wyre-technology/msp-claude-plugins/msp-claude-plugins/abnormal/abnormal-security/skills/cases/SKILL.md
Abnormal Security Cases
Abnormal Security abuse mailbox cases: user-reported email submissions, case statuses and judgments, the case lifecycle, bulk and remediation actions, and phishing simulation handling.
- Source repository stars
- 39
- Declared platforms
- 0
- Static risk flags
- 0
- Last source update
- 2026-08-06
- Source checked
- 2026-08-06
Decision brief
What it does—and where it fits
Abnormal Security abuse mailbox cases: user-reported email submissions, case statuses and judgments, the case lifecycle, bulk and remediation actions, and phishing simulation handling.
Not for
- Tasks that require unconfirmed production actions or broad system permissions.
- Environments where the pinned source and install steps cannot be inspected.
Compatibility matrix
Platform support, with evidence labels
| Platform | Status | Evidence | What to check |
|---|---|---|---|
| Codex | Not declared | No explicit evidence | Portability before use |
| Claude Code | Not declared | No explicit evidence | Portability before use |
| Cursor | Not declared | No explicit evidence | Portability before use |
| Gemini CLI | Not declared | No explicit evidence | Portability before use |
Installation
Inspect first. Install second.
The source command is displayed only when detected. A safe inspection prompt is always available so your agent can explain every action before execution.
npx skills add https://github.com/wyre-technology/msp-claude-plugins --skill "msp-claude-plugins/abnormal/abnormal-security/skills/cases"Inspect the Agent Skill "Abnormal Security Cases" from https://github.com/wyre-technology/msp-claude-plugins/blob/c1011303bfd2a65abc9b260884d9858d1a482a6f/msp-claude-plugins/abnormal/abnormal-security/skills/cases/SKILL.md at commit c1011303bfd2a65abc9b260884d9858d1a482a6f. List every install step, command, network request, credential, file read/write, external action, and rollback step. Explain whether it fits my task. Do not install or execute anything until I approve.
Workflow
What the source asks the agent to do
- 01
Tool Usage Examples
List cases from this month:
List cases from this month: - 02
Standard Triage Workflow
1. List open cases - Get all cases with overallStatus eq 'Open' 2. Sort by severity - Address critical and high severity first 3. Review AI judgment: - If Malicious: verify and remediate across organization - If Spam: dismiss or move to junk - If Safe: dismiss and respond to rep…
List open cases - Get all cases with overallStatus eq 'Open'Sort by severity - Address critical and high severity firstReview AI judgment: - 03
Bulk Triage Workflow
1. Filter cases by judgment - Start with cases judged as Malicious 2. Review Suspicious - Manually review cases without clear judgment 3. Batch the read, not the write - paginate abnormalcaseslist to build the full picture in one pass. There is no bulk case action to follow it w…
Filter cases by judgment - Start with cases judged as MaliciousReview Suspicious - Manually review cases without clear judgmentBatch the read, not the write - paginate abnormalcaseslist to - 04
Anti-triggers
A compromised mailbox rather than a reported email — sign-in
A compromised mailbox rather than a reported email — sign-inThreats Abnormal found on its own — no user reported them, so noUser-reported phishing in a different platform — IRONSCALES runs - 05
Case Lifecycle
Review the “Case Lifecycle” section in the pinned source before continuing.
Review and apply the “Case Lifecycle” source section.
Permission review
Static risk signals and limitations
No configured static risk pattern was detected
This is not proof of safety. Runtime behavior, indirect dependencies, and hidden external systems are outside the static scan.
Evidence record
Why each signal appears
| Signal | Value | Evidence type | Meaning |
|---|---|---|---|
| Quality score | 87/100 | Computed | Documentation, specificity, maintenance, and trust rules |
| Repository stars | 39 | Source | Repository attention, not individual Skill quality |
| Compatibility | 0 platforms | Source | Declared in the catalog source record |
| Usage guide | automated source guide | Editorial | Generated or reviewed according to the visible evidence level |
Pinned source
Provenance and original SKILL.md
- Repository
- wyre-technology/msp-claude-plugins
- Skill path
- msp-claude-plugins/abnormal/abnormal-security/skills/cases/SKILL.md
- Commit
- c1011303bfd2a65abc9b260884d9858d1a482a6f
- License
- Apache-2.0
- Collected
- 2026-08-06
- Default branch
- main
View the original SKILL.md
Abnormal Security Abuse Mailbox Cases
Overview
Abnormal Security's Abuse Mailbox automatically processes user-reported suspicious emails. When users forward or report emails to a designated abuse mailbox address, Abnormal analyzes the reported message and creates a case with an AI-generated judgment. This skill covers case lifecycle, triage workflows, remediation actions, and bulk operations.
