tlp-guide

Apply TLP designations to intelligence outputs via YAML frontmatter and headers.

15|5|Updated Apr 6, 2026
One-click install
npx skills add https://github.com/Liberty91LTD/cti-skills --skill tlp-guide
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: tlp-guide
Source: https://github.com/Liberty91LTD/cti-skills/tree/main/skills/tlp-guide
Command: npx skills add https://github.com/Liberty91LTD/cti-skills --skill tlp-guide

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Every intelligence output from this platform MUST have a TLP designation. This is enforced by platform rules and validated by hooks.

Core Features & Use Cases

  • Defines TLP levels and their sharing scopes (RED, AMBER, GREEN, CLEAR)
  • Provides a decision tree to determine appropriate TLP based on risk and recipients
  • Guides consistent application in reports, briefs, and datasets

Quick Start

Set the TLP designation on every intelligence output to enforce proper sharing.

Frequently Asked Questions about tlp-guide

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is TLP designation for intelligence outputs?

TLP designation controls the distribution of intelligence outputs by defining sharing scopes across RED, AMBER, GREEN, and CLEAR levels. It enforces platform policy by requiring a YAML frontmatter entry and a corresponding header for reports and briefs.

How do I apply TLP levels to security reports and datasets?

To apply TLP levels to security reports, set the TLP designation in the YAML frontmatter and include the corresponding TLP header. This enforces consistent sharing policies and enables targeted distribution to named recipients across all intelligence outputs.

When do I need to define sharing rules for intelligence briefs?

You need to define sharing rules for intelligence briefs when distributing outputs to named recipients or onboarding teams. Platform rules mandate that every intelligence output must have a TLP designation, which is validated by hooks.

How does the decision tree determine appropriate TLP designations?

The decision tree determines appropriate TLP designations by evaluating risk levels and intended recipients. It guides you in selecting the correct sharing scope among RED, AMBER, GREEN, and CLEAR to ensure consistent application across reports, briefs, and datasets.

Can I use TLP designations to control distribution for onboarding teams?

Yes, you can use TLP designations to control distribution for onboarding teams. By applying the TLP header and YAML frontmatter to intelligence outputs, you enable targeted sharing that restricts access based on the designated sharing scope.

Why does my intelligence output require a TLP designation?

Your intelligence output requires a TLP designation because platform rules enforce mandatory sharing policies. This is validated by hooks to ensure consistent governance, preventing unauthorized distribution of security intelligence across reports and datasets.