hs:cti-expert

Conducts OSINT and cyber threat intelligence investigations with structured reports.

Updated Jul 19, 2026
One-click install
npx skills add https://github.com/Dozyboy/VSF --skill hs-cti-expert-dozyboy
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: hs:cti-expert
Source: https://github.com/Dozyboy/VSF/tree/main/Day2_VSF/Demo1/harness/plugins/hs/disabled-skills/cti-expert
Command: npx skills add https://github.com/Dozyboy/VSF --skill hs-cti-expert-dozyboy

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill requires scrapling, agentflow-py, maigret, holehe, h8mail, theHarvester, trufflehog, waymore, whoisdomain, xeuledoc, oletools, and includes scripts (resource) and references (resource) and assets (resource) components.

What problem does it solve? Investigating a person, domain, email, username, IP, or organization across public sources requires dozens of manual lookups, pivot steps, and report-writing effort. This Skill turns the AI into a structured intelligence analyst that runs multi-vector reconnaissance, validates findings, scores exposure, and delivers formatted intelligence reports without requiring paid API keys for core functionality. ## Core Features & Use Cases - Multi-vector reconnaissance: 67+ commands covering username enumeration across 3000+ platforms, email and breach lookups, phone intelligence, subdomain enumeration, WHOIS/DNS forensics, threat intelligence checks, image forensics, blockchain tracing, darknet monitoring, and geolocation. - AEAD case lifecycle: Acquire, Enrich, Assess, Deliver workflow with parallel enrichment via AgentFlow, exposure scoring (0-100), finding validation, and conflict resolution. - Structured reporting: Auto-generates Markdown INTSUM reports and styled DOCX documents with charts, network topology diagrams, and timelines; supports IOC export in STIX 2.1. - Use Case: A security analyst runs /cti-expert /case example.com to enumerate subdomains, check breach exposure, verify scam indicators, and receive a complete DOCX intelligence report with risk scoring. ## Quick Start Ask the AI to run a full CTI Expert case investigation on a target domain such as example.com and generate the report.

Frequently Asked Questions about hs:cti-expert

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I run an OSINT investigation on a domain?▼

Run the /case command with the target domain to execute every applicable technique automatically, including subdomain enumeration, WHOIS, DNS forensics, breach checks, and scam verification. The investigation ends with auto-generated Markdown and DOCX reports.

What tools are used for username enumeration across platforms?▼

Username enumeration uses Maigret, Sherlock, and Blackbird to check over 3000 platforms for a given handle. The /username command runs these tools and logs findings with collection method tags.

Does this OSINT workflow require paid API keys?▼

Core functionality works without API keys using free sources like certificate transparency logs, Wayback Machine, and public threat feeds. Optional free keys for Wigle, VirusTotal, and URLScan.io enhance specific techniques.

Can it trace cryptocurrency wallet transactions?▼

Yes, the blockchain module traces wallets using Blockchair, Etherscan, WalletExplorer, OXT.me, and Chainabuse. It identifies exchange deposit addresses, detects mixer usage, and maps transaction flows across multiple chains.

What happens if a required CLI tool is not installed?▼

The skill auto-installs missing tools like maigret, holehe, subfinder, or exiftool via pip, pipx, go, or apt before proceeding. If installation fails, it falls back to the next tool in the cascade without blocking the investigation.

What are the ethical and legal boundaries of this skill?▼

The skill operates only on publicly available information for journalism, security audits, due diligence, and self-review. It prohibits stalking, doxxing, unauthorized access, and social engineering, and issues ethical reminders near sensitive territory.