Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Exceptions

ASecurity

The Checkpoint Harmony Email (Avanan) whitelist and blacklist surface: the match fields and matching modes an exception accepts, the defaults that widen an entry beyond what was typed, the id mismatch between listing and editing, and the standing security consequence of a detection bypass.

48 stars
0 votes
0 copies
1 views
Added 10/2/2026
ai-agentsgoapisecurity

Works with

cliapimcp

Security Analysis

A100/100

Scanned 10/2/2026

$npx -y skills add wyre-technology/msp-claude-plugins --skill exceptions --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Exceptions?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Exceptions
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/wyre-technology-exceptions/badge)](https://www.skillsdirectory.com/skills/wyre-technology-exceptions)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: "Checkpoint Avanan Exceptions"
description: >
  The Checkpoint Harmony Email (Avanan) whitelist and blacklist surface: the
  match fields and matching modes an exception accepts, the defaults that
  widen an entry beyond what was typed, the id mismatch between listing and
  editing, and the standing security consequence of a detection bypass.
when_to_use: >-
  When reading, adding, editing or removing sender exceptions in Checkpoint
  Harmony Email, or auditing accumulated ones. Use when: checkpoint whitelist,
  avanan whitelist, checkpoint blacklist, allow list, block list, sender
  exception, hec_list_exceptions, hec_add_exception, exempt sender, block
  domain, or exception hygiene review.
---

# Checkpoint Harmony Email Exceptions

## Overview

Exceptions are Harmony Email's two standing lists. A **whitelist** entry
exempts matching mail from the detection engines; a **blacklist** entry
condemns it. They are the only configuration surface this plugin can write,
and each entry persists tenant-wide until someone removes it. MSP work here
is adding narrow, justified entries and auditing the ones that accumulated.

## Anti-triggers

- **Policy configuration** — enabling, disabling, tuning or scoping a
  security policy, adjusting engine sensitivity, editing DLP rules or
  impersonation-protection rosters. **No tool in this plugin reaches any of
  it**, and no sibling skill covers it; that work is console-only. Exceptions
  are not policies.
- **Delivering one held message** — a release is a message action, not a list
  entry. Use `avanan-quarantine`.
- **Which policy or engine fired** — use `avanan-threats`.
- **Microsoft 365 tenant policy** — conditional access, transport rules and
  security baselines are not Harmony Email exceptions. Use `cipp-standards`
  or `cipp-mailboxes`.
- **Another vendor's lists** — SpamTitan is `spamtitan-lists`. The `mimecast`
  plugin has no managed-sender skill; it covers message tracking, delivery
  queues and threat intelligence only.

## The four tools

Every call requires `excType`, valued `whitelist` or `blacklist` — including
`hec_list_exceptions`, which lists one list at a time. Auditing both means
two calls.

| Tool | Requires | Notes |
|---|---|---|
| `hec_list_exceptions` | `excType` | Returns the whole list; no paging |
| `hec_add_exception` | `excType` + ≥1 match field | |
| `hec_update_exception` | `excType`, `excId` | Full replace of supplied fields |
| `hec_delete_exception` | `excType`, `excId` | Irreversible |

**The id argument is not the id field you were given.**
`hec_list_exceptions` returns each entry's identifier as `entityId`, but
`hec_update_exception` and `hec_delete_exception` take it as `excId`. Passing
it under the name it arrived with fails schema validation.

`excId` is also unrelated to the `entityId` of a mail entity, despite the
shared field name — an exception id is not a message id.

## Match fields

An add needs at least one of these; a bare `excType` is rejected.

| Field | Matches |
|---|---|
| `senderEmail` | Sender address |
| `senderDomain` | Sender domain |
| `senderName` | Sender display name |
| `recipient` | Recipient address |
| `subject` | Subject line |
| `attachmentMd5` | Attachment MD5 hash |
| `comment` | Free text — not a match field, but the audit trail |

Supplying several narrows the entry: they combine, so `senderEmail` plus
`subject` matches only mail meeting both.

### Matching modes and their defaults

Each mode governs how loosely its field matches, and **the defaults are wider
than most people intend**:

| Mode | Values | Default |
|---|---|---|
| `senderEmailMatching` | `matching`, `contains` | `matching` |
| `senderDomainMatching` | `contains`, `endswith` | `endswith` |
| `subjectMatching` | `matching`, `contains` | `contains` |

`senderDomain` defaults to `endswith`, so `example.com` also exempts
`notexample.com` and `evil-example.com`. Set `senderDomainMatching` to
`contains` only deliberately — it is wider still, not narrower. There is no
exact-match mode for a domain; a truly exact exemption has to be written as a
`senderEmail` entry, or as one `senderDomain` entry per address you accept.

