Cyber threat intelligence and OSINT toolkit — structured investigations with sourced, trust-scored findings. Bundles the skill, the /cti command set, the typed intel MCP surface, and the RULE 1 / outbound-action safety hooks as one installable unit.
AGENTS.md instructions for 7onez/cti-expert, covering agents.md — cti expert (cross-agent operating contract), 1. skill directory (resolve once, then reuse as $skilldir), 2. step 0 — detect the os (once per session), 3. runtime: uv-first (the portable path) and 4. generate report outputs (works on any os / any agent).
Claude Code instructions for 7onez/cti-expert, covering cti-expert — contributor rules, rule 2 — there is exactly one case store, rule 3 — register every new tool with the mcp surface, rule 4 — wrapper/collector drift must stay self-healing and rule 5 — indicator classification changes need a test.
Cyber threat intelligence and OSINT analysis toolkit. Runs structured investigations and delivers analyst-grade intelligence products with sourced, trust-scored findings. Use for OSINT and CTI cases, digital-footprint and exposure review, domain/subdomain/DNS/certificate recon, web-infrastructure pivoting (favicon…
Run the full deterministic pipeline on one or more seeds: collect, ingest, prior-overlap, risk, cluster, ICD-203 assessment. Usage: /cti-case [seed...].
THE ENTRY POINT for cti-expert. Investigate any target — domain, IP, email, username, phone, wallet, hash or APK. Routes to the right chain automatically. Usage: /cti [--deep|--quick|--passive].