Anti-triggers
- A compromised mailbox rather than a reported email — sign-in
anomalies, new inbox rules, and session revocation have no surface on
this server at all; investigate identity in the M365 tenant, use
cipp-users. - Threats Abnormal found on its own — no user reported them, so no
case exists; use
Abnormal Security Threats. - User-reported phishing in a different platform — IRONSCALES runs
its own report-to-incident loop from its Outlook and Gmail add-ins,
with separate IDs and its own classification verbs; use
IRONSCALES Incidents. - A user who reported a simulated phish — campaign reporting rates
belong to the training platform; use
KnowBe4 Phishing.
Case Lifecycle
User Reports Email
|
v
Case Created (status: Open)
|
v
AI Analysis (judgment generated)
|
+---> Malicious ---> Auto-Remediate (if configured)
|
+---> Suspicious ---> Analyst Review Required
|
+---> Spam ---> Auto-Dismiss (if configured)
|
+---> Safe ---> Auto-Dismiss (if configured)
|
v
Analyst Action
|
+---> Remediate (quarantine/delete across org)
|
+---> Mark Not Spam (release to inbox)
|
+---> Dismiss (close case, no action)
|
v
Case Closed (status: Done)
Case Field Reference
Core Fields
| Field | Type | Description |
|---|---|---|
caseId | number | Unique case identifier — numeric, unlike threatId |
severity | string | Severity level of the case |
affectedEmployee | string | Email address of the user who reported |
firstReported | datetime | When the case was first reported |
Judgment Fields
| Field | Type | Description |
|---|---|---|
overallStatus | string | Case status: Open, Acknowledged, Done |
judgmentStatus | string | AI judgment: Malicious, Spam, Safe, No Action Needed |
customerVisibleTime | datetime | When the case became visible in portal |
Reported Message Fields
| Field | Type | Description |
|---|---|---|
reportedMessage.subject | string | Subject of the reported email |
reportedMessage.senderAddress | string | Sender of the reported email |
reportedMessage.senderName | string | Display name of the sender |
reportedMessage.recipientAddress | string | Recipient of the reported email |
reportedMessage.receivedTime | datetime | When the reported email was received |
reportedMessage.attackType | string | Detected attack type (if malicious) |
Case Judgments
| Judgment | Description | Recommended Action |
|---|---|---|
| Malicious | Confirmed threat (BEC, phishing, malware) | Remediate across organization |
| Spam | Unsolicited bulk email, marketing | Dismiss or move to junk |
| Safe | Legitimate email, no threat detected | Dismiss, notify user it is safe |
| No Action Needed | Phishing simulation or already remediated | Dismiss |
MCP Tools
The cases domain is read-only. Two tools, both GETs. There is no tool that changes a case's state, assigns it to an analyst, dismisses it, or closes it. Case state changes happen in the Abnormal portal, not through this server — an agent can read and reason about a case, then it has to hand the actual disposition to a human in the UI.
| Tool | Description | Parameters |
|---|---|---|
abnormal_cases_list | List cases | pageSize (default 100, max 100), pageNumber (1-indexed), filter (OData string) |
abnormal_cases_get | Get one case by ID | caseId (required, number) |
There is no date-range parameter. Narrow by time through the OData
filter string: createdTime gt 2026-03-01T00:00:00Z.
ID vocabulary
caseId is a number — 12345, not "12345". The neighbouring
threatId used by abnormal_threats_get is a UUID string. Both are
called "the ID" in conversation and they are not interchangeable; a
threat UUID passed to abnormal_cases_get is a type error, not a lookup
miss.
The one action this server can take on the mail behind a case is
message remediation, and it is reached through the threat, not the case:
abnormal_remediation_manage needs a threatId and a messageId, and a
caseId is neither.
