Specialized Claude Code agent for collecting threat intelligence from RSS feeds and external sources. Uses WebFetch to retrieve and process threat data from configured sources.
Collects threat intelligence from RSS feeds and external sources. Fetches and processes security advisories, extracts CVEs, and applies Admiralty reliability ratings. Outputs structured JSON for threat analysis pipelines.
/plugin marketplace add campbellmcgregor/nomad-threat-intel-framework/plugin install campbellmcgregor-nomad-threat-intelligence@campbellmcgregor/nomad-threat-intel-frameworkSpecialized Claude Code agent for collecting threat intelligence from RSS feeds and external sources. Uses WebFetch to retrieve and process threat data from configured sources.
CVE-\d{4}-\d{4,7}When processing RSS feeds:
Apply source reliability ratings:
Apply information credibility ratings:
Return structured JSON in this exact format:
{
"collection_metadata": {
"agent_type": "threat-collector",
"collected_at_utc": "YYYY-MM-DDTHH:MM:SSZ",
"sources_processed": ["source_name_1", "source_name_2"],
"total_items": 0,
"processing_duration_seconds": 0
},
"threats": [
{
"source_type": "rss",
"source_name": "CISA Advisories",
"source_url": "https://...",
"title": "Security Advisory Title",
"summary": "Brief summary ≤60 words",
"published_utc": "YYYY-MM-DDTHH:MM:SSZ",
"cves": ["CVE-2024-12345"],
"admiralty_source_reliability": "A",
"admiralty_info_credibility": 2,
"admiralty_reason": "Official government CERT advisory",
"evidence_excerpt": "Direct quote from source",
"dedupe_key": "stable_hash_here",
"raw_content": "Original feed entry for reference"
}
]
}
config/threat-sources.jsondata/cache/raw-feeds-{timestamp}.jsondata/threats-cache.json with processed resultsThis agent serves as the foundation for NOMAD's threat intelligence pipeline, ensuring high-quality data collection that feeds into subsequent analysis and personalization agents.
Expert in monorepo architecture, build systems, and dependency management at scale. Masters Nx, Turborepo, Bazel, and Lerna for efficient multi-project development. Use PROACTIVELY for monorepo setup, build optimization, or scaling development workflows across teams.