GitHub collection

wyre-ai/msp-claude-plugins

Imported from GitHub — is this yours?

48 skills imported from this repository.

View on GitHub
46 26 Apache-2.0
Claude Skill 3cx

3CX API Patterns

3CX's native PBX MCP server: the per-PBX endpoint shape (every PBX is its own FQDN and its own OAuth authorization server — there is no shared mcp.3cx.com), the Admin Console + client setup flow, the permission model (fully inherited from the 3CX account that approved the connect

LLM Mart

Claude Skill 3cx

3CX Calls, Queues & Profiles

3CX's live-operations surface: read-only visibility into active calls, recordings, voicemail, department and queue membership, and forwarding/presence profiles, plus the write actions that change live call routing — dropping a call, switching a profile, and logging a queue agent

LLM Mart

Claude Skill 3cx

3CX Directory & Contacts

3CX's read-only directory surface: resolving a caller by email or by exact extension, searching the PBX's own phonebooks, searching contacts synced from an integrated CRM, and listing PBX users/extensions.

LLM Mart

Claude Skill 3cx

3CX PBX Admin & Diagnostics

3CX's system-and-configuration surface: server time, PBX event log and application log search, service status, database schema and the read-only SELECT-only Query tool, DIDs, IP and phone blocklists, SIP trunks, call flow apps, and the configuration write/delete actions that chan

LLM Mart

Claude Skill abnormal-security

Abnormal Security API Patterns

Abnormal Security REST API fundamentals: Bearer token authentication, base URLs, rate limiting, pagination, OData filtering, request/response formats, and error handling.

LLM Mart

Claude Skill abnormal-security

Abnormal Security Cases

Abnormal Security abuse mailbox cases: user-reported email submissions, case statuses and judgments, the case lifecycle, bulk and remediation actions, and phishing simulation handling.

LLM Mart

Claude Skill abnormal-security

Abnormal Security Messages

Abnormal Security message analysis: message retrieval, email header inspection, attachments, sender reputation, delivery context, and SPF/DKIM/DMARC authentication results.

LLM Mart

Claude Skill abnormal-security

Abnormal Security Threats

Abnormal Security threat detection: threat types (BEC, phishing, malware, socially-engineered attacks, spam, graymail, credential theft), attack vectors, severity assessment, remediation actions, and investigation workflows.

LLM Mart

Claude Skill atera

Atera Alerts

Atera alerts: alert types, severity levels, alert sources, the acknowledge/resolve lifecycle, and alert-to-ticket conversion.

LLM Mart

Claude Skill atera

Atera API Patterns

Atera REST API fundamentals: X-API-KEY header authentication, OData-style pagination, the 700 requests/minute rate limit, endpoint conventions, and error handling.

LLM Mart

Claude Skill atera

Atera Customers

Atera customers and contacts: customer records and fields, contact management, custom fields, and customer lifecycle operations.

LLM Mart

Claude Skill atera

Atera Tickets

Atera service desk tickets: ticket fields, statuses, priorities, comments, work hours, and billing duration.

LLM Mart

Claude Skill autotask

Autotask API Patterns

Autotask REST API fundamentals: header-based authentication, zone detection, the query/filter DSL (14 operators, logical grouping, includes), pagination, rate limits, and CRUD conventions across the 215+ entity PSA.

LLM Mart

Claude Skill autotask

Autotask Billing

Autotask billing item retrieval, approval-level workflows, and invoice search — covering billing item types, approval status filtering, and reconciliation of billable work against invoices for MSP finance teams.

LLM Mart

Claude Skill autotask

Autotask Configuration Items

Autotask Configuration Item (CI) asset management: CI types and categories, lifecycle status codes, the CI field schema, related-item relationships, DNS records, notes, and contract/billing associations for MSP infrastructure tracking.

LLM Mart

Claude Skill autotask

Autotask Contracts

Autotask contract and service agreement management - contract types (recurring services, block hours, time & materials, fixed price, retainer), service/service bundle associations, SLAs, and how contracts drive billing for MSP account managers.

