research-analyst

Triangulate claims across multiple sources and assign confidence scores.

8|1|Updated Mar 30, 2026
One-click install
npx skills add https://github.com/drewid74/ai_skills --skill research-analyst-drewid74
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: research-analyst
Source: https://github.com/drewid74/ai_skills/tree/main/research-analyst
Command: npx skills add https://github.com/drewid74/ai_skills --skill research-analyst-drewid74

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill helps you research, verify, and publish claims with trustworthy sourcing by triangulating evidence across multiple primary or authoritative references and assigning explicit confidence.

Core Features & Use Cases

  • Source triangulation and fact-checking: Requires corroboration across at least three independent sources and discourages single-source “confirmed” claims.
  • Evidence-first threat intelligence workflow: Supports investigation of IOCs, threat actors, campaigns, and adversary activity with structured CTI normalization.
  • Confidence scoring and recency checks: Produces confidence scores, flags stale information (e.g., older than 18 months for fast-moving domains), and surfaces conflicts instead of silently resolving them.
  • Interoperable outputs for CTI: Guides mapping to STIX 2.1 / TAXII 2.1 concepts and emphasizes IOC storage and graph-based relationship modeling.
  • Use case: Verify a competitive or security allegation (e.g., “Group X targeted org Y using IOC Z”) by cross-checking feeds, confirming dates, and producing a cited report that distinguishes confirmed findings from hypotheses.

Quick Start

Use the research-analyst skill to investigate the claim “IOC hash X is linked to threat group Y” and return a cited assessment with confidence scores and source dates.

Frequently Asked Questions about research-analyst

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I triangulate threat intelligence claims across multiple sources?▼

Triangulate threat intelligence claims by corroborating evidence across at least three independent sources, prioritizing primary references, and surfacing conflicts instead of silently resolving them. This method assigns explicit confidence scores to verified adversary activity.

What is the best way to fact check IOC investigations with confidence scoring?▼

Fact check IOC investigations by cross-checking threat feeds, confirming dates, and producing a cited report. This process distinguishes confirmed findings from hypotheses by applying recency filtering and explicit confidence scoring to adversary claims.

Can I normalize IOC investigation outputs for STIX 2.1 and TAXII 2.1?▼

You can normalize IOC investigation outputs for STIX 2.1 and TAXII 2.1 readiness. The workflow guides mapping structured threat intelligence concepts and emphasizes IOC storage and graph-based relationship modeling for interoperable CTI.

How does source triangulation handle stale threat intelligence data?▼

Source triangulation handles stale threat intelligence data by applying recency checks, flagging information older than 18 months for fast-moving domains. It surfaces conflicting evidence rather than silently resolving discrepancies between sources.