Agent skill · security · membranedev

recorded-future

Recorded Future integration. Manage data, records, and automate workflows. Use when the user wants to interact with Recorded Future data.

Why this skill is useful

Adds specific commands and workflows for integrating with Recorded Future's threat intelligence platform that the AI wouldn't reliably generate on its own.

What it needs

Requires @membranehq/cli installed locally. Requires membrane account access. About 4k tokens when loaded. Last updated 2026-04-28. 253 stars on the source repository.

What this skill does

Recorded Future Recorded Future is a threat intelligence platform that collects and analyzes information from the web to identify emerging threats. Security teams and intelligence analysts use it to proactively protect their organizations from cyberattacks. It helps them understand risks, prioritize vulnerabilities, and disrupt malicious activity. Official docs: https://api.recordedfuture.com/v2/ Recorded Future Overview Intelligence List Entity Rule Risk Rule User Dashboard Report Attack Surface Entity Vulnerability Use action names and parameters as needed. Working with Recorded Future This skill uses the Membrane CLI to interact with Recorded Future. Membrane handles authentication and credentials refresh automatically — so you can focus on the integration logic rather than auth plumbing. Install the CLI Install the Membrane CLI so you can run membrane from the terminal: Authentication This will either open a browser for authentication or print an authorization URL to the console, depending on whether interactive mode is available. Headless environments: The command will print an authorization URL. Ask the user to open it in a browser. When they see a code after completing login, finish with: Add --json to any command for machine-readable JSON output. Agent Types : claude, openclaw, codex, warp, windsurf, etc. Those will be used to adjust tooling to be used best with your harness Connecting to Recorded Future Use membrane connection ensure to find or create a connection by app URL or domain: The user completes authentication in the browser. The output contains the new connection id. This is the fastest way to get a connection. The URL is normalized to a domain and matched against known apps. If no app is found, one is created and a connector is built automatically. If the returned connection has state: "READY", skip to Step 2. 1b. …

How to use it

Reference it in AdaL, Claude Code, Cursor or any coding agent — nothing to install:

@skills membranedev/recorded-future

View the source on GitHub

Browse the @skills marketplace