cti-expert

Conduct structured cyber threat intelligence and OSINT analysis on target entities.

1|Updated May 4, 2026
One-click install
npx skills add https://github.com/auxi-wardrobe/auxi-all-in --skill cti-expert
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cti-expert
Source: https://github.com/auxi-wardrobe/auxi-all-in/tree/main/.agents/skills/cti-expert
Command: npx skills add https://github.com/auxi-wardrobe/auxi-all-in --skill cti-expert

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill requires agentflow-py, fastapi, pydantic, boto3, pandas, and includes scripts (resource) and references (resource) and assets (resource) components.

What problem does it solve?

This Skill transforms Claude into a trained cyber threat intelligence and open-source intelligence analyst, enabling structured intelligence collection and analysis of targets without the need for API keys.

Core Features & Use Cases

  • Multi-vector Reconnaissance: Perform comprehensive reconnaissance on any target type (person, domain, organization, etc.) with automated validation and structured intelligence delivery.
  • AEAD Workflow: Acquire raw data, enrich with pivot expansion, assess findings, and deliver structured reports (Markdown + Word with charts, diagrams, styled formatting).
  • Techniques: Utilizes 67+ commands and 38 techniques for various OSINT and CTI tasks, including domain, infrastructure, people, and image analysis.

Quick Start

Use the /cti-expert /case command followed by the target to initiate a full autonomous case investigation.

Frequently Asked Questions about cti-expert

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform open-source intelligence reconnaissance on a target entity?

Cyber threat intelligence collection is achieved by transforming Claude into a trained OSINT analyst, which executes an automated workflow to acquire raw data, enrich findings via pivot expansion, assess results, and deliver structured Markdown and Word reports without requiring API keys.

Can I conduct cyber threat intelligence analysis without needing API keys?

Yes, cyber threat intelligence analysis requires no API keys for core functionality. The system handles structured collection, reconnaissance, data enrichment, assessment, and report generation entirely through OSINT techniques and commands.

What is the AEAD workflow for cyber threat intelligence?

The AEAD workflow for cyber threat intelligence is a structured processing pipeline that Acquires raw data, Enriches findings with pivot expansion, Assesses the intelligence, and Delivers final structured reports in Markdown and Word formats with charts and diagrams.

How do I start an autonomous OSINT investigation on a specific target?

To begin an autonomous OSINT investigation, use the /cti-expert /case command followed by the target entity. This initiates the full automated cyber threat intelligence workflow, executing multi-vector reconnaissance and structured analysis.

Does this OSINT analyst tool require external dependencies like FastAPI or pandas?

The OSINT analyst tool relies on agentflow-py, fastapi, pydantic, boto3, and pandas as dependencies. These frameworks support the advanced internal design required for structured intelligence collection, data enrichment, and report generation.

What formats are supported for cyber threat intelligence report delivery?

Cyber threat intelligence report delivery supports Markdown and Word formats featuring styled formatting, charts, and diagrams. These outputs present the assessed findings from the multi-vector reconnaissance and data enrichment phases.