Building Attack Pattern Library From Cti Reports
Extract and catalog attack patterns from cyber threat intelligence reports into a structured STIX-based library
Install
Quick install
npx skills add https://github.com/OTRF/ATTACK-Python-Clientnpx skills add OTRF/ATTACK-Python-Client --agent claude-codenpx skills add OTRF/ATTACK-Python-Client --agent cursornpx skills add OTRF/ATTACK-Python-Client --agent codexnpx skills add OTRF/ATTACK-Python-Client --agent opencodenpx skills add OTRF/ATTACK-Python-Client --agent github-copilotnpx skills add OTRF/ATTACK-Python-Client --agent windsurfMore install options
Shorthand — useful for multi-skill repos:
npx skills add OTRF/ATTACK-Python-ClientManual — clone the repo and drop the folder into your agent's skills directory:
git clone https://github.com/OTRF/ATTACK-Python-Client.gitcp -r ATTACK-Python-Client ~/.claude/skills/Building Attack Pattern Library From Cti Reports
Extract and catalog attack patterns from cyber threat intelligence reports into a structured STIX-based library
---
Source: https://github.com/OTRF/ATTACK-Python-Client
Author: mukul975
Discovered via: skillsdirectory.com
Genre: testing-security
SKILL.md source
--- name: Building Attack Pattern Library From Cti Reports description: Extract and catalog attack patterns from cyber threat intelligence reports into a structured STIX-based library --- # Building Attack Pattern Library From Cti Reports Extract and catalog attack patterns from cyber threat intelligence reports into a structured STIX-based library --- **Source**: https://github.com/OTRF/ATTACK-Python-Client **Author**: mukul975 **Discovered via**: skillsdirectory.com **Genre**: testing-security
Related skills 6
caveman
Ultra-compressed communication mode. Cuts token usage ~75% by speaking like caveman while keeping full technical accuracy. Supports intensity levels: lite, full (default), ultra, wenyan-lite, wenyan-full, wenyan-ultra. Use when user says "caveman mode", "talk like caveman", "use caveman", "less tokens", "be brief", or invokes /caveman. Also auto-triggers when token efficiency is requested.
secure-linux-web-hosting
Use when setting up, hardening, or reviewing a cloud server for self-hosting, including DNS, SSH, firewalls, Nginx, static-site hosting, reverse-proxying an app, HTTPS with Let's Encrypt or ACME clients, safe HTTP-to-HTTPS redirects, or optional post-launch network tuning such as BBR.
readme-i18n
Use when the user wants to translate a repository README, make a repo multilingual, localize docs, add a language switcher, internationalize the README, or update localized README variants in a GitHub-style repository.
lark-shared
Use when first setting up lark-cli, running auth login, switching user/bot identity (--as), handling permission denied or scope errors, needing to update lark-cli, or seeing _notice in JSON output.
improve-codebase-architecture
Find deepening opportunities in a codebase, informed by the domain language in CONTEXT.md and the decisions in docs/adr/. Use when the user wants to improve architecture, find refactoring opportunities, consolidate tightly-coupled modules, or make a codebase more testable and AI-navigable.
paper-context-resolver
Optional RigorPilot helper for README-first deep learning repo reproduction. Use only when the README and repository files leave a narrow reproduction-critical gap and the task is to resolve a specific paper detail such as dataset split, preprocessing, evaluation protocol, checkpoint mapping, or runtime assumption from primary paper sources while recording conflicts. Do not use for general paper summary, repo scanning, environment setup, command execution, title-only paper lookup, or replacin...