Liberty91 Lookup and Write.
/lookup-liberty91
cti-skills is a free, open-source pack of 75 cyber threat intelligence skills for Claude Code and other AI coding assistants, built by Liberty91. A skill is a set of instructions the assistant loads when you type a command, so you can ask questions in plain English and let it do the technical work. The /lookup-liberty91 skill connects the pack to the Liberty91 platform itself: it reads the incidents, indicators and threat actors your account holds, tells you who reported each one and how well corroborated it is, and can write your own findings back.
One incident, not five copies of it.
Most threat intelligence tooling stores reports: vendor write-ups, news articles, advisories. Liberty91 stores those too, but then works out which reports describe the same real-world incident. Say a company is breached, and the breach is covered by a vendor write-up, three news articles and a post on a criminal leak site. That is five documents, but only one thing happened. The platform keeps both layers: the five reports, and the single deduplicated incident they all describe, which it calls a Threat Event. When you ask the skill what happened, you get each incident once, with every report behind it attached, instead of five copies of the same story to untangle yourself.
What you can ask it.
You ask in plain English and the skill translates. 'What happened to energy companies in the Middle East this month?' returns the incidents reported for that sector and region, each with its sources. 'Is this IP address already known to us?' checks an indicator you found elsewhere against everything your account holds. 'Show me APT28' looks up a threat actor in the platform's canonical catalogue, which also knows the other names vendors use for the same group, so asking about Fancy Bear lands on the same record. And 'does this campaign affect us?' matches an incident against the organisation profile you maintain in the platform, which is the question none of the public sources can answer for you.
How you know what to trust.
Every incident carries three separate judgements, and the skill reports all three rather than collapsing them into one score. Source reliability grades who said it, from A to F: a government agency starts higher than an anonymous blog. Credibility grades how well-supported the claim is, from 1 (confirmed) to 6 (cannot be judged), and republished copies of the same article cannot inflate it. Verification records where the incident stands, for example picked up automatically, corroborated by independent sources, verified by an analyst, or disputed. These are the same NATO-style ratings intelligence teams use, produced by the platform itself, and when sources disagree about what happened, the skill reports the disagreement instead of averaging it away.
Writing your own intelligence back.
Most lookups in the pack only read; this one also writes, which is what makes it a two-way integration. When you finish an investigation, you can push your findings into the platform as a report of your own, where they are enriched, matched against existing incidents, and kept private to your account. You can have the platform generate a finished intelligence package for your organisation, ready to send to a stakeholder. And you can upload documents to an organisation's profile, a supplier register for example, so the platform knows what to watch on your behalf. Everything you do through the API draws on the credits in your Liberty91 account, the platform's usage allowance, and writes draw more than reads, so the skill asks for your confirmation before each write and never sends one in the middle of an automated run.
How it fits an investigation.
You rarely need to invoke it by name. When you ask the pack to investigate an IP address, a domain, a file hash or a URL, it checks Liberty91 first whenever a key is configured, because your own platform knows something public sources cannot: whether the indicator has already appeared in reporting that matters to you. The workflow that enriches a whole list of indicators does the same, and offers to write the confirmed findings back at the end. Profiling a threat actor starts from the platform's canonical record instead of rebuilding one from scratch, and vulnerability research can pull the incidents where a CVE was actually exploited in the wild, rather than relying on its severity score alone.
What you need to set it up.
Two things. First, the cti-skills pack installed in your AI coding assistant: a couple of copy-and-paste commands install it in Claude Code, and it works in Cursor, Codex and Windsurf too. Second, a Liberty91 API key: log into the platform, open Account and then API Keys, create a key, and set it as LIBERTY91_API_KEY in your environment. The quota command shows your connection and remaining allowance, the skill warns you when credits run low, and if the key is missing it says so and stops rather than inventing an answer. If you do not have a Liberty91 account yet, the rest of the pack works without this skill, and you can join the waitlist for the platform any time.
Keep going.
- How the platform models incidents: Threat Events→
- Source reliability and confidence ratings explained→
- How the pack investigates a whole list of indicators→
- OpenCTI lookup and write, the same idea for your own OpenCTI server→
- Browse all 75 open-source CTI Skills →
- How Liberty91 speeds up analyst work →
- Start for Free, the free tier is coming →
Frequently Asked Questions.
Want to see this on your own organisation?
Request a demo or start your free trial today, and get straight to AI-powered threat intelligence built around your organisation.