with one click
msp-claude-plugins
msp-claude-plugins contains 331 collected skills from wyre-technology, with repository-level occupation coverage and site-owned skill detail pages.
Skills in this repository
Use this skill when working with the Clio Manage MCP tools — OAuth 2.0 Authorization Code connection via Conduit, the matters-as-hub data model, decision-tree tool navigation, pagination, and the deliberate v1 scope limits (no delete anywhere, documents metadata-only, communications/ calendar/bills read-only). Essential background before touching any other Clio skill.
Use this skill when creating, updating, searching, or reasoning about Clio contacts — the people and companies connected to matters. Covers person vs. company contacts and the relationship between a contact and the matters they're party to (client, opposing party, witness, and other roles).
Use this skill when creating, updating, searching, or reasoning about Clio matters — the case/client-file object that almost everything else in Clio hangs off of. Covers the matter status lifecycle, linking a matter to a client contact, practice areas, custom fields, and matter numbering.
Use this skill when logging time or expense activities against a Clio matter, or when reading (not writing) bills. Covers the activities domain's create-only lifecycle, the billing-read/time-entry-write split, and why billing mutations are out of scope for v1.
Use this skill when identifying devices, operating system versions, or firmware approaching or past end-of-life (EOL) or end-of-support (EOS), combining device inventory data (make/model/OS version) pulled from whatever RMM platforms are connected with general knowledge of common EOL/EOS dates for widely-deployed OS and hardware, and prioritizing the resulting risk list by device criticality. Always use conduit__search_tools to discover which RMM(s) are actually connected before assuming a specific vendor, and always caveat EOL/EOS dates as needing verification against current vendor lifecycle pages since they can change.
Use this skill when building a forward-looking hardware refresh calendar by combining warranty expiration, EOL/EOS timing, and device age across whatever RMM platforms and documentation tools are connected through the gateway. Covers how to bucket devices into replace-now, plan-this-year, and monitor tiers so refresh conversations happen proactively — ahead of a failure or a forced EOL migration — rather than reactively after something breaks. Always use conduit__search_tools to discover which tools are actually connected before assuming a specific vendor.
Use this skill when pulling and normalizing warranty status across whatever RMM platforms (Datto RMM, NinjaOne, N-central, Kaseya VSA, ConnectWise Automate, Atera, SuperOps, Syncro, Action1, ImmyBot) and documentation tools (IT Glue, Hudu) are connected through the gateway. Covers the reliability spread between RMM warranty fields (some pull directly from OEM APIs, some rely on manually-entered fields that go stale), cross-referencing documentation platforms when RMM warranty data is missing or stale, and flagging devices with expired or soon-expiring warranty. Always use conduit__search_tools to discover which RMM and documentation tools are actually connected before assuming a specific vendor.
Use this skill to assess portfolio-wide backup job health across whatever BCDR and SaaS-backup tools are connected: job success/failure rate, missed- backup detection, storage-consumption trending, and how to normalize very different vendor job models (image-based appliance backup vs. SaaS-data snapshot backup) into one comparable health view.
Use this skill to track and verify whether backups are recoverable rather than merely present: the difference between "a backup exists" and "a backup is recoverable," how to use screenshot/boot-verification features and spot-check restore drills as evidence, what counts as an adequate testing cadence for different data-criticality tiers, and how to flag backups that have never been restore-tested.
Use this skill to check actual retention configuration and backup cadence against contracted/required retention policy and RPO (recovery point objective) targets — detecting gaps where a client's contract specifies a retention window the appliance isn't actually configured for, or an RPO target the current backup frequency can't actually meet.
Use this skill when analyzing phishing-simulation campaign results: click-rate trends over time, repeat-clicker identification, and — where a technical threat-response tool is also connected — correlating simulated-phishing performance with real-world phishing incidents as a compounding risk signal. Covers how to surface that correlation as optional enrichment without assuming secops-pack or any incident-response tool is installed.
Use this skill when building a per-user or per-org "human risk score" from training completion, phishing-simulation performance, and optionally real-world click-through data from connected email-security tools. Covers a simple, explainable, non-black-box scoring approach and how to degrade gracefully to training-completion-only scoring when phishing-simulation data isn't available.
Use this skill when assessing security-awareness training completion for a single client or across the whole portfolio. Covers overdue-training detection, per-org completion-rate calculation, and how to flag clients falling behind their contracted training cadence (e.g. quarterly phishing simulations, annual security-awareness modules) — across whatever training/awareness platform is connected, discovered via conduit__search_tools rather than assumed.
Use this skill when right-sizing or forecasting capacity for cloud resources across whatever cloud platforms (Azure, DigitalOcean) are connected through the gateway. Covers identifying over-provisioned and under-utilized resources (Azure resource groups/quotas, DigitalOcean Droplets/Kubernetes/Databases), building a growth-trend-based capacity forecast, and — critically — the difference between a genuine capacity risk and normal variance that doesn't warrant action. Always use conduit__search_tools to discover which cloud platforms are actually connected before assuming a specific vendor.
