Provides real-time cyber and cognitive security threat intelligence, scoring and briefing relevant news, vulnerabilities, exploits, and influence operations...
数据来源:ClawHub。 在 ClawSkills 查看
选择你使用的 Agent
方法一:命令行安装(推荐)
推荐(无需提前安装 clawhub)
npx clawhub@latest --dir ~/.claude/skills install seithar-intel或使用 clawhub CLI(需提前安装)
clawhub --dir ~/.claude/skills install seithar-intel⚠️ 需要 Node.js 18+,没有 Node?请使用下方方法二直接下载 ZIP。 安装 Node.js →
方法二:手动下载安装(无需 Node)
下载 ZIP,解压后将文件夹放到以下路径,重启 Agent 即可:
安装路径
~/.claude/skills/seithar-intel/💡解压后将文件夹放到上方路径,重启 Agent 即可生效
A personal cyber threat intelligence and cognitive security analyst for OpenClaw. Monitors RSS feeds for security news, vulnerability disclosures, exploit drops, and influence operation reports. Scores items against your interests, delivers daily briefings, and provides on-demand deep-dive analysis of any threat — technical or cognitive.
This is ThreatMouth in your pocket. Cyber + cognitive security awareness from any chat app.
---
This skill turns your OpenClaw into a threat intelligence analyst that:
---
---
The operator should configure the following in their OpenClaw settings or by telling the agent directly:
Tell your OpenClaw your security interests and it will calibrate scoring. Example:
My security interests are:
- Malware analysis and reverse engineering
- Social engineering and cognitive security
- Network exploitation
- OSINT and intelligence gathering
- Influence operations and information warfare
- Vulnerability research and exploit development
I'm currently studying:
- MITRE ATT&CK framework
- DISARM framework for influence operations
- Python security tooling
- OverTheWire wargames
My skill level: intermediate
Deprioritize:
- Enterprise compliance and GRC
- Cloud IAM and AWS security
- Vendor marketing announcements
- Corporate breach notifications unless technically interesting
The skill stores this profile in memory and uses it to score every feed item for relevance.
Default schedule (configurable):
Tell your OpenClaw: "Change my briefing time to 9 AM and 7 PM" or "Only send critical alerts, no scheduled briefings"
Default: every 2 hours. The skill uses OpenClaw's cron/heartbeat system to periodically fetch and process feeds.
---
On each check interval, the skill instructs the agent to:
web_fetch toolEach new item is scored 0.0 to 1.0 against the operator's profile:
The agent scores by examining the item's title, summary, source, and any CVE/technique references against the stored interest profile. No external API needed — the LLM does the scoring inline.
Items are categorized into:
╔══════════════════════════════════════════════════╗
║ SEITHAR INTELLIGENCE BRIEFING ║
║ 2026-02-11 08:00 EST ║
╚══════════════════════════════════════════════════╝
CRITICAL (act now):
🔴 [0.95] Pre-auth RCE in OpenSSH (CVE-2026-XXXXX)
Full Disclosure | 2h ago
Affects OpenSSH 9.x. Public PoC available.
▸ Say "deep dive CVE-2026-XXXXX" for full analysis
HIGH RELEVANCE:
🟠 [0.87] Lazarus Group deploys new social engineering
toolkit targeting crypto developers
The Hacker News | 4h ago
DISARM: T0047 (Develop Content), ATT&CK: T1566.001
▸ Say "deep dive lazarus social engineering" for analysis
🟠 [0.82] New Nuclei templates for Spring4Shell variants
Exploit-DB | 6h ago
12 new detection templates + PoC payloads
▸ Say "explain spring4shell" for context
🟠 [0.78] Russian influence operation targeting NATO
narratives detected across 3 platforms
DFRLab | 5h ago
DISARM: T0046, T0048, T0056 | Coordinated inauthentic behavior
▸ Say "deep dive nato influence op" for DISARM breakdown
STUDY RECOMMENDATION:
Based on today's feed: review SSH key exchange internals
and pre-authentication attack surfaces. OverTheWire Bandit
levels 14-17 cover SSH fundamentals.
──────────────────────────────────────────────────
24 items collected | 4 high relevance | 1 critical
Seithar Intelligence Division v1.0
認知作戦 | seithar.com/research
──────────────────────────────────────────────────
When the operator says "deep dive [topic]" or "explain [CVE]", the skill:
web_fetchhttps://api.github.com/search/repositories?q=CVE-XXXX-XXXXX&sort=stars)╔══════════════════════════════════════════════════╗
║ SEITHAR DEEP DIVE ║
║ CVE-2026-XXXXX — OpenSSH Pre-Auth RCE ║
╚══════════════════════════════════════════════════╝
WHAT HAPPENED:
A memory corruption vulnerability in OpenSSH's key exchange
handler allows unauthenticated attackers to achieve remote
code execution as root. No credentials required.
HOW THE EXPLOIT WORKS:
1. Attacker connects to SSH port 22
2. During key exchange (before authentication), sends
oversized payload in the KEX_INIT message
3. Buffer overflow overwrites return address on stack
4. Execution redirected to attacker's shellcode
5. Root shell achieved — no credentials needed
Pseudocode:
connect(target, 22)
send(kex_init_with_overflow_payload)
# Stack is now corrupted
# Return address points to shellcode
# Root shell spawns
MITRE ATT&CK:
T1190 — Exploit Public-Facing Application
T1068 — Exploitation for Privilege Escalation
...安装 seithar-intel 后,可以对 AI 说这些话来触发它
Help me get started with seithar-intel
Explains what seithar-intel does, walks through the setup, and runs a quick demo based on your current project
Use seithar-intel to real-time cyber and cognitive security threat intelligence, scoring...
Invokes seithar-intel with the right parameters and returns the result directly in the conversation
What can I do with seithar-intel in my finance & investment workflow?
Lists the top use cases for seithar-intel, with example commands for each scenario
将技能文件夹放到 ~/.claude/skills/seithar-intel/ 目录(个人级,所有项目可用),或 .claude/skills/seithar-intel/(项目级)。重启 AI 客户端后,用 /seithar-intel 主动调用,或让 AI 根据上下文自动发现并使用。
seithar-intel 支持 Claude、Cursor、OpenClaw,可与这些 AI 平台无缝集成,扩展其能力。
seithar-intel 可免费安装使用。请查阅仓库了解许可证信息。
Provides real-time cyber and cognitive security threat intelligence, scoring and briefing relevant news, vulnerabilities, exploits, and influence operations...
seithar-intel 属于「Finance & Investment」分类,该分类的技能帮助 AI 智能体在此领域执行专业任务。
Automate my finance & investment tasks using seithar-intel
Identifies repetitive steps in your workflow and sets up seithar-intel to handle them automatically