`subject` defaults to `contains`, which makes a short subject exception
alarmingly broad.

### Fields the schema does not advertise

The handler also forwards `linkDomains`, `linkDomainMatching`,
`senderNameMatching`, `recipientMatching`, `ignoringSpfCheck`,
`senderClientIp`, `senderIp` and `actionNeeded` when supplied, but the
published input schema does not declare them. A strict MCP client will strip
them before the call. Treat them as unsupported unless you have confirmed
they survived — check the returned entry rather than assuming.

`ignoringSpfCheck` in particular turns a whitelist entry into a bypass of
sender authentication as well as content inspection.

## Security semantics

A whitelist entry is a **standing detection bypass**, not a note. It exempts
matching mail from the engines that would otherwise catch it, permanently and
tenant-wide, and it is the first thing an attacker wants. Mail spoofing the
exempted sender inherits the exemption — which is why a domain-level entry
with the default `endswith` mode is a materially different object from the
single-sender exemption someone thought they were creating.

Adding one changes no mail flow at the moment it runs, which is exactly why it
reads as harmless. A pattern of agent-created whitelist entries is a signal to
review, not a productivity win.

Deleting an exception is equally consequential in reverse: it re-admits
detection for a sender somebody deliberately exempted. That may be the right
fix, or it may break a customer's mail flow tomorrow. The delete is a POST to
a `/delete/` path and is annotated irreversible — there is no undo and no
soft-delete.

## Auditing accumulated exceptions

`hec_list_exceptions` returns `entityId`, the match fields, `comment`,
`addedBy` and `updateTime` — enough for a hygiene pass without any other call.

1. List both `whitelist` and `blacklist`.
2. Flag entries with an empty `comment` — no recorded justification.
3. Flag `senderDomain` entries where a `senderEmail` would have sufficed, and
   any entry relying on the `endswith` or `contains` defaults.
4. Sort by `updateTime` and flag anything unreviewed beyond the customer's
   agreed interval.
5. Cross-check `addedBy` against current staff — entries from departed
   technicians rarely have a live owner.
6. Produce a review list. Do not delete unilaterally: removal needs the
   technician or customer who can say whether the mail flow still matters.

Narrowing an over-broad entry is `hec_update_exception`, not delete-and-add —
it preserves the id and the `addedBy` history.

## Gotchas

- **No paging, no filtering.** `hec_list_exceptions` returns the entire list
  for one type. On a large tenant that is a large response; there is no
  server-side search.
- **No expiry.** Nothing in the surface sets a review or sunset date. A
  "temporary" exception is permanent unless a human returns to it, so the
  `comment` field is the only place a sunset date can live.
- **Updates replace what they touch.** `hec_update_exception` applies the
  fields you send; re-send the fields you intend to keep rather than assuming
  a partial merge preserves them.
- **`attachmentMd5` is MD5, not SHA-256.** Hashes carried from an EDR or
  threat feed usually need converting or re-sourcing.

## Related Skills

- [Checkpoint Quarantine](../quarantine/SKILL.md) — acting on one message
- [Checkpoint Threats](../threats/SKILL.md) — what the engines caught
- [Checkpoint API Patterns](../api-patterns/SKILL.md) — ids, auth, regions

Attribution

WYRE-AIWYRE-AI
View sourceSee grades on GitHubMore from wyre-technology →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Caveman

Terse caveman voice: answer first, fluff gone, every technical fact kept. Use for /caveman, "caveman mode", "talk like caveman", "be brief", "less tokens". Stays on until "stop caveman" or "normal mode".

1100021 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

698461 votes

Writing Skills

Create and manage Claude Code skills in HASH repository following Anthropic best practices. Use when creating new skills, modifying skill-rules.json, understanding trigger patterns, working with hooks, debugging skill activation, or implementing progressive disclosure. Covers skill structure, YAML frontmatter, trigger types (keywords, intent patterns), UserPromptSubmit hook, and the 500-line rule. Includes validation and debugging with SKILL_DEBUG. Examples include rust-error-stack, cargo-dep...

3931 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3421 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Amp, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Grok Build, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

741 votes
View all in ai-agents →