What problem does it solve? Investigating a person, domain, email, username, IP, or organization across public sources requires dozens of manual lookups, pivot steps, and report-writing effort. This Skill turns the AI into a structured intelligence analyst that runs multi-vector reconnaissance, validates findings, scores exposure, and delivers formatted intelligence reports without requiring paid API keys for core functionality. ## Core Features & Use Cases - Multi-vector reconnaissance: 67+ commands covering username enumeration across 3000+ platforms, email and breach lookups, phone intelligence, subdomain enumeration, WHOIS/DNS forensics, threat intelligence checks, image forensics, blockchain tracing, darknet monitoring, and geolocation. - AEAD case lifecycle: Acquire, Enrich, Assess, Deliver workflow with parallel enrichment via AgentFlow, exposure scoring (0-100), finding validation, and conflict resolution. - Structured reporting: Auto-generates Markdown INTSUM reports and styled DOCX documents with charts, network topology diagrams, and timelines; supports IOC export in STIX 2.1. - Use Case: A security analyst runs /cti-expert /case example.com to enumerate subdomains, check breach exposure, verify scam indicators, and receive a complete DOCX intelligence report with risk scoring. ## Quick Start Ask the AI to run a full CTI Expert case investigation on a target domain such as example.com and generate the report.