threat-assessment

Calculate threat levels using Intent, Capability, and Opportunity frameworks.

15|5|Updated Apr 6, 2026
One-click install
npx skills add https://github.com/Liberty91LTD/cti-skills --skill threat-assessment
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: threat-assessment
Source: https://github.com/Liberty91LTD/cti-skills/tree/main/skills/threat-assessment
Command: npx skills add https://github.com/Liberty91LTD/cti-skills --skill threat-assessment

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This methodology helps security teams evaluate threats by translating qualitative signals into a concise, auditable threat rating based on Intent, Capability, and Opportunity.

Core Features & Use Cases

  • Combines Intent, Capability, and Opportunity into a single, comparable Threat Level for actors or scenarios.
  • Provides a structured guidance pack for evidence-based assessment, decision-making, and reporting.
  • Suitable for risk reviews, threat modeling, post-incident analysis, and strategic threat intelligence synthesis.

Quick Start

Provide a threat assessment using the Intent, Capability, and Opportunity framework to determine the overall threat level.

Frequently Asked Questions about threat-assessment

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is a structured threat assessment framework based on intent, capability, and opportunity?

A structured threat assessment framework evaluates risk by scoring intent, capability, and opportunity to calculate a single, auditable Threat Level for security analysis and reporting.

How do I calculate a threat level for a specific threat actor or scenario?

You calculate a threat level by providing evidence and scenarios, which the framework assesses across intent, capability, and opportunity to generate a rated synthesis with mitigations and key assumptions.

Can I use this threat modeling approach for post-incident analysis and risk reviews?

Yes, this threat modeling approach suits post-incident analysis, risk reviews, and strategic threat intelligence synthesis by translating qualitative signals into comparable threat ratings.

Does the threat assessment output include mitigations and key assumptions?

Yes, the threat assessment output explicitly includes the calculated Threat Level, rated components, a synthesis, key assumptions, recommended mitigations, and sources for auditable reporting.

What is the best way to translate qualitative security signals into an auditable threat rating?

The best way to translate qualitative signals into an auditable threat rating is applying a structured framework that evaluates evidence across intent, capability, and opportunity dimensions.

Are there limitations to using a high-level threat intelligence synthesis for security evaluation?

This high-level threat intelligence synthesis is designed for broad analysis and reporting rather than granular detection, relying on provided evidence and scenarios to generate strategic threat assessments.