
Claude Skills by WYRE-AI
github.com/WYRE-AIrunZero API fundamentals: the available MCP tools, Bearer-token authentication, the Export API for bulk retrieval, pagination, rate-limit headers, error codes, and the runZero query language.
The runZero asset inventory: searching and browsing assets, asset attributes, OS fingerprinting, hardware details, and network interfaces.
runZero discovered services: listing services, filtering by port or protocol, identifying vulnerabilities, and auditing exposed services across sites.
runZero sites: creating and managing organization sites, defining scan scope and exclusions, deploying explorers, and organizing assets by location or client.
runZero scan tasks: creating scans, scheduling recurring scans, managing explorers, configuring scan parameters, and reviewing scan results.
runZero wireless network discovery: discovered wireless networks, rogue access point identification, wireless security configuration analysis, and SSID auditing.
SaaS Alerts MCP fundamentals: API-key authentication via the gateway header, the MSP → customer → account → user hierarchy, navigation and functional tool naming, event filter parameters, cursor pagination, and HTTP error codes.
Triaging the SaaS Alerts queue across managed M365 / Google Workspace tenants: the triage tool surface, the critical-first sweep, per-customer summary and cross-tenant pattern workflows, the low/medium/critical severity model and its default dispositions, and the edge cases — legitimately empty results, time-window sensitivity, whitelist suppression, and per-partner rate limits.
CRM pipeline health assessment against whatever CRM is discovered through the gateway: stage-velocity norms derived from closed-won deals, activity-based stalled-deal detection, raw and quality-adjusted pipeline coverage against a revenue target, and the CRM-less degradation rule (report nothing rather than fabricate figures).
The quote-to-close handoff chain — a Pax8/Sherweb/Kaseya Quote Manager quote or SalesBuildr proposal, through a PandaDoc document's sent/viewed/signed status, to a closed-won CRM deal — and the four distinct stall points along it (quote built with no proposal document, proposal sent but not opened, viewed but not signed, signed but the CRM deal never marked closed-won), including cross-system record matching and what to report when only part of the chain is connected.
Lead-warmth scoring from intent and engagement signals — Warmly website-visitor identification, CRM form fills and email engagement, and Calendly booking activity — using an explainable Hot/Warm/Warm-Cool/Cool tiering, plus routing recommendations based on owner continuity, CRM routing rules, or rep capacity, and the degradation path to CRM-only signals when intent tools aren't connected.
Salesbuildr API fundamentals: api-key header authentication, offset-based from/size pagination, error handling, and the 500 requests per 10 minutes rate limit.
Salesbuildr companies and contacts: company search, contact filtering by company, and contact creation with its required fields.
Salesbuildr opportunities: pipeline search, opportunity creation, stage updates, and deal values, plus how opportunities link companies and contacts to potential revenue.
Salesbuildr product catalog: product search, pricing lookup, category browsing, and how products become quote line items.
Salesbuildr quotes: quote creation with product line items, quote search, and retrieving quote details, plus how quotes link to companies, contacts, and opportunities.
ScalePad MCP fundamentals: API-key authentication via the `X-ScalePad-Api-Key` header, tool discovery across the five product domains, cursor pagination, the 50-requests-per-5-seconds rate limit, and 402 subscription errors.
ScalePad Backup Radar, the read-only backup monitoring surface: per-client backup health records and backup device inventory, in regions us and eu.
ScalePad ControlMap per-client compliance management: risk registers, control libraries, evidence collection, policies and procedures, framework objectives, assessments, and remediation action items across regions us, eu, ca, and au.
The ScalePad Core API — the read-only, US-only unified data layer over clients, contacts, members, sites, opportunities, hardware and SaaS assets, the product catalog, service contracts, tickets, and integration configurations.
ScalePad Lifecycle Manager, the engagement and roadmap workflow product: initiatives, goals, meetings, action items, assessments, deliverables, budget forecasting, contracts, notes, hardware lifecycle records, and warranty pricing.
Quoter through ScalePad: building and publishing quotes, managing the catalog (items, item groups, tiers, options, manufacturers), quote contacts, suppliers and datafeeds, and the OAuth helpers for the standalone api.quoter.com path.
A common Critical/High/Medium/Low normalized severity model for security alerts, incidents, and findings, with the judgment axes (confidence, mitigation state, blast radius) that place a record in a tier and the mapping from each vendor's native terminology — Huntress incident status, SentinelOne threat confidence, Blumira finding priority, CIPP alert queue severity, Blackpoint Cyber SOC severity, SaaS Alerts risk level — plus how to discover which security vendors are actually connected.
Business Email Compromise detection and first response: the signals that reveal it in CIPP/M365 audit logs, mailbox and forwarding rules, and connected email security vendor alerts; the order-dependent response sequence (session revocation, forwarding-rule audit, mailbox rule and delegate cleanup, password reset, MFA re-enrollment, lateral-spread check, recipient notification); and what a defensible incident timeline must capture for insurance or bank-fraud claims.
Ordered first-response containment sequences for the most common MSP incident classes — compromised account, malware/ransomware detection, business email compromise, and exposed credential — including why the order matters, which connected tool family (RMM, EDR, CIPP/Entra, PSA, documentation) handles each step, and the evidence-preservation principles that apply across all of them.
SentinelOne's read-only unified alert surface: the list/search/get alert tools plus notes and history, severity levels, status values, view types, GraphQL filter syntax, and cursor-based pagination.
The SentinelOne Purple MCP server and the APIs behind it: uvx installation and transport modes, Service User token levels, the 23 read-only tools organized by domain, and the dual GraphQL (cursor pagination) / REST (offset pagination) architecture with its differing filter syntaxes, rate limits, and error causes.
