Install
$ agentstack add skill-wyre-ai-msp-claude-plugins-incident-response ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Blackpoint Incident Response
The functional Blackpoint tool surface today is read-only and centers on detections and the assets they fire against. This skill walks the investigation flow: tenant → asset → detections → vulnerabilities, plus dark-web and external-vulnerability cross-references.
Anti-triggers
- Responding, acknowledging, isolating, or closing — despite the
skill name there is no incident object and no write tool here. The MCP surface cannot mutate CompassOne state; response happens in the portal. If the intent is an actionable incident lifecycle, the operator is probably thinking of huntress-incidents or sentinelone-alerts.
blackpoint_alerts_*andblackpoint_tickets_*— those domains
are stubs, not an alternative alerting surface. Detections are the only detection object Blackpoint exposes.
- Exposure work in its own right — CVE filtering, scan history,
dark-web, and external exposure have their own skill: blackpoint-vulnerability-management. Use this one only when a detection is the starting point.
- Sweeping every customer rather than investigating one — use
blackpoint-multi-tenant-operations.
API Tools
Tenants
| Tool | Purpose | |------|---------| | blackpoint_tenants_list | Partner's customer tenants | | blackpoint_tenants_get | Detail for one tenant |
Assets
| Tool | Purpose | |------|---------| | blackpoint_assets_list | Assets for a tenant | | blackpoint_assets_get | Detail for one asset | | blackpoint_assets_search | Search assets by name / identifier | | blackpoint_assets_relationships | Asset relationships (parent / child / related) |
Detections
| Tool | Purpose | |------|---------| | blackpoint_detections_list | Detections for the tenant / asset scope | | blackpoint_detections_get | Full detail for one detection |
Vulnerabilities
| Tool | Purpose | |------|---------| | blackpoint_vulnerabilities_list | Known vulnerabilities for the scope | | blackpoint_vulnerabilities_scans_list | Recent scan results | | blackpoint_vulnerabilities_darkweb_list | Dark-web exposure findings | | blackpoint_vulnerabilities_external_list | External (internet-facing) vulnerabilities |
Common Workflows
Walk a detection end-to-end
- Identify the tenant:
blackpoint_tenants_list→
blackpoint_tenants_get.
- List recent detections:
blackpoint_detections_list. - Pick the detection of interest:
blackpoint_detections_get. - Pivot to the affected asset:
blackpoint_assets_get and blackpoint_assets_relationships.
- Cross-reference vulnerabilities on that asset:
blackpoint_vulnerabilities_list.
Per-tenant exposure rollup
blackpoint_tenants_getto confirm scope.blackpoint_vulnerabilities_external_listfor internet-facing
exposure.
blackpoint_vulnerabilities_darkweb_listfor credential / data
leakage.
blackpoint_vulnerabilities_scans_listfor recent scan history.- Roll up: count by severity, age, and asset. Surface anything
high-severity with no recent scan.
Asset relationship map
blackpoint_assets_searchto find the entry asset.blackpoint_assets_relationshipsto enumerate connected assets.- For each related asset, summarize detections and vulnerabilities
to build a blast-radius view.
Multi-tenant detection sweep (partner view)
blackpoint_tenants_listto enumerate customers.- For each tenant, call
blackpoint_detections_listfor a recent
window.
- Roll up: detections per tenant, severity distribution, top
detection types.
- Surface tenants with abnormal volume or new detection types as
priority follow-ups.
Edge Cases
- Stub domains —
blackpoint_alerts_*,
blackpoint_cloud_security_*, blackpoint_notifications_*, blackpoint_partners_*, blackpoint_threat_intel_*, and blackpoint_tickets_* are placeholders today and should not be invoked. Prefer the four functional domains.
- Read-only — Any "respond" or "acknowledge" action must happen
in the CompassOne portal; the MCP surface cannot mutate state yet.
- Asset identity drift — Re-imaged endpoints can produce two
asset records. Use blackpoint_assets_search and dedupe on hostname / serial before reporting.
Best Practices
- Always include tenant name in every output — partner-level work
spans many customers and ambiguity bites.
- Pair detections with the associated asset and any related
vulnerabilities in a single view; analysts should not have to chase the link themselves.
- For QBRs, pull the external-vulnerability list and dark-web list
together — they tell complementary stories.
Related Skills
- [api-patterns](../api-patterns/SKILL.md) - Auth, hierarchy, pagination
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: WYRE-AI
- Source: WYRE-AI/msp-claude-plugins
- License: Apache-2.0
- Homepage: https://mcp.wyre.ai/getting-started/
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.