# OpenCTI

> Use this tool when you need to interact with the OpenCTI threat intelligence platform to query and manipulate cyber threat data. It provides a standardized interface for AI systems to access and analyze threat information, solving problems such as automated threat analysis and indicator enrichment. With API authentication and endpoint configuration, it enables seamless integration of threat data into AI-driven security workflows.

Canonical page: https://skillsregistry.net/skills/spathodea-network-opencti  
JSON: https://api.skillsregistry.net/v1/skills/spathodea-network-opencti

## Description

This OpenCTI MCP server, developed by zxzinn and Spathodea Network, provides a standardized interface for interacting with the OpenCTI threat intelligence platform. Built with TypeScript and leveraging the Model Context Protocol SDK, it offers a streamlined way to query and manipulate threat intelligence data. The server implements OpenCTI API authentication and endpoint configuration, enabling AI systems to easily access and analyze cyber threat information. This implementation is particularly valuable for security teams and researchers working with threat intelligence, facilitating use cases such as automated threat analysis, indicator enrichment, and integration of threat data into AI-driven security workflows.

## Trust

- **Trust score (0–1):** 0.50
- **Verification tier:** unverified

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** security
- **Updated:** 2026-04-25

## Source

- **Source listing:** [PulseMCP](https://www.pulsemcp.com/servers/spathodea-network-opencti)
- **Repository:** <https://github.com/spathodea-network/opencti-mcp>

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "spathodea-network-opencti"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/spathodea-network-opencti` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/spathodea-network-opencti/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
