
Claude Skills by wyre-technology
github.com/wyre-technologyUse this skill when [describe the trigger conditions - what user requests or contexts should activate this skill]. Include specific scenarios and use cases.
Use this skill when working with Abnormal Security account takeover (ATO) detection - suspicious sign-ins, impossible travel, compromised accounts, mailbox rule changes, and lateral movement indicators. Covers account takeover cases, investigation workflows, and remediation actions. Essential for MSP security analysts investigating compromised accounts detected by Abnormal Security.
Use this skill when working with the Abnormal Security REST API - Bearer token authentication, base URLs, rate limiting, pagination, OData filtering, error handling, and common API patterns. Covers token management, request/response formats, and integration best practices. Essential for developers and MSP administrators integrating with the Abnormal Security API.
Use this skill when working with Abnormal Security abuse mailbox cases - user-reported emails, case triage, remediation actions, case lifecycle, and phishing simulation management. Covers case statuses, judgments, bulk actions, and MSP workflows for managing user-reported suspicious emails. Essential for MSP security analysts triaging abuse mailbox submissions in Abnormal Security.
Use this skill when working with Abnormal Security message analysis - email headers, attachments, sender reputation, delivery context, authentication results (SPF/DKIM/DMARC), and message metadata. Covers message retrieval, header inspection, and contextual analysis for incident investigation. Essential for MSP security analysts performing deep message analysis in Abnormal Security.
Use this skill when working with Abnormal Security threat detection and analysis - BEC, phishing, malware, socially-engineered attacks, spam, graymail, and credential theft. Covers threat types, attack vectors, severity assessment, remediation actions, and investigation workflows. Essential for MSP security analysts investigating email-borne threats detected by Abnormal Security's AI-powered behavioral engine.
Use this skill when working with Abnormal Security VendorBase vendor risk assessment - vendor risk scores, compromised vendor detection, vendor domain analysis, and supply chain email threat monitoring. Covers vendor risk levels, risk factors, compromised vendor workflows, and vendor-related threat investigation. Essential for MSP security analysts monitoring third-party vendor risk via Abnormal Security.
Use this skill when working with Atera RMM agents - listing, searching, monitoring, or executing commands on managed devices. Covers agent information, online/offline status, PowerShell execution, and agent lifecycle. Essential for MSP technicians managing endpoints through Atera RMM.
Use this skill when working with Atera alerts - viewing, acknowledging, resolving, or managing alerts from monitored devices. Covers alert types, severity levels, alert sources, and alert-to-ticket conversion. Essential for MSP monitoring operations through Atera.
Use this skill when working with Atera customers and contacts - creating, updating, searching, or managing customer records. Covers customer information, contact management, custom fields, and customer lifecycle operations. Essential for MSP account management through Atera.
Use this skill when working with Atera device monitors - HTTP, SNMP, and TCP monitors for network devices, services, and applications. Covers monitor types, configuration, thresholds, and monitoring best practices. Essential for MSP network monitoring through Atera.
Use this skill when working with Atera tickets - creating, updating, searching, or managing service desk operations. Covers ticket fields, statuses, priorities, comments, work hours, and billing duration. Essential for MSP technicians handling service delivery through Atera.
Use this skill when working with Auvik network and interface entities - the network entity model, IP-range scoping, interface-to-device relationships, and admin vs oper status.
Use this skill when connecting the azure-mcp vendor through the WYRE MCP Gateway — registering an Azure service principal, supplying tenantId/clientId/clientSecret, and granting least-privilege Reader-tier RBAC. Covers the read-only deployment model and why broader write roles must not be granted.
Use this skill for Azure cost, pricing, capacity, and inventory work through the azure-mcp connector — retail pricing lookups, subscription quota and usage-limit checks, and listing/inspecting subscriptions and resource groups. All read-only.
Use this skill for Azure observability, diagnostics, and resource-health work through the azure-mcp connector — pulling Azure Monitor metrics, running Log Analytics KQL queries, checking alert state, reading Resource Health status, triaging AppLens diagnostics, and reviewing Azure Advisor recommendations. All read-only.
Use this skill when working with Better Stack incidents -- listing, triaging, acknowledging, and resolving incidents triggered by uptime monitors or manual reports.
Use this skill when working with Better Stack log management (Logtail) -- querying logs, managing log sources, structured log search, log-based alerting, and log analysis workflows.
Use this skill when working with Better Stack uptime monitors -- listing, creating, updating, pausing, and deleting monitors, heartbeat monitors, monitor groups, and check types.
Use this skill when working with Better Stack on-call schedules -- on-call calendars, escalation/notification policies, rotation management, understanding who is currently on-call, and responding to active incidents via the on-call flow.
Use this skill when working with Better Stack status pages -- managing status pages, adding resources/components, posting maintenance windows, and communicating service status to end users.
Use this skill when working with Blackpoint Cyber (CompassOne) asset data — listing assets by class for a tenant, searching across classes, pulling asset detail, and walking parent/child/sibling relationships to build a blast-radius or topology view.
Use this skill when investigating a Blackpoint Cyber detection — drilling from a tenant to its assets, walking the detection list, pulling vulnerability and dark-web context, and assembling an incident timeline.
Use this skill when operating Blackpoint Cyber (CompassOne) at the MSP partner level — enumerating customer tenants, sweeping detections and vulnerabilities across all of them, spotting volume anomalies, and building per-tenant scorecards.
Use this skill when analyzing Blackpoint Cyber (CompassOne) exposure data — host vulnerability findings filtered by CVE and exploitability, vulnerability scan history, dark-web credential and data leaks, and external internet-facing exposures.
