tavily-ai/use-case-skills · Archived

threat-intelligence-enrichment

Enrich threat intelligence from CVEs, IOCs, malware names, threat actors, vendor advisories, security incidents, exploit reports, vulnerability disclosures, breach news, and mitigation guidance. Use when the user asks to investigate a CVE, enrich indicators, summarize vendor advisories, assess exploit status, collect mitigations, or produce a source-grounded security brief.

First seen Jul 17, 2026

Installation

$ npx skills add tavily-ai/use-case-skills --skill threat-intelligence-enrichment

Stronger alternatives

This repository is archived — consider an actively maintained alternative.

Similar popular skills

Related neighbors and high-traction skills in the same topics — useful to compare before installing.

Also in this package

Other skills from tavily-ai/use-case-skills · top by installs.

npx skills add tavily-ai/use-case-skills

Browse all from tavily-ai/use-case-skills

More details

Agent compatibility

Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.

Claude Code Not declared
Cursor Not declared
Codex Not declared
GitHub Copilot Not declared
Windsurf Not declared
Gemini CLI Not declared
Cline Not declared
OpenCode Not declared

Repository health

Stars 1
License MIT
Default branch main
Open issues 0
Status Archived

Skill metadata

Parsed from SKILL.md frontmatter.

Version0.1.0
LicenseMIT
More metadata
author
tavily
version
0.1.0
homepage
https://www.tavily.com
source
https://github.com/tavily-ai/use-case-skills

Package contents

Files included with this skill beyond the listing page.

  • skill md SKILL.md 4,631 B
  • docs SUMMARY.md 414 B

History

  1. First seen on skills.sh
  2. First recorded snapshot · 11 installs

SKILL.md

Threat Intelligence Enrichment

Workflow

Use search and extract to enrich security entities with authoritative and recent evidence; use map or crawl for known vendor portals or advisory collections. Keep this skill focused on query construction, source priority, verification, and security synthesis; execution mechanics should come from companion endpoint skills.

Treat the guidance below as base guidance; adapt it to the user's request when appropriate.

  • Identify the input type: CVE, IOC, malware/tool, threat actor, vendor/product, advisory URL, incident, or campaign.
  • Break the task into short subqueries under 400 characters: identifier, affected product, exploit status, vendor advisory, patches, mitigations, exploitation in the wild, and recent reporting.
  • Search first, using exact-match style queries for CVEs, hashes, domains, IPs, advisory IDs, and malware names.
  • Filter sources before extraction. Prioritize NVD/CVE records, vendor advisories, CISA/agency alerts, security research blogs, reputable incident reports, and official patch notes.
  • Extract selected pages that can support exploit status, impact, affected versions, mitigations, timeline, or confidence.
  • Use site navigation for vendor advisory portals or documentation sites when the relevant page is hard to find.
  • Collect scoped advisory, changelog, release note, or documentation sections only when the user needs broad coverage.

Research Budget

  • Start with a small focused search set covering the identifier, vendor advisory, exploit status, and mitigation or patch evidence.
  • Extract only the strongest authoritative sources before drafting.
  • Add more searches only for named gaps, such as missing affected versions, missing patch notes, or unclear exploitation status.
  • Do not use map unless a known vendor portal or documentation site has a specific advisory or release note to locate.
  • Do not use crawl unless the user asks for coverage across many related advisories or docs pages.

Capability Guidance

  • Use search for CVEs, IOCs, advisories, exploit status, affected versions, mitigations, and recent incident reporting.
  • Use extract on selected vendor advisories, CVE records, agency alerts, patch notes, and security research pages.
  • Use map when a vendor portal or documentation site is known but the specific advisory is hard to locate.
  • Use crawl for advisory/doc sets only when the user asks for coverage across many related pages.
  • Use research only for threat landscape reports or multi-campaign summaries.

Query And Source Guidance

  • Use exact identifiers in queries: CVE IDs, advisory IDs, product/version names, hashes, domains, IPs, malware names, and actor aliases.
  • Prioritize vendor advisories, NVD/CVE records, CISA or national agency alerts, CERT/CC, official patch notes, and reputable security research.
  • Treat social posts, exploit-db style references, and secondary news as supporting evidence unless confirmed by authoritative sources.
  • Separate "exploited in the wild", "public PoC", "theoretical exploitability", and "patched" as different statuses.
  • Report failed or inaccessible sources when they affect vendor advisories, CVE records, affected-version evidence, or mitigation guidance.

Output Template

Use this markdown structure and label uncertainty:

# Threat Intelligence Brief: <entity>

## Summary
- Current status:
- Confidence:
- Most important source:

## Entity Details
- Type:
- Aliases/identifiers:
- Related products or systems:

## Impact And Exposure
- Affected products/versions:
- Exploit status:
- Evidence quality:

## Mitigation And Detection
- Patches or mitigations:
- Detection or hunting notes:
- Recommended checks:

## Timeline
- <date>: <event> ([source](URL))

## Sources And Gaps
- Sources:
- Gaps or unresolved claims:

Do not overstate attribution, exploitation, or compromise evidence. Label speculation and unverified claims.