# Blackpoint Incident Response

> >

- **Type:** Skill
- **Install:** `agentstack add skill-wyre-ai-msp-claude-plugins-incident-response`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [WYRE-AI](https://agentstack.voostack.com/s/wyre-ai)
- **Installs:** 0
- **Category:** [Agent Skills](https://agentstack.voostack.com/c/agent-skills)
- **Latest version:** 0.1.0
- **License:** Apache-2.0
- **Upstream author:** [WYRE-AI](https://github.com/WYRE-AI)
- **Source:** https://github.com/WYRE-AI/msp-claude-plugins/tree/main/msp-claude-plugins/blackpoint/blackpoint/skills/incident-response
- **Website:** https://mcp.wyre.ai/getting-started/

## Install

```sh
agentstack add skill-wyre-ai-msp-claude-plugins-incident-response
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# Blackpoint Incident Response

The functional Blackpoint tool surface today is read-only and centers
on detections and the assets they fire against. This skill walks the
investigation flow: tenant → asset → detections → vulnerabilities,
plus dark-web and external-vulnerability cross-references.

## Anti-triggers

- **Responding, acknowledging, isolating, or closing** — despite the
  skill name there is no incident *object* and no write tool here. The
  MCP surface cannot mutate CompassOne state; response happens in the
  portal. If the intent is an actionable incident lifecycle, the
  operator is probably thinking of `huntress-incidents` or
  `sentinelone-alerts`.
- **`blackpoint_alerts_*` and `blackpoint_tickets_*`** — those domains
  are stubs, not an alternative alerting surface. Detections are the
  only detection object Blackpoint exposes.
- **Exposure work in its own right** — CVE filtering, scan history,
  dark-web, and external exposure have their own skill:
  `blackpoint-vulnerability-management`. Use this one only when a
  detection is the starting point.
- **Sweeping every customer rather than investigating one** — use
  `blackpoint-multi-tenant-operations`.

## API Tools

### Tenants

| Tool | Purpose |
|------|---------|
| `blackpoint_tenants_list` | Partner's customer tenants |
| `blackpoint_tenants_get` | Detail for one tenant |

### Assets

| Tool | Purpose |
|------|---------|
| `blackpoint_assets_list` | Assets for a tenant |
| `blackpoint_assets_get` | Detail for one asset |
| `blackpoint_assets_search` | Search assets by name / identifier |
| `blackpoint_assets_relationships` | Asset relationships (parent / child / related) |

### Detections

| Tool | Purpose |
|------|---------|
| `blackpoint_detections_list` | Detections for the tenant / asset scope |
| `blackpoint_detections_get` | Full detail for one detection |

### Vulnerabilities

| Tool | Purpose |
|------|---------|
| `blackpoint_vulnerabilities_list` | Known vulnerabilities for the scope |
| `blackpoint_vulnerabilities_scans_list` | Recent scan results |
| `blackpoint_vulnerabilities_darkweb_list` | Dark-web exposure findings |
| `blackpoint_vulnerabilities_external_list` | External (internet-facing) vulnerabilities |

## Common Workflows

### Walk a detection end-to-end

1. Identify the tenant: `blackpoint_tenants_list` →
   `blackpoint_tenants_get`.
2. List recent detections: `blackpoint_detections_list`.
3. Pick the detection of interest: `blackpoint_detections_get`.
4. Pivot to the affected asset:
   `blackpoint_assets_get` and `blackpoint_assets_relationships`.
5. Cross-reference vulnerabilities on that asset:
   `blackpoint_vulnerabilities_list`.

### Per-tenant exposure rollup

1. `blackpoint_tenants_get` to confirm scope.
2. `blackpoint_vulnerabilities_external_list` for internet-facing
   exposure.
3. `blackpoint_vulnerabilities_darkweb_list` for credential / data
   leakage.
4. `blackpoint_vulnerabilities_scans_list` for recent scan history.
5. Roll up: count by severity, age, and asset. Surface anything
   high-severity with no recent scan.

### Asset relationship map

1. `blackpoint_assets_search` to find the entry asset.
2. `blackpoint_assets_relationships` to enumerate connected assets.
3. For each related asset, summarize detections and vulnerabilities
   to build a blast-radius view.

### Multi-tenant detection sweep (partner view)

1. `blackpoint_tenants_list` to enumerate customers.
2. For each tenant, call `blackpoint_detections_list` for a recent
   window.
3. Roll up: detections per tenant, severity distribution, top
   detection types.
4. Surface tenants with abnormal volume or new detection types as
   priority follow-ups.

## Edge Cases

- **Stub domains** — `blackpoint_alerts_*`,
  `blackpoint_cloud_security_*`, `blackpoint_notifications_*`,
  `blackpoint_partners_*`, `blackpoint_threat_intel_*`, and
  `blackpoint_tickets_*` are placeholders today and should not be
  invoked. Prefer the four functional domains.
- **Read-only** — Any "respond" or "acknowledge" action must happen
  in the CompassOne portal; the MCP surface cannot mutate state yet.
- **Asset identity drift** — Re-imaged endpoints can produce two
  asset records. Use `blackpoint_assets_search` and dedupe on
  hostname / serial before reporting.

## Best Practices

- Always include tenant name in every output — partner-level work
  spans many customers and ambiguity bites.
- Pair detections with the associated asset and any related
  vulnerabilities in a single view; analysts should not have to chase
  the link themselves.
- For QBRs, pull the external-vulnerability list and dark-web list
  together — they tell complementary stories.

## Related Skills

- [api-patterns](../api-patterns/SKILL.md) - Auth, hierarchy, pagination

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [WYRE-AI](https://github.com/WYRE-AI)
- **Source:** [WYRE-AI/msp-claude-plugins](https://github.com/WYRE-AI/msp-claude-plugins)
- **License:** Apache-2.0
- **Homepage:** https://mcp.wyre.ai/getting-started/

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** no
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/skill-wyre-ai-msp-claude-plugins-incident-response
- Seller: https://agentstack.voostack.com/s/wyre-ai
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
