threat-assessment

Calculate threat levels using Intent, Capability, and Opportunity frameworks.

15|5|Updated Apr 6, 2026
One-click install
npx skills add https://github.com/Liberty91LTD/cti-skills --skill threat-assessment
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: threat-assessment
Source: https://github.com/Liberty91LTD/cti-skills/tree/main/skills/threat-assessment
Command: npx skills add https://github.com/Liberty91LTD/cti-skills --skill threat-assessment

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This methodology helps security teams evaluate threats by translating qualitative signals into a concise, auditable threat rating based on Intent, Capability, and Opportunity.

Core Features & Use Cases

  • Combines Intent, Capability, and Opportunity into a single, comparable Threat Level for actors or scenarios.
  • Provides a structured guidance pack for evidence-based assessment, decision-making, and reporting.
  • Suitable for risk reviews, threat modeling, post-incident analysis, and strategic threat intelligence synthesis.

Quick Start

Provide a threat assessment using the Intent, Capability, and Opportunity framework to determine the overall threat level.

Frequently Asked Questions about threat-assessment

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is a structured threat assessment framework based on intent, capability, and opportunity?▼

A structured threat assessment framework evaluates risk by scoring intent, capability, and opportunity to calculate a single, auditable Threat Level for security analysis and reporting.

How do I calculate a threat level for a specific threat actor or scenario?▼

You calculate a threat level by providing evidence and scenarios, which the framework assesses across intent, capability, and opportunity to generate a rated synthesis with mitigations and key assumptions.

Can I use this threat modeling approach for post-incident analysis and risk reviews?▼

Yes, this threat modeling approach suits post-incident analysis, risk reviews, and strategic threat intelligence synthesis by translating qualitative signals into comparable threat ratings.

Does the threat assessment output include mitigations and key assumptions?▼

Yes, the threat assessment output explicitly includes the calculated Threat Level, rated components, a synthesis, key assumptions, recommended mitigations, and sources for auditable reporting.

What is the best way to translate qualitative security signals into an auditable threat rating?▼

The best way to translate qualitative signals into an auditable threat rating is applying a structured framework that evaluates evidence across intent, capability, and opportunity dimensions.

Are there limitations to using a high-level threat intelligence synthesis for security evaluation?▼

This high-level threat intelligence synthesis is designed for broad analysis and reporting rather than granular detection, relying on provided evidence and scenarios to generate strategic threat assessments.