LLM Mart

Claude Skill autotask

Autotask CRM

Autotask CRM entities - companies (accounts), contacts, and sites/locations - including field references, company type classifications, and how these records underpin tickets, contracts, and projects for MSP account management.

LLM Mart

Claude Skill autotask

Autotask Expenses

Autotask expense report and expense item structure - the report/item parent-child relationship, approval status workflow, expense categories, payment types, and the billable vs reimbursable distinction for MSP operational expenses.

LLM Mart

Claude Skill autotask

Autotask Picklists

Autotask picklist and reference-data lookups — queues, ticket statuses, ticket priorities, and project phases — the instance-specific configured values required before creating or filtering tickets and other entities.

LLM Mart

Claude Skill autotask

Autotask Product Catalog

Autotask product catalog structure - Products, Services, and Service Bundles - and how Price Lists override default unit pricing. Covers product/service fields, inventory tracking, and cost-vs-billing margin analysis for MSP quoting and procurement.

LLM Mart

Claude Skill autotask

Autotask Projects

Autotask project structure - projects, phases, tasks, and milestones - including project and task fields, status values, resource assignment, and how project work links to contract billing for MSP project managers.

LLM Mart

Claude Skill autotask

Autotask Quotes

Autotask quote structure and line items - quote item types (product, service, service bundle, labor, expense, shipping), the mutually-exclusive catalog reference rules, and the three discount mechanisms (unit, line, percentage) used to build customer proposals.

LLM Mart

Claude Skill autotask

Autotask Service Calls

Autotask Service Call data model - the ServiceCall / ServiceCallTicket / ServiceCallTicketResource three-layer structure - covering fields, status codes, and how tickets and technicians (resources) are linked to scheduled work.

LLM Mart

Claude Skill autotask

Autotask Ticket Notes & Attachments

Autotask ticket notes, attachments, and charges — the secondary entities attached to tickets: retrieving/searching notes and attachments, and creating, updating, or searching ticket charges for labor and expenses billed directly to a ticket.

LLM Mart

Claude Skill autotask

Autotask Tickets

Autotask ticket lifecycle: status/priority codes and transition rules, the ticket field schema, SLA calculation and clock behavior, escalation rules, ticket metrics, and the MCP tool surface (create, update, search, history, notes) for MSP service desk operations.

LLM Mart

Claude Skill autotask

Autotask Time Entries

Autotask time entry structure: approval status codes and workflow, the time entry field schema, the billing rate hierarchy, budget and contract-limit validation, utilization analytics, and the MSP business rules for rounding and minimum billing increments.

LLM Mart

Claude Skill autotask

Autotask Tool Discovery

The Autotask MCP lazy-loading pattern - four meta-tools (list_categories, list_category_tools, execute_tool, router) that expose the full 39+ tool catalog progressively instead of loading every tool schema upfront, plus the natural-language router for intent-based tool lookup.

LLM Mart

Claude Skill auvik

Auvik Alerts

Auvik alerts: severity tiers, status lifecycle, dismissal semantics, and the common alertName patterns that show up in MSP NOC queues.

LLM Mart

Claude Skill auvik

Auvik API Patterns

Auvik MCP fundamentals: the JSON:API envelope shape, basic-auth credential model, region routing, cursor-based pagination, rate-limit handling, and the v1 vs v2 device API distinction.

LLM Mart

Claude Skill auvik

Auvik Devices

Auvik device records: device types, manageStatus and onlineStatus, lifecycle and warranty fields, and choosing between the v1 list endpoint and the detailed device endpoints.

LLM Mart

Claude Skill auvik

Auvik Networks

Auvik network and interface entities: the network entity model, IP-range scoping, interface-to-device relationships, and adminStatus vs operStatus.