Use this skill when working with Blumira findings (security alerts/detections), including listing, filtering, investigating, resolving, assigning, and commenting on findings.
Use this skill when working with Blumira MSP (Managed Service Provider) multi-tenant operations, including managing multiple client accounts, cross-account finding queries, and per-account device/user management.
Use this skill when resolving Blumira findings, choosing the correct resolution type, or understanding resolution workflows and their impact on security metrics.
Use this skill when listing or looking up Blumira users, finding user IDs for finding assignment, or auditing user access.
Use this skill when listing or creating M365 groups in CIPP — security groups, distribution lists, M365 groups, mail-enabled security groups. Covers tenant-scoped group enumeration and creation as part of user onboarding or access-management workflows.
Use this skill when working with M365 license assignments and CSP license inventory through CIPP — listing license usage per tenant, identifying unused licenses, surfacing license SKUs available for assignment, and reviewing CSP-level license commitments. Drives license-rightsizing reports for MSP billing reviews.
Use this skill when working with Exchange Online mailboxes through CIPP — listing mailboxes, auditing mailbox permissions, configuring out-of-office auto-replies, and setting email forwarding. Covers the mailbox surface most relevant to MSP operations: offboarding, leave coverage, BEC remediation.
Use this skill when working with CIPP operational tooling — GDAP role and invite management, scheduled tasks, server health checks, version reporting, and CIPP application logs. Covers the meta-layer: keeping CIPP itself healthy and properly delegated to managed tenants.
Use this skill when reviewing M365 conditional access policies and named locations through CIPP — auditing CA coverage, finding policies that exclude critical apps, listing trusted IP ranges, identifying tenants without baseline conditional access. Read-only surface focused on security posture review.
Use this skill when working with CIPP Standards, Best Practice Analyser (BPA), and domain health checks — listing configured standards per tenant, triggering on-demand compliance checks, retrieving BPA results, checking SPF/DKIM/DMARC. The core surface for CIPP's tenant-baseline enforcement model.
Use this skill when working with CIPP tenants — listing managed M365 tenants, checking tenant details, identifying tenant ID/domain, and scoping operations to a specific tenant. The starting point for almost every CIPP workflow since most other tools require a tenant filter.
Use this skill when working with ConnectWise Automate clients - creating, reading, updating, and deleting client organizations. Covers client identifiers, locations, client-level settings, groups, extra data fields (EDFs), and client hierarchy management.
Use this skill when working with ConnectWise Automate computers/endpoints - listing, searching, managing, and monitoring devices. Covers computer identifiers (ComputerID, Name, MAC), computer statuses (online/offline), hardware/software inventory, patch status, antivirus status, and remote management operations.
Use this skill when working with ConnectWise Automate scripts - listing, executing, passing parameters, and retrieving results. Covers script types (PowerShell, batch, VBScript), script folders, script execution on computers, parameter handling, execution history, and result retrieval.
Use this skill when working with ConnectWise PSA companies - creating, updating, searching, or managing company/account records. Covers company types, statuses, sites/locations, custom fields, and company relationships. Essential for MSP account management and CRM operations in ConnectWise PSA.
Use this skill when working with ConnectWise PSA contacts - creating, updating, searching, or managing contact records. Covers contact types, communication items (email, phone), portal access, and relationships to companies. Essential for MSP customer relationship management in ConnectWise PSA.
Use this skill when working with the ConnectWise PSA product catalog — searching, creating, or updating catalog items (SKUs), managing categories, subcategories, manufacturers, or using catalog items on quotes, opportunities, agreements, and tickets. Covers the full catalog item field reference, the common MSP workflows (hardware SKU, software license, managed service, agreement add-on), and the passthrough pattern for fields not surfaced on the MCP tool directly.
Use this skill when working with ConnectWise PSA projects - creating, updating, managing project phases, templates, and resource allocation. Covers project lifecycle, budgeting, billing methods, and project tickets. Essential for MSPs delivering project-based services through ConnectWise PSA.
Use this skill when working with ConnectWise PSA time entries - creating, updating, searching, or managing time tracking. Covers billable vs non-billable time, work types, work roles, time approval, and time sheet operations. Essential for MSPs tracking technician time and billing in ConnectWise PSA.
Use this skill when working with Crewhu CSAT/NPS surveys — listing recent responses, drilling into a specific survey, isolating detractors and promoters for follow-up, and rolling responses up by user.
Use this skill when working with Domotz Eyes -- TCP and HTTP sensors, custom monitoring checks, synthetic tests, latency tracking, and service availability monitoring.
Use this skill when working with Domotz network operations -- network scanning, SNMP polling, port monitoring, speed tests, and network topology discovery.
Use this skill when working with Checkpoint Harmony Email security policies - DLP policies, anti-phishing rules, anti-malware settings, quarantine policies, allow/block lists, and policy configuration. Covers policy types, enable/disable workflows, policy effects, and policy tuning best practices. Essential for MSP administrators managing email security policies across customer tenants in Checkpoint Harmony Email & Collaboration (Avanan).
Use this skill when working with Checkpoint Harmony Email quarantine - listing, searching, releasing, deleting quarantined emails. Covers quarantine reasons, release workflows, bulk operations, and quarantine policies. Essential for MSP security analysts managing email quarantine across customer tenants in Checkpoint Harmony Email & Collaboration (Avanan).
Use this skill when working with KnowBe4 phishing simulations - creating campaigns, managing security tests, tracking recipient interactions (sent, opened, clicked, reported), calculating phish-prone percentages, and analyzing phishing simulation results. Covers campaign lifecycle, template selection, landing pages, and click tracking. Essential for MSP security teams running phishing awareness programs.