Best use case
STIX/TAXII Intelligence Skill is best used when you need a repeatable AI agent workflow instead of a one-off prompt.
STIX/TAXII threat intelligence format and sharing
Teams using STIX/TAXII Intelligence Skill should expect a more consistent output, faster repeated execution, less prompt rewriting.
When to use this skill
- You want a reusable workflow that can be run more than once with consistent structure.
When not to use this skill
- You only need a quick one-off answer and do not need a reusable workflow.
- You cannot install or maintain the underlying files, dependencies, or repository context.
Installation
Claude Code / Cursor / Codex
Manual Installation
- Download SKILL.md from GitHub
- Place it in
.claude/skills/stix-taxii/SKILL.mdinside your project - Restart your AI agent — it will auto-discover the skill
How STIX/TAXII Intelligence Skill Compares
| Feature / Agent | STIX/TAXII Intelligence Skill | Standard Approach |
|---|---|---|
| Platform Support | Not specified | Limited / Varies |
| Context Awareness | High | Baseline |
| Installation Complexity | Unknown | N/A |
Frequently Asked Questions
What does this skill do?
STIX/TAXII threat intelligence format and sharing
Where can I find the source code?
You can find the source code on GitHub using the link provided at the top of the page.
SKILL.md Source
# STIX/TAXII Intelligence Skill ## Overview This skill provides STIX/TAXII threat intelligence format creation, querying, and sharing capabilities. ## Capabilities - Create STIX 2.1 bundles - Query TAXII servers - Generate threat reports - Create indicator relationships - Map to MITRE ATT&CK - Support OpenIOC format - Validate STIX syntax - Share intelligence feeds ## Target Processes - threat-intelligence-research.js - malware-analysis.js - security-advisory-writing.js ## Dependencies - stix2 library (Python) - taxii2-client - Python 3.x - TAXII server access (optional) ## Usage Context This skill is essential for: - Threat intelligence sharing - IOC standardization - Intelligence feed management - Threat report generation - Intelligence correlation ## Integration Notes - Supports STIX 2.0 and 2.1 - Can publish to TAXII servers - Integrates with MISP - Supports multiple IOC formats - Can generate human-readable reports
Related Skills
competitive-intelligence
Deep competitive analysis and market monitoring capabilities for product strategy
gong-conversation-intelligence
Gong.io conversation analytics for sales insights and coaching
reputation-intelligence
Reputation measurement and benchmarking platform integration
competitive-intelligence-tracker
Competitive intelligence collection and analysis skill for systematic competitor monitoring
cog-team-intelligence
Cross-reference GitHub, Linear, Slack, and PostHog with bidirectional sync for team briefs
cog-daily-intelligence
Generate personalized verified news briefs with 7-day freshness and 95%+ source accuracy
process-builder
Scaffold new babysitter process definitions following SDK patterns, proper structure, and best practices. Guides the 3-phase workflow from research to implementation.
babysitter
Orchestrate via @babysitter. Use this skill when asked to babysit a run, orchestrate a process or whenever it is called explicitly. (babysit, babysitter, orchestrate, orchestrate a run, workflow, etc.)
yolo
Run Babysitter autonomously with minimal manual interruption.
user-install
Install the user-level Babysitter Codex setup.
team-install
Install the team-pinned Babysitter Codex workspace setup.
retrospect
Summarize or retrospect on a completed Babysitter run.