SentinelOne's unified asset inventory across four surface types — agent-managed endpoints, AWS/Azure/GCP cloud resources, AD/Entra identities, and Ranger-discovered network devices. Covers the read-only inventory tools, the REST (not GraphQL) offset-pagination and filter model, asset field reference, and agent-coverage audit workflows.
Cloud security posture findings from SentinelOne's XSPM module across AWS, Azure, GCP, Kubernetes, identity providers, and infrastructure-as-code. Covers the read-only misconfiguration tools, view types, severity and status values, compliance-standard and MITRE ATT&CK mappings, evidence fields, and remediation guidance.
The `purple_ai` tool — SentinelOne's natural language investigation assistant over the full Singularity telemetry model. Covers how to phrase investigative prompts, behavioral anomaly and MITRE ATT&CK TTP analysis, PowerQuery generation, and handing generated queries to the `powerquery` tool for execution.
PowerQuery against the Singularity Data Lake: the Scalyr-based pipeline syntax (distinct from SPL, SQL, KQL, and Elasticsearch DSL), the powerquery, get_timestamp_range, and iso_to_unix_timestamp tools, time-range and row-limit handling, common hunting scenarios, and the Purple AI generation path.
CVE tracking through SentinelOne's XSPM module: the read-only vulnerability tools, EPSS scores and exploit-maturity values and why they outrank raw CVSS severity for prioritization, status values and their transitions, the vulnerability field reference, and patch-prioritization and reporting workflows.
Reconciling cloud marketplace subscriptions (Pax8) against accounting invoices (Xero, QuickBooks Online): the matching strategy, billing gaps, unbilled subscriptions, and margin discrepancy analysis.
Vendor-agnostic cross-tool incident correlation: combining PSA tickets, RMM device state, documentation-platform assets, and configuration- monitoring changes into a unified incident summary across Kaseya, ConnectWise, HaloPSA, Syncro, Atera, and similar MSP stacks.
MSP industry terminology: acronyms, roles, contract and billing concepts, and the vocabulary used across PSA, RMM, documentation, and security platforms.
Vendor-agnostic PSA ticket triage: priority determination, categorization, routing, and initial response practices applicable to Autotask, ConnectWise, HaloPSA, and other platforms.
WYRE MCP Gateway diagnostics: missing vendor tools, OAuth failures, "Failed to update tool access" errors, expired credentials, and the request flow through mcp-remote to gateway to vendor container to external API.
Sherweb Partner API fundamentals: OAuth 2.0 client-credentials auth, token caching, subscription-key header, scopes and base URLs, endpoint and MCP tool catalog, page-based pagination, Accept-Language localization, rate limits, and error codes.
Sherweb distributor billing: explicit billing date ranges, Setup/Recurring/Usage charge types, billing cycles (OneTime, Monthly, Yearly), the pricing breakdown (listPrice, netPrice, prorated, subTotal), promotional and performance deductions, fees, taxes, and MSP margin calculation. Also covers what this plugin cannot retrieve: there is no billing-period enumeration and no invoice surface.
Sherweb customer records: the distributor > service provider > customer hierarchy and its API scoping consequences, customer lifecycle stages, core address and contact fields, accounts-receivable data with aging buckets, and cross-referencing customers with PSA, subscription, and billing data.
Sherweb subscription management: the subscription lifecycle and its states, seat/license quantity rules (absolute values, minimums, proration, commitment restrictions), the quantity-change workflow, subscription and change-response fields, and state-transition errors.
SpamTitan MCP fundamentals: the available tool catalog and its exact parameters, API-key header authentication, API structure, pagination, rate limiting, and error handling. Includes the tenant-isolation limit — spamtitan_get_queue takes no domain filter.
SpamTitan sender allowlists and blocklists: the add/remove/list action parameter, entry types, allowlisting trusted senders to prevent false positives, blocking unwanted senders and domains, and the scoping limit — neither manage tool takes a domain parameter.
SpamTitan quarantine queue: quarantine types, release vs. delete semantics, message aging, email flow statistics, and the tenant-isolation limit — the queue listing accepts no domain filter, so on a multi-tenant appliance it spans every customer.
SuperOps.ai RMM alerting: alert types, severity levels, status lifecycle and valid transitions, asset/client/monitor associations, and the GraphQL operations for listing, acknowledging, resolving, and converting alerts into tickets. Includes triage, dashboard, and client-reporting workflows.
SuperOps.ai GraphQL API fundamentals: Bearer token plus CustomerSubDomain header auth, region-specific endpoints, request/variable structure, cursor pagination, the 800 req/min rate limit, filter operators, UTC date handling, error codes, and null-reset semantics.
SuperOps.ai RMM asset inventory: asset status and platform enums, hardware, network, OS and association fields, software inventory, disk usage, patch status, activity history, and the GraphQL queries and script-execution mutations behind them. Includes health-check, patch-compliance, and software-audit workflows plus remote-action readiness checks.
SuperOps.ai client (account) management: stage and status enums, core/business/ address fields, client CRUD mutations, site and contact (requester) management, custom fields, soft vs. hard delete, and onboarding workflows.
SuperOps.ai RMM script automation: script types and OS targeting, run-as contexts, execution priority, parameterized arguments, single-asset and batch execution, recurring schedules, execution status polling, and exit-code interpretation.
SuperOps.ai service desk ticketing: ticket fields, status and priority enums, client/site/requester/assignee associations, notes, time entries, and the GraphQL mutations and queries behind them. Includes triage and escalation workflows, input validation rules, and common ticket API errors.