LLM Mart

Claude Skill avanan

Checkpoint Avanan API Patterns

Shape of the Checkpoint Harmony Email (Avanan) `hec_*` tool surface: the thirteen tools and what each reaches, the event/entity split that governs which tool accepts which id, the `responseEnvelope`/`responseData` result shape, `scrollId` pagination, and the auth, regional-routin

LLM Mart

Claude Skill avanan

Checkpoint Avanan Exceptions

The Checkpoint Harmony Email (Avanan) whitelist and blacklist surface: the match fields and matching modes an exception accepts, the defaults that widen an entry beyond what was typed, the id mismatch between listing and editing, and the standing security consequence of a detecti

LLM Mart

Claude Skill betterstack

Better Stack API Patterns

Better Stack MCP and API surface across Uptime, Telemetry (Logtail), and Error Tracking: available tools, Bearer token authentication, API structure, cursor-based pagination, rate limiting, and error handling.

LLM Mart

Claude Skill betterstack

Better Stack Incidents

Better Stack incidents: incident records raised by uptime monitors or reported manually, and the triage, acknowledgment, and resolution lifecycle.

LLM Mart

Claude Skill betterstack

Better Stack Logging

Better Stack log management (Logtail): log sources, structured log search and query syntax, log-based alerting, and log analysis workflows.

LLM Mart

Claude Skill betterstack

Better Stack Monitors

Better Stack uptime monitors: check types, monitor fields, heartbeat monitors, monitor groups, and create/update/pause/delete operations.

LLM Mart

Claude Skill betterstack

Better Stack On-Call

Better Stack on-call: on-call calendars and rotations, escalation and notification policies, alert routing, and determining who is currently on call.

LLM Mart

Claude Skill betterstack

Better Stack Status Pages

Better Stack status pages: status page configuration, resources and components, maintenance windows, and public service-status communication.

LLM Mart

Claude Skill blumira

Blumira Agents

Blumira agents (sensors) and the devices they run on: device inventory and filtering, agent health via last-seen timestamps, and agent deployment keys.

LLM Mart

Claude Skill blumira

Blumira API Patterns

Blumira REST API fundamentals: JWT authentication, the dual `/org/*` vs `/msp/*` path structure, suffix-based filter operators, pagination parameters and response metadata, the stateful MCP navigation tools, and HTTP error causes.

LLM Mart

Claude Skill blumira

Blumira Findings

The Blumira finding lifecycle: status and severity codes, resolution types, list filtering, enriched detail retrieval, assignment, and comment threads.

LLM Mart

Claude Skill blumira

Blumira MSP

Blumira's MSP path group (`/msp/*`): managed-account enumeration, cross-account and per-account finding queries, per-account device, agent-key and user management, and how MSP paths differ from org paths.

LLM Mart

Claude Skill blumira

Blumira Resolutions

Blumira resolution types (Valid, Not Applicable, False Positive): how to choose between them, their effect on security metrics and detection tuning, and the org- and MSP-level resolve calls.

LLM Mart

Claude Skill blumira

Blumira Users

Blumira organization users: listing and filtering users, user roles, and looking up the user IDs required for finding assignment and access audits.

LLM Mart

Claude Skill kaseya-quote-manager

Kaseya Quote Manager API Patterns

Kaseya Quote Manager (Datto Commerce) API fundamentals: API-key auth and the gateway's header translation, the read-only `kqm_<entity>_list`/`_get` tool surface across the sales, procurement, catalog, CRM, and org domains, page/pageSize/modifiedAfter pagination, rate limits, and

LLM Mart

Claude Skill kaseya-quote-manager

Kaseya Quote Manager Purchasing

Kaseya Quote Manager procurement data: purchase orders with their lines and costs, the suppliers they are placed with, and product-supplier records mapping catalog products to supplier SKUs and pricing. Read-only tool surface.

LLM Mart

Claude Skill kaseya-quote-manager

Kaseya Quote Manager Quotes & Sales Orders

Kaseya Quote Manager quoting data: the quote → section → line item hierarchy, and the sales orders, order lines, and payments a quote becomes once accepted. Read-only tool surface.

