunt
- Intel gaps: ...

--full — Long-Form Brief

Add: executive summary, per-source analysis paragraphs, MITRE ATT&CK mapping table, recommended detection rules (Sigma header stubs).

--json

Return raw JSON array of result objects (schema above).


NotebookLM Integration

When --notebooklm flag is set, use the NotebookLM connector plugin to ingest findings.

Plugin location (Claude Code): ~/.claude/plugins/notebooklm-connector/ Plugin repo: https://github.com/Security-Phoenix-demo/security-skills-claude-code/tree/main/plugins/notebooklm-connector

Connector flow:

1. Collect all result URLs from the search phase
2. Format as source list per plugin spec
3. Call connector to add sources to target NotebookLM notebook
4. Report: N sources added, notebook URL

Plugin call pattern (Claude Code):

# Check connector is installed
ls ~/.claude/plugins/notebooklm-connector/

# Call connector with source list
node ~/.claude/plugins/notebooklm-connector/index.js \
  --notebook-id "$NOTEBOOKLM_NOTEBOOK_ID" \
  --sources "$(echo $URLS | jq -R -s 'split("\n")')" \
  --title "CTI: $QUERY — $(date +%Y-%m-%d)"

Required env var:

export NOTEBOOKLM_NOTEBOOK_ID=""
# Or pass via --notebook-id flag at query time

Fallback (Claude.ai — no plugin runtime):

If running in Claude.ai (no bash), present a formatted source list the user can manually add to NotebookLM, plus a direct link to their notebook if the ID is known.


Slash Command (Claude Code)

Install by creating ~/.claude/commands/cti-search.md:

---
description: "Search 300+ security domains for CTI on any topic, CVE, actor, or malware"
argument-hint: " [--count N] [--full] [--json] [--notebooklm] [--notebook-id ID]"
allowed-tools: WebSearch, Bash
---

Search curated security domains for threat intelligence on: $ARGUMENTS

Follow the CTI Domain Research skill (cti-domain-research) exactly.
Domain list: ~/.claude/commands/cti-domains.txt

Flags:
- --count N        : Return N results (default 10)
- --full           : Long-form brief with MITRE mapping
- --json           : Raw JSON output
- --notebooklm     : Push sources to NotebookLM after search
- --notebook-id ID : Target notebook ID (overrides env var)
- --tier 1|2|3|4   : Restrict to specific domain tier
- --since DAYS     : Limit to last N days (default 90)

Installation Script

Run scripts/install.sh to:

  1. Copy slash command to ~/.claude/commands/
  2. Copy domain list to ~/.claude/commands/cti-domains.txt
  3. Verify NotebookLM connector plugin presence
  4. Print setup confirmation

See scripts/install.sh for full details.


Error Handling

| Condition | Behaviour | |-----------|-----------| | No results for domain batch | Skip tier, try next; warn if all tiers empty | | NotebookLM connector not installed | Warn + fallback to manual source list | | Rate limited on search | Back off 2s, retry once; surface partial results | | Query too broad (>1000 potential results) | Auto-narrow to Tier 1+2 only, suggest refinement | | CVE not yet in NVD | Note "CVE may be pre-NVD — check vendor advisories directly" |


Reference Files

  • references/domains.txt — Full curated domain list (300+ sources, one per line)
  • references/tier-map.json — Domain → tier + authority score mapping
  • scripts/install.sh — One-shot installer for Claude Code slash command

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.