Tool Usage Examples
List cases from this month:
{
"tool": "abnormal_cases_list",
"parameters": {
"filter": "createdTime gt 2026-03-01T00:00:00Z",
"pageSize": 25
}
}
Get case details:
{
"tool": "abnormal_cases_get",
"parameters": {
"caseId": 12345
}
}
Triage Workflows
Standard Triage Workflow
- List open cases - Get all cases with
overallStatus eq 'Open' - Sort by severity - Address critical and high severity first
- Review AI judgment:
- If Malicious: verify and remediate across organization
- If Spam: dismiss or move to junk
- If Safe: dismiss and respond to reporter
- If No Action Needed: dismiss (likely phishing simulation)
- Decide - produce the disposition and the evidence for it
- Hand off - the case's own state (Open → Acknowledged → Done) can
only be changed in the Abnormal portal. If mail still needs pulling
from inboxes, that runs through the threat:
abnormal_messages_listthenabnormal_remediation_manageper message.
Bulk Triage Workflow
- Filter cases by judgment - Start with cases judged as Malicious
- Review Suspicious - Manually review cases without clear judgment
- Batch the read, not the write - paginate
abnormal_cases_listto build the full picture in one pass. There is no bulk case action to follow it with; dispositions are entered in the portal one at a time.
Escalation Criteria
Escalate a case when:
- Multiple users report the same email
- The reported email impersonates an executive
- The email contains active malware or ransomware
- Credentials may have been entered on a phishing page
- The sender is a known vendor or partner (supply chain risk)
Case Actions — where they actually happen
The dispositions below are portal actions. None of them is an MCP tool, and none can be driven from this server.
| Disposition | Effect | Where |
|---|---|---|
| Remediate | Remove the email from recipients' inboxes | Abnormal portal — or, per message, via abnormal_remediation_manage on the underlying threat |
| Mark not spam | Release email back to inbox | Abnormal portal only |
| Dismiss | Close case without action | Abnormal portal only |
The gap matters for automation design: an agent can fully triage the
queue from abnormal_cases_list and abnormal_cases_get, but the case
stays Open until a human touches the portal. Write the handoff into the
workflow rather than assuming the agent closed anything.
Error Handling
Common API Errors
| Code | Message | Resolution |
|---|---|---|
| 400 | Invalid filter | Check OData filter syntax |
| 401 | Unauthorized | Check API token |
| 403 | Insufficient permissions | Token needs abuse mailbox scope |
| 404 | Case not found | Verify the case ID — and that you passed a numeric caseId, not a threat UUID |
| 429 | Rate limited | Wait and retry |
Best Practices
- Triage daily - Review abuse mailbox cases at least once per day
- Trust the AI judgment - Abnormal's accuracy is high; use it to prioritize
- Remediate every message, not "the case" - remediation is per message on the underlying threat; loop
abnormal_remediation_manageand confirm each one, or you will leave the campaign half-pulled - Respond to reporters - Let users know their report was reviewed
- Track phishing simulation reports - Monitor security awareness training effectiveness
- Correlate with threats - Check if reported emails match known threat campaigns
- Monitor false positive rate - High FP rates may indicate policy tuning needed
Related Skills
- Abnormal Threats - Threat detection and analysis
- Abnormal Messages - Message analysis
- Abnormal API Patterns - API authentication and usage
Alternatives
Compare before choosing
alirezarezvani/claude-skills
app-store-optimization
App Store Optimization (ASO) toolkit for researching keywords, analyzing competitor rankings, generating metadata suggestions, and improving app visibility on Apple App Store and Google Play Store. Use when the user asks about ASO, app store rankings, app metadata, app titles and descriptions, app store listings, app visibility, or mobile app marketing on iOS or Android. Supports keyword research and scoring, competitor keyword analysis, metadata optimization, A/B test planning, launch checklist
prowler-cloud/prowler
postgresql-indexing
PostgreSQL indexing best practices for Prowler: index design, partial indexes, partitioned table indexing, EXPLAIN ANALYZE validation, concurrent operations, monitoring, and maintenance. Trigger: When creating or modifying PostgreSQL indexes, analyzing query performance with EXPLAIN, debugging slow queries, reviewing index usage statistics, reindexing, dropping indexes, or working with partitioned table indexes. Also trigger when discussing index strategies, partial indexes, or index maintenance
wanshuiyin/Auto-claude-code-research-in-sleep
citation-audit
Use it for operations and research tasks; the detail page covers purpose, installation, and practical steps.
K-Dense-AI/scientific-agent-skills
dask
Distributed computing for larger-than-RAM pandas/NumPy workflows. Use when you need to scale existing pandas/NumPy code beyond memory or across clusters. Best for parallel file processing, distributed ML, integration with existing pandas code. For out-of-core analytics on single machine use vaex; for in-memory speed use polars.