Traction scoreGitHub stars can be faked, so popularity alone can be misleading. Traction Score looks for broader signs of recent attention, adoption, and active maintenance.
CTI Expert gives threat intelligence analysts a structured case lifecycle for collecting, pivoting, assessing, and reporting OSINT. It follows domains, identities, breach artifacts, certificates, wallets, and infrastructure through recursive investigations, then records sources, confidence, coverage gaps, and alternative hypotheses in analyst-ready reports.
WHO IT'S FOR
Threat Intelligence Analysts
running structured CTI and OSINT investigations
Digital Forensics and Incident Response (DFIR) teams
triaging infostealer logs and breach data
Security Researchers
performing web-infrastructure pivoting and reconnaissance
Compatible AgentsThe repository documents support for these agents. The skills may also work with other agents that can load SKILL.md files, but they may need some setup or small changes.
Installs: CTI Expert repository skill loaded through the repository's AGENTS.md contract · OpenAI Codex
Before you start
An OpenAI Codex environment that understands AGENTS.md
Git
Run from: cti-expert
In a terminal, clone the CTI Expert repository in the desired parent directory.
git clone https://github.com/7onez/cti-expert.git
Open Codex inside the cloned cti-expert repository, where it auto-loads AGENTS.md, and ask it to follow SKILL.md. This is performed in the Codex session, not entered as a terminal command.
Any known context needed to distinguish the subject, if available
Check the repository for this skill’s setup.
Use the cti-expert skill for a guided first-time investigation of [person name or identifier]. Produce a small initial investigation plan and a focused first set of precision search queries, explaining what each query is intended to find. Do not publish findings or contact anyone.