LLM Mart

Commands (200)

  • /account-summary — Get a security posture summary for a RocketCyber customer account source
  • /add-action — Add an action (note, update, or response) to an existing HaloPSA ticket source
  • /add-note — Add an internal or external note to a ConnectWise PSA ticket source
  • /add-note — Add a note or comment to an existing Autotask ticket source
  • /agent-inventory — List and filter Huntress agents across organizations source
  • /agent-inventory — List all devices and agents across the organization with status and health information source
  • /alert-triage — Triage open Auvik alerts, rank by severity, and recommend dismissals for known noise source
  • /azure-cost — Azure cost and pricing analysis for a subscription — Advisor cost recommendations, retail pricing lookups, and quota-driven right-sizing signals, scoped to one subscription source
  • /azure-diagnostics — Resource health and diagnostics triage for an Azure resource or subscription — Resource Health status, AppLens deep diagnostics, and Azure Monitor alert state source
  • /backup-health-check — Check backup health for one Axcient-protected device source
  • /backup-status — Portfolio-wide backup job health snapshot - failure count, at-risk clients, and storage trends source
  • /billing-report — Generate a Huntress billing summary for a period source
  • /block-sender — Create a Mailprotector block rule for a sender address or domain at a chosen scope source
  • /campaign-summary — Get summary of recent phishing and training campaigns from KnowBe4 source
  • /capacity-check — Capacity forecast for cloud resources, scoped to a resource type or covering everything connected source
  • /capacity-check — Scan Auvik interface statistics for saturated links and recurring congestion source
  • /case-review — Review and triage abuse mailbox cases in Abnormal Security source
  • /check-agreement — View agreement status and entitlements for a company in ConnectWise PSA source
  • /check-contract — View contract status, entitlements, and remaining hours for a company or specific contract source
  • /check-mfa-status — Audit MFA enrollment across all M365 users, highlighting accounts with no MFA source
  • /check-pricing — Check pricing details for an Autotask product or service from price lists source
  • /check-quarantine — Review the Mailprotector quarantine at any scope and summarize held messages source
  • /check-queue — Check Mimecast email delivery queue status and identify stuck or deferred messages source
  • /check-threat — Pull full detail for one Checkpoint Harmony Email detection and the message behind it source
  • /check-threats — View recent TAP threat events including blocked messages, delivered threats, and click activity source
  • /classify-email — Get an Ironscales AI verdict on a raw email, then act on it with a remediation action source
  • /client-backup-overview — Backup health overview across every device for one Axcient client source
  • /close-ticket — Close a ConnectWise PSA ticket with resolution notes source
  • /compliance-report — Generate an ImmyBot software-compliance scorecard for a tenant or the whole fleet source
  • /contract-status — Check contract status, service entitlements, and billing information for a client source
  • /cost-report — Cloud cost anomaly and reclaimable-spend report for a given window source
  • /create-deal — Create a new deal in HubSpot with company association source
  • /create-monitor — Create a new Better Stack uptime monitor source
  • /create-monitor — Create a threshold-based monitor for an Atera agent source
  • /create-quote — Create a ConnectWise CPQ quote by copying a template or an existing quote source
  • /create-quote — Create a new Autotask quote with line items for products, services, and service bundles source
  • /create-ticket — Create a new service ticket in ConnectWise PSA source
  • /create-ticket — Create a new service ticket in Atera source
  • /create-ticket — Create a new service ticket in Autotask PSA source
  • /create-ticket — Create a new service ticket in HaloPSA source
  • /decode-url — Decode a Proofpoint URL Defense rewritten URL back to the original URL source
  • /deploy-software — Stage and reconcile an ImmyBot desired-state software deployment to a tenant or computer source
  • /device-inventory — Inventory devices for an Auvik tenant with type, manage status, and lifecycle breakdown source
  • /device-inventory — List all devices at a Domotz-monitored site source