Use this skill when tracking and flagging cloud spend anomalies across whatever cloud platforms (Azure, DigitalOcean) are connected through the gateway. Covers unexpected cost spikes, orphaned/idle resources still incurring cost (unattached volumes, idle load balancers, stopped-but-not- deallocated compute), and how to build a monthly cost trend view from whatever billing/usage data each connected platform exposes. Always use conduit__search_tools to discover which cloud platforms are actually connected before assuming a specific vendor.
Use this skill when checking device and network health across whatever network-monitoring tools (Auvik, Meraki, Domotz) are connected through the gateway. Covers device-down detection, interface error/utilization thresholds, topology-change detection, and how to reconcile each vendor family's different data model — Auvik's device/interface model, Meraki's dashboard-org/network model, Domotz's agent-based collector model — into one normalized health view. Always use conduit__search_tools to discover what's actually connected before assuming a specific vendor's tool names.
Use this skill when computing or reporting error-budget status across whatever observability tools are connected through the gateway. Covers SLO/error-budget concepts applied practically — how to compute current burn rate from available observability data (Sentry error rate, Datadog/Grafana uptime or latency SLIs, BetterStack uptime checks), what counts as a budget-threatening trend versus noise, and how to degrade gracefully when no formal SLO is defined (fall back to raw error-rate/uptime trend reporting instead of a burn-rate calculation). Discover connected tools via conduit__search_tools before assuming a specific vendor; never hardcode a tool surface.
Use this skill when assembling a blameless postmortem from an incident across whatever incident-management and observability tools are connected through the gateway. Covers timeline reconstruction from the incident tool's event log plus correlated observability data (Sentry error spikes, Datadog/Grafana metric anomalies, GitHub deploy history around the incident window), a root-cause hypothesis structure, and the difference between contributing factors and root cause. Discover connected tools via conduit__search_tools before assuming a specific vendor; never hardcode a tool surface.
Use this skill when assembling a proper on-call handoff across whatever incident-management tool (Rootly, PagerDuty, BetterStack) is connected through the gateway. Covers what belongs in a handoff — currently paging or unresolved incidents, last-shift incident history and status, known-flaky alerts worth flagging, and anything escalated but not yet actioned — and, critically, how to use conduit__search_tools to discover which incident-management tool is actually connected before assuming a specific vendor's tool names. Do not hardcode a vendor's tool surface; discover it first.
Use this skill when assessing CRM pipeline health across whatever CRM is actually connected through the gateway (typically HubSpot for this pack's target vendor set, but discovered rather than assumed). Covers stage-velocity norms, stalled-deal detection (no stage change in N days), pipeline coverage ratio against a quota/target where one is available, and how to degrade gracefully — reporting a partial or CRM-less result rather than fabricating figures — when no CRM is connected at all.
Use this skill when tracing a deal's progress across the quote-to-close chain — a Pax8/Sherweb/Kaseya Quote Manager quote or a SalesBuildr proposal, through a PandaDoc document's sent/viewed/signed status, to a closed-won deal in the CRM. Detects and names exactly which handoff point a deal is stuck at (quote sent but no proposal document yet, proposal sent but not opened, proposal viewed but not signed, or signed but the CRM deal was never marked closed-won), across whichever combination of these tools is actually connected.
Use this skill when scoring lead warmth from intent and engagement signals — Warmly website-visitor identification, HubSpot form fills and email engagement, and Calendly booking activity — and proposing which rep a warm lead should be routed to. Covers a practical scoring approach for "how warm is this lead" and explicit handling for when intent-signal tools (Warmly, Calendly) aren't connected, falling back to CRM-only engagement signals rather than failing outright.
Use this skill when a compliance control (CIS, SOC 2, HIPAA, or a cyber-insurance questionnaire line item) needs to be traced to concrete, retrievable evidence from connected MSP tooling rather than answered from memory or assumption. Covers how to resolve a control statement to specific gateway tool calls across CIPP (M365/Entra), Liongard (infrastructure inspections), and IT Glue/Hudu (documentation), and the critical distinction between evidence that proves a control is actually met versus evidence that only proves the control is written down as policy.
Use this skill when drafting answers to a cyber-insurance renewal or new-business questionnaire for an MSP client. Covers the standard recurring question set (MFA everywhere, EDR deployed, backups tested, incident response plan documented, employee security training) and how to answer each type by pulling live evidence from connected tools rather than guessing, plus how to flag questions that cannot be answered with current tool coverage instead of submitting an unverified answer.
Use this skill when a client's live configuration needs to be compared against a previously established baseline or standard to detect drift. Covers CIPP standards checks and Best Practice Analyser results, Liongard change detection and inspection timelines, what qualifies as drift versus normal operational change, how to distinguish intentional/authorized change from unauthorized or risky drift, and how to prioritize which drift findings matter most when several surface at once.
Use this skill when reconciling a PSA contract or agreement against what an MSP is actually invoicing in its accounting system, across any combination of PSA (Autotask, HaloPSA, ConnectWise, Syncro) and accounting platform (QuickBooks Online, Xero). Detects under-billing, over-billing, and lapsed agreements still being invoiced.
