cti-setup

Configure and verify CTI API keys for seven threat-intel integrations in Claude Code.

15|5|Updated Apr 6, 2026
One-click install
npx skills add https://github.com/Liberty91LTD/cti-skills --skill cti-setup
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cti-setup
Source: https://github.com/Liberty91LTD/cti-skills/tree/main/skills/cti-setup
Command: npx skills add https://github.com/Liberty91LTD/cti-skills --skill cti-setup

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

In-chat configuration of API keys for the CTI skills pack. Use this when you want to configure the seven threat-intel integrations inside Claude Code without dropping to a shell, and to keep keys synchronized and secure within the pack.

Core Features & Use Cases

  • In-chat configuration of the seven threat-intel keys (VirusTotal, OTX, URLScan, Shodan, AbuseIPDB, GreyNoise, Censys) with non-destructive merges to the local settings file.
  • Verifies and re-runs setup as needed, and provides guidance for key rotation and troubleshooting within the chat.
  • Use cases include onboarding new keys, re-running configuration after plugin installs, and validating that keys are wired up for live lookups.

Quick Start

Configure your CTI API keys for all integrations directly in Claude Code.

Frequently Asked Questions about cti-setup

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I configure threat intelligence API keys for VirusTotal and Shodan inside Claude Code?

You can configure threat intelligence API keys for VirusTotal, Shodan, and other integrations directly in Claude Code by running the cti-setup skill, which performs a non-destructive merge into your local settings file without dropping to a shell.

What threat intel integrations are supported for API key setup in Claude Code?

The supported threat intel integrations include VirusTotal, URLScan, Shodan, AbuseIPDB, GreyNoise, AlienVault OTX, and Censys, allowing you to manage all seven API keys within chat workflows.

Can I rotate and verify CTI API keys without leaving the chat interface?

Yes, you can rotate and verify CTI API keys entirely within the chat interface, as the skill provides guidance for key rotation, troubleshooting, and validation that keys are wired up for live lookups.

Does configuring CTI keys overwrite existing settings in the local configuration file?

Configuring CTI keys does not overwrite existing settings because the skill performs a non-destructive merge into .claude/settings.local.json, preserving your current configuration while adding or updating keys.

Why do I need to re-run API key configuration after installing threat intelligence plugins?

You need to re-run API key configuration after plugin installs to validate that keys are correctly wired up for live lookups and to ensure all threat-intel integrations remain synchronized and secure within the pack.

What is the best way to onboard new keys for multiple threat intel platforms at once?

The best way to onboard new keys for multiple threat intel platforms is to use an in-chat configuration skill that guides you through setup, verification, and non-destructive merging for all integrations in a single workflow.