  • /device-inventory — Inventory devices for an N-central customer or site with class, warranty, and monitor-health breakdown source
  • /device-lookup — Find a Domotz device by name, IP address, or MAC address source
  • /device-lookup — Find a device in Datto RMM by hostname, IP address, or MAC address source
  • /drift-report — Portfolio-wide Inforcer baseline drift report — every managed tenant's alignment vs its assigned baseline, classified aligned / semi-aligned / drifted and sorted drifted-first, with secure score source
  • /drift-report — Report control and configuration drift since the last known-good baseline for a client or the whole portfolio source
  • /edit-doc-sections — Read, edit, and restructure sections of an IT Glue document source
  • /entra-audit — Run a read-only Microsoft Entra identity hygiene audit via the Graph Enterprise MCP — inactive user accounts, admins without MFA registered, unassigned/wasted licenses, and a guest user inventory source
  • /entra-report — Conversational Microsoft Entra directory reporting via the Graph Enterprise MCP — license usage, user and group counts, application inventory, and directory composition, formatted for client check-ins and QBRs source
  • /eol-report — EOL/EOS risk report — devices, OS versions, and firmware approaching or past end-of-life/end-of-support, prioritized by criticality source
  • /error-budget — Run the reliability scorecard for one service, or every connected service if omitted - error-budget burn rate where an SLO is defined, trend reporting otherwise source
  • /evidence-pack — Build a source-cited compliance evidence package for a client against a named framework source
  • /expenses — Use this skill when working with Autotask expense reports - creating reports, adding expense items, searching by status or submitter, and tracking reimbursable and billable expenses source
  • /find-company — Find a company in Hudu by name source
  • /find-contact — Resolve a 3CX contact or extension by email, extension, or name source
  • /finding-triage — Triage open Blumira findings by severity, presenting a prioritized list for review source
  • /find-organization — Find an organization in IT Glue by name source
  • /find-secret — Locate a Keeper record by description and return its UID and metadata without revealing any credential source
  • /get-kb-articles — Search the Atera knowledge base for articles source
  • /get-password — Retrieve a password from Hudu (with security logging) source
  • /get-password — Retrieve a password from IT Glue (with security logging) source
  • /get-quote — Get a Kaseya Quote Manager quote with its sections and line items source
  • /get-quote — Get a ConnectWise CPQ quote with its tabs, line items, customers, and terms source
  • /get-record — Retrieve a NetSuite record by type and internal ID source
  • /get-sales-order — Get a Kaseya Quote Manager sales order with its lines and payments source
  • /get-ticket — Retrieve detailed ticket information from ConnectWise PSA source
  • /get-user — Look up a Microsoft 365 user by name or email, showing account status, licenses, MFA, and last sign-in source
  • /group-report — Get security awareness metrics for a KnowBe4 group source
  • /incident-triage — Triage open Huntress incidents by severity source
  • /incident-triage — Triage current Better Stack incidents source
  • /investigate-detection — Investigate a single Blackpoint Cyber / CompassOne detection end-to-end source
  • /investigate-finding — Deep investigation of a specific Blumira finding with details, context, and comment history source
  • /investigate-incident — Deep dive investigation into a specific Huntress incident with remediations source
  • /investigate-threat — Deep-dive threat investigation with forensics, campaign context, and remediation options source
  • /issue-sweep — Sweep active issues across N-central customers, grouped by severity and probable root cause source
  • /kb-search — Search the HaloPSA knowledge base for articles and solutions source
  • /liongard-environment-summary — Generate a detailed summary of a Liongard environment source
  • /liongard-health-check — Check Liongard connectivity and return system health summary source
  • /list-alerts — List active RMM alerts from Atera source
  • /list-computers — List computers in ConnectWise Automate with optional filters source
  • /list-computers — List and filter ImmyBot-managed computers, optionally scoped to a tenant source
  • /list-licenses — Show Microsoft 365 license inventory - available SKUs, consumed seats, and optimization opportunities source
