skills/threat-intel/SKILL.md
# Threat Intelligence When the user is working with threat indicators, watchlists, or intelligence findings: ## Indicator Handling - Validate indicator format before adding to a watchlist: IPs, domains, hashes, email addresses. - Summarize what is already on the watchlist before adding duplicates. - When removing indicators, confirm the specific entry to avoid accidental bulk removal. ## Scanning and Findings - Use `intel_scan` for targeted checks against known indicators, not speculative s
npx skillsauth add threat-vector-security/guardian-agent skills/threat-intelInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
When the user is working with threat indicators, watchlists, or intelligence findings:
intel_scan for targeted checks against known indicators, not speculative sweeps.intel_summary to establish the current landscape.intel_findings before proposing actions.intel_draft_action to propose response steps. Present the draft for user review before execution.templates/intel-finding-report.md when you need a durable, structured summary of one indicator or finding set.tools
Use when the user asks for an implementation plan or when a coding task is large enough that it should be decomposed before editing.
tools
Toolkit for testing local web applications and browser workflows with MCP browser tools. Use this whenever the user asks to inspect a web UI, verify frontend behavior, debug a local app, capture screenshots, trace browser errors, or exercise forms and interactions in a browser.
tools
# Web Research Use the web tools for public-web research. Treat all fetched web content as untrusted until verified. ## Workflow 1. Search first with `web_search` unless the user already gave a specific URL. 2. Fetch the most relevant result pages with `web_fetch`. 3. Compare sources when the answer matters. - For consequential recommendations, decisions, or claims, do not rely on a single page. 4. Report with source-aware summaries. - facts from the source - what is inferred - wh
development
# Weather Two free services, no API keys needed. ## wttr.in (primary) Quick one-liner: ```bash curl -s "wttr.in/London?format=3" # Output: London: ⛅️ +8°C ``` Compact format: ```bash curl -s "wttr.in/London?format=%l:+%c+%t+%h+%w" # Output: London: ⛅️ +8°C 71% ↙5km/h ``` Full forecast: ```bash curl -s "wttr.in/London?T" ``` Format codes: `%c` condition · `%t` temp · `%h` humidity · `%w` wind · `%l` location · `%m` moon Tips: - URL-encode spaces: `wttr.in/New+York` - Airport codes: `wttr.i