Skip to content

opentidehq/opentide-detection-skills

v1.0.0EUPL-1.2

Detection engineering skills for OpenTide — TVM, DOM, and MDR authoring, hunt-to-rule workflows, MITRE ATT&CK, platform query languages, and defensive internals — with the OpenTide MCP server.

OpenTide Skills

skills.sh

Canonical home for reusable Agent Skills for detection engineering — 27 skills, one plugin (opentide-detection-skills). The machine-readable catalogue for opentide setup skills is manifest.json.

Install

Install the OpenTide MCP server once. The plugin starts it as opentide-mcp on PATH.

pip install 'opentide[mcp]'

Then use the command for your agent. Each one installs this repository.

AgentCommand
skills.shnpx skills add OpenTideHQ/skills
Cursor/add-plugin OpenTideHQ/skills
Claude Code/plugin marketplace add OpenTideHQ/skills then /plugin install opentide-detection-skills@opentide
VS CodeCommand Palette → Chat: Install Plugin From Source → OpenTideHQ/skills
Copilot CLIcopilot plugin marketplace add OpenTideHQ/skills then copilot plugin install opentide-detection-skills@opentide
CodexIn this repo, run /plugins and install opentide-detection-skills
KiroPowers → Add Custom Power → Import from GitHub → https://github.com/OpenTideHQ/skills

Copy AGENTS.md into a detection project when the agent reads project instructions from the workspace root.

VS Code needs chat.plugins.enabled. A conforming client starts opentide-mcp in this plugin root. Point the server at the detection content repository when that working directory is this skills repository. See the OpenTide MCP configuration.

skills.sh.json groups the skills.sh repository page. skills.sh reads that file from the default branch on the next npx skills add.

Longer notes for each harness: docs/install.md.

Architecture

Skills live once under skills/. Harness manifests at the repository root point at that tree.

plugin.json                      # Agent Plugins 1.0.0 manifest
mcp.json                         # OpenTide MCP server (opentide-mcp, stdio)
skills.sh.json                   # skills.sh repository page groups
skills/                          # Canonical skills (only copy in git)
AGENTS.md                        # Unified agents.md entrypoint
POWER.md                         # Kiro Power (legacy activation; plugin.json is preferred)
steering/                        # Kiro workflow routing (points at skills/)
.cursor-plugin/plugin.json       # Cursor compatibility manifest
.claude-plugin/plugin.json       # Claude Code manifest (mcpServers → ./mcp.json)
.codex-plugin/plugin.json        # OpenAI Codex compatibility manifest
.plugin/plugin.json              # Legacy OpenPlugin compatibility manifest
rules/                           # Cursor rules (optional)

Install-time caching may copy files into a local plugin cache on the user's machine. That cache is platform behaviour, and this repository keeps a single copy.

Still to publish

These installs work from GitHub today. The remaining catalogue submissions are tracked in #19.

CatalogueWhat is left
Cursor MarketplaceSubmit this repository. Listing is manually reviewed. The plugin icon is docs/opentide-icon.svg.
Claude communityRun claude plugin validate ., then submit. The official Claude catalogue is invite-only.
Awesome CopilotOpen a pull request using that repository's contributing guide.
ChatGPT / Codex directorySubmit the plugin for the shared public directory.
Kiro PowersGitHub import works now. A curated registry listing still needs the Kiro submission path.
GitHub skill searchAdd the repository topic agent-skills, then gh skill publish.

The engine task for opentide setup installing this plugin is opentide#431.

Contributing

  1. Edit skills under skills/<skill-name>/SKILL.md.
  2. Run ./scripts/validate-skills.sh (frontmatter checks and manifest drift gate).
  3. Regenerate the catalogue: ./scripts/build-manifest.sh (commits manifest.json).
  4. Open a pull request.

manifest.json is the catalogue source for opentide setup skills discover|show|install. Harness plugin manifests at the repo root still point at ./skills/.

See skills/README.md for authoring conventions.

The OpenTide mark is copied from OpenTideHQ/.github (logo-normal.svg, icon-normal.svg). Marketplace marks in this README identify install targets and belong to their respective owners.

License

Licensed under the European Union Public Licence v. 1.2 (EUPL-1.2).