  • /list-overdue-invoices — List open and overdue Alternative Payments invoices and optionally generate hosted payment links for them source
  • /list-quotes — List Kaseya Quote Manager quotes, optionally scoped to a recent window source
  • /list-templates — List ConnectWise CPQ quote templates available to copy source
  • /log-activity — Log a note or create a task on a HubSpot contact, company, or deal source
  • /log-time — Log a time entry (billable activity) against a Clio matter source
  • /log-time — Log a time entry against a ConnectWise PSA ticket source
  • /log-time — Log work hours on an Atera ticket source
  • /lookup-asset — Find an asset in Hudu by name, hostname, serial number, or IP address source
  • /lookup-asset — Find a configuration item (asset) in IT Glue by name, hostname, serial number, or IP address source
  • /lookup-asset — Search for Autotask configuration items/assets by name, serial number, or company source
  • /lookup-company — Find a HubSpot company by name or domain and show associated contacts and deals source
  • /lookup-company — Search for Autotask companies by name, ID, or other attributes source
  • /lookup-config — Search for configuration items (assets) in ConnectWise PSA source
  • /lookup-contact — Search for Autotask contacts by name, email, phone, or company source
  • /maintenance-status — Show ImmyBot maintenance session status — active sessions, or detail and logs for a specific session source
  • /matter-summary — Consolidated view of one Clio matter — contacts, open tasks, recent activities, recent communications, and bills source
  • /meraki-find-device — Locate a Meraki device by serial, name, or MAC across an organization's networks source
  • /meraki-firewall-review — Pull and summarize a Meraki network's L3 firewall rules and flag overly-permissive (any/any allow) rules source
  • /meraki-network-health — Sweep an organization's networks, devices, and appliance VPN status for a site-health overview source
  • /monitor-status — Check all Better Stack monitor statuses and identify downtime source
  • /month-end-recon — Run the full billing-drift sweep for a billing period, formatted as a month-end reconciliation report source
  • /msp-overview — MSP dashboard showing all managed accounts with open finding counts and severity breakdown source
  • /my-tickets — List tickets currently assigned to you with optional filtering source
  • /network-audit — Audit a tenant's networks, interfaces, and saved configurations; flag drift and missing backups source
  • /network-sweep — Full network health sweep across all connected network-monitoring tools — devices down, degraded links, and topology changes source
  • /offboard-user — Run the complete M365 offboarding workflow for a departing user - revoke access, handle mailbox, transfer data source
  • /offboard-user — Run the complete CIPP M365 offboarding workflow for a departing user — capture audit state, revoke access, handle mailbox, reclaim licenses source
  • /onboard-customer — Onboard a new customer onto Mailprotector - customer, domain, user group, services, users source
  • /oncall-brief — Generate the current on-call handoff brief - what's paging, what's escalated without an owner, last-shift history, and known-flaky alerts to watch source
  • /org-health — Organization health check covering agents, incidents, and escalations source
  • /org-health-check — Full health check for one Proofpoint Essentials customer org source
  • /partner-overview — Portfolio-level Blackpoint Cyber / CompassOne rollup of detections and exposure across all tenants source
  • /pbx-health-check — Quick health check for a connected 3CX PBX source
  • /phishing-results — View phishing campaign results and click rates from KnowBe4 source
  • /phishing-results — Phishing-simulation results and click-rate trend for a given window source
  • /pipeline-summary — Summarize the HubSpot deal pipeline - deals per stage, total value, and expected close dates source
  • /postmortem — Draft a blameless postmortem for a given incident (by ID or name), or the most recent significant incident within a time window source
  • /questionnaire — Draft evidence-backed answers to the standard cyber-insurance questionnaire for a client source
  • /queue-status — Snapshot of 3CX queue staffing and active call load source
  • /reassign-ticket — Reassign a ticket to a different resource or queue source
  • /reconcile-payout — Reconcile an Alternative Payments payout by listing its transactions and matching them against invoices and customers source