Use this skill when matching cloud-marketplace subscription seat counts (Pax8, Sherweb) against what is actually being billed to the client and what is actually deployed/active in the tenant (M365/CIPP user counts where available). Catches "paying for 50 seats but billing for 45" and "deprovisioned 5 users but never reduced the subscription" gaps.
Use this skill when computing per-client or per-service-line margin for an MSP: revenue from PSA billing/accounting invoices minus cost from Pax8/Sherweb wholesale pricing plus estimated labor from PSA time entries where available. Handles missing cost data by flagging it rather than guessing.
Use this skill for recurring ticket-board maintenance across whatever PSA is connected: detecting stale tickets (no activity in N days), finding and linking duplicate or related tickets, catching status-transition problems (tickets stuck in Waiting-on-Client past a threshold), and checking queue balance across technicians. This is board-wide hygiene, distinct from working any single ticket.
Use this skill when scoring and assigning an unassigned ticket queue across whatever PSA (and, where useful, RMM) is connected through the gateway. Covers the priority-scoring factors (SLA proximity, client tier, ticket age, technician load), and — critically — how to use conduit__search_tools to discover which PSA/RMM tools are actually available before assuming a specific vendor's tool names. Do not hardcode a vendor's tool surface; discover it first.
Use this skill when triaging SLA pressure on whatever PSA is connected through the gateway. Covers how to read breach-risk state across the major PSA families (Autotask, HaloPSA, ConnectWise Manage, Syncro, Kaseya BMS), a common escalation decision framework that sits on top of those different data models, how escalation severity and audience change by contract tier, and what evidence to gather before paging someone. Resolve status/priority/ SLA IDs via the connected PSA's own list tools (e.g. autotask__list_ticket_priorities, halopsa__tickets_list) — never hardcode tenant-specific IDs. If no PSA is connected, this skill degrades to general escalation guidance and says so explicitly.
Use this skill when triaging security alerts, incidents, or findings that come from more than one connected EDR/MDR/SIEM vendor and a single, comparable severity ranking is needed. Covers a common Critical/High/Medium/Low normalized model, how to map each vendor's native severity terminology (Huntress incident status, SentinelOne threat confidence, Blumira finding priority, CIPP alert queue severity, Blackpoint Cyber SOC severity, SaaS Alerts risk level, and others) into it, and how to discover which vendors are actually connected before assuming any one of them is present.
Use this skill when Business Email Compromise (BEC) is suspected or confirmed for a client. Covers how to detect the signs from CIPP/M365 audit logs and connected email security vendor alerts, the immediate response sequence (session revocation, forwarding-rule audit, mailbox rule cleanup, password reset, MFA re-enrollment), and how to document the incident timeline for a client-facing report.
Use this skill when a security incident has been confirmed or is highly suspected and immediate first-response containment steps are needed. Covers standard containment sequences for the most common MSP incident classes — compromised account, malware/ransomware detection, business email compromise, and exposed credential — including what to do first, the correct order of operations, and which connected tool family (RMM, EDR, CIPP/Entra, PSA) handles each step.
Use this skill when working with Abnormal Security account takeover (ATO) detection - suspicious sign-ins, impossible travel, compromised accounts, mailbox rule changes, and lateral movement indicators. Covers account takeover cases, investigation workflows, and remediation actions. Essential for MSP security analysts investigating compromised accounts detected by Abnormal Security.
Use this skill when working with the Abnormal Security REST API - Bearer token authentication, base URLs, rate limiting, pagination, OData filtering, error handling, and common API patterns. Covers token management, request/response formats, and integration best practices. Essential for developers and MSP administrators integrating with the Abnormal Security API.
Use this skill when working with Abnormal Security abuse mailbox cases - user-reported emails, case triage, remediation actions, case lifecycle, and phishing simulation management. Covers case statuses, judgments, bulk actions, and MSP workflows for managing user-reported suspicious emails. Essential for MSP security analysts triaging abuse mailbox submissions in Abnormal Security.
Use this skill when working with Abnormal Security message analysis - email headers, attachments, sender reputation, delivery context, authentication results (SPF/DKIM/DMARC), and message metadata. Covers message retrieval, header inspection, and contextual analysis for incident investigation. Essential for MSP security analysts performing deep message analysis in Abnormal Security.
Use this skill when working with Abnormal Security threat detection and analysis - BEC, phishing, malware, socially-engineered attacks, spam, graymail, and credential theft. Covers threat types, attack vectors, severity assessment, remediation actions, and investigation workflows. Essential for MSP security analysts investigating email-borne threats detected by Abnormal Security's AI-powered behavioral engine.
Use this skill when working with Abnormal Security VendorBase vendor risk assessment - vendor risk scores, compromised vendor detection, vendor domain analysis, and supply chain email threat monitoring. Covers vendor risk levels, risk factors, compromised vendor workflows, and vendor-related threat investigation. Essential for MSP security analysts monitoring third-party vendor risk via Abnormal Security.