  • /refresh-calendar — Forward-looking hardware refresh calendar for the given window — replace-now / plan-this-year / monitor tiers source
  • /release-message — Release one or more quarantined Mailprotector messages to their recipients source
  • /release-quarantine — Release one or more quarantined messages to their intended recipients source
  • /release-quarantine — Restore quarantined mail to its recipients in Checkpoint Harmony Email, with task polling source
  • /renewals — List upcoming contract and subscription renewals within a window, sorted by date source
  • /resolve-alert — Resolve an RMM alert in Atera source
  • /resolve-alert — Resolve an open alert in Datto RMM source
  • /resolve-escalation — Review and resolve a Huntress escalation source
  • /resolve-finding — Resolve a Blumira finding with the appropriate resolution type and notes source
  • /restore-check — Restore-readiness check - has this actually been restore-tested, for one client or the whole portfolio source
  • /retention-audit — Retention and RPO compliance audit against contracted requirements, for one client or the whole portfolio source
  • /review-threats — Review Mimecast TTP threat logs for URL clicks, malicious attachments, and impersonation attempts source
  • /risk-report — Human risk score report for one client or the whole portfolio, built from training completion and phishing-simulation performance source
  • /run-job — Run a quick job on a device in Datto RMM source
  • /run-powershell — Execute a PowerShell script on an Atera agent source
  • /run-script — Execute a script on an endpoint in ConnectWise Automate source
  • /run-script — Find and execute an ImmyBot PowerShell script on a target computer (destructive, SYSTEM context) source
  • /schedule-entry — Create a schedule entry/appointment in ConnectWise PSA source
  • /scope-audit — Report exactly what the connected Keeper KSM application can reach - folders, record counts, and record types - reading no credential values source
  • /search-agents — Search for RMM agents in Atera by customer or machine name source
  • /search-articles — Search Hudu knowledge base articles by keyword or phrase source
  • /search-assets — Search for configuration items/assets by name, serial number, type, or client source
  • /search-clients — Search for HaloPSA clients by name, domain, or other attributes source
  • /search-contacts — Search HubSpot contacts by name, email, or company source
  • /search-contacts — Search Clio contacts by name, company, or email source
  • /search-customers — Search for Atera customers by name or criteria source
  • /search-deals — Search HubSpot deals by name, stage, or company source
  • /search-detections — List recent Blackpoint Cyber detections for a tenant source
  • /search-docs — Search IT Glue documentation by keyword or phrase source
  • /search-incidents — Search RocketCyber security incidents by account, status, severity, verdict, and date range source
  • /search-logs — Search logs via Better Stack Logtail source
  • /search-matters — Search or list Clio matters by name/client and status source
  • /search-org — Resolve a Proofpoint Essentials customer org by name or domain and show its details source
  • /search-products — Search the Autotask product catalog for products, services, or inventory items source
  • /search-quarantine — Search quarantined messages in Proofpoint by sender, recipient, subject, or reason source
  • /search-quarantine — Find messages in Checkpoint Harmony Email by sender, subject, attachment hash or quarantine state source
  • /search-quotes — Search ConnectWise CPQ quotes by account, status, or date range source
  • /search-software — Search the ImmyBot software catalog (per-tenant + global) source
  • /search-surveys — Search recent Crewhu surveys, surfacing detractors and promoters source
  • /search-threats — Search for specific threat patterns in Abnormal Security by sender, recipient, attack type, or keywords source
  • /search-threats — Sweep security events in Checkpoint Harmony Email by type, state, severity and date range source
  • /search-tickets — Search Freshdesk tickets with the Freshdesk query language — filter by status, priority, agent, group, type, tag, and date — and return a ranked, readable result list source
  • /search-tickets — Search for tickets in HaloPSA by various criteria source
  • /search-tickets — Search for tickets in ConnectWise PSA by various criteria source
  • /search-tickets — Search for tickets in Autotask PSA by various criteria source
  • /secure-score-report — Generate a portfolio-wide M365 security posture report — Secure Score equivalents, MFA enrollment, conditional access coverage, and domain authentication across all managed tenants source
  • /security-posture — Overall security posture review including open findings by severity, agent coverage, and trends source
  • /show-ticket — Display comprehensive ticket information including history, actions, and related entities source
  • /site-devices — List all devices at a site in Datto RMM source
  • /site-overview — Overview of a Domotz site's network health source
  • /sla-dashboard — View SLA status across tickets, including approaching breaches and at-risk tickets source
  • /standards-drift — Find tenants that have drifted from the MSP's configured CIPP standards baseline — missing standards, standards in Report-only mode, recent compliance failures source
  • /status-page-update — Update a Better Stack status page with current status or maintenance source
  • /task-status — Drill into an N-central scheduled task's outcome - aggregate status down to per-device results and output source
  • /tenant-exposure — Build a prioritized exposure report for a Blackpoint Cyber / CompassOne tenant source
  • /tenant-health — Quick health snapshot for a single tenant — BPA failures, conditional access enforcement, MFA gaps, domain authentication, standards compliance source
  • /tenant-overview — Single-tenant Auvik snapshot - devices, alerts, networks, billing usage source
  • /tenant-posture — Single-tenant Microsoft 365 posture snapshot from Inforcer — secure score plus alignment score, band, and the per-policy drift detail against the tenant's assigned baseline source
  • /threat-triage — Triage recent email threats detected by Abnormal Security by severity and attack type source
  • /ticket-summary — Summarize a single Freshdesk ticket and its full conversation thread — the request, what has happened, current SLA state, and the recommended next action source
  • /time-entry — Log time against tickets or projects in Autotask PSA source
  • /trace-message — Trace an email through Mimecast by sender, recipient, subject, or date range source
  • /training-status — Check training completion status for users or groups in KnowBe4 source
  • /training-status — Training completion snapshot for one client or the whole portfolio — completion rates, overdue users, and cadence status source
  • /triage-detections — Sweep and prioritize the open Blackpoint Cyber / CompassOne detection queue across tenants source
  • /triage-incidents — Triage open Ironscales phishing incidents — list by status and severity, investigate, and remediate source
  • /true-up — Run the license true-up reconciliation for one client or the whole portfolio source
  • /update-ticket — Update fields on an existing ConnectWise PSA ticket source
  • /update-ticket — Update fields on an existing Autotask ticket (status, priority, queue, due date) source
  • /update-ticket — Update fields on an existing HaloPSA ticket including status, priority, and assignment source
  • /update-ticket — Update fields on an existing Atera ticket source
  • /user-risk — Get risk score and risk history for a KnowBe4 user source
  • /vap-report — Get the Very Attacked People (VAP) report showing the most targeted users source
  • /warranty-status — Warranty status snapshot — expired, expiring-soon, and unknown-coverage devices for one client or the whole portfolio source

MCP servers (23)

  • auvik http https://conduit.wyre.ai
  • blackpoint http https://conduit.wyre.ai
  • conduit http https://conduit.wyre.ai
  • conduit http https://conduit.wyre.ai
  • conduit http https://conduit.wyre.ai
  • conduit http https://conduit.wyre.ai
  • conduit http https://conduit.wyre.ai
  • conduit http https://conduit.wyre.ai
  • conduit http https://conduit.wyre.ai
  • conduit http https://conduit.wyre.ai
  • conduit http https://conduit.wyre.ai
  • conduit http https://conduit.wyre.ai
  • crewhu http https://conduit.wyre.ai
  • freshdesk http https://conduit.wyre.ai
  • immybot http https://conduit.wyre.ai
  • inforcer http https://conduit.wyre.ai
  • msp-mcp-gateway http https://conduit.wyre.ai
  • ncentral http https://conduit.wyre.ai
  • netsuite http https://conduit.wyre.ai
  • posthog http https://conduit.wyre.ai
  • saas-alerts http https://conduit.wyre.ai
  • threatlocker http https://conduit.wyre.ai
  • timezest http https://conduit.wyre.ai

Connection details are shown as declared in the repository; arguments and environment values are deliberately not imported.