๐งช Community โ Claude Code โ Claude Desktop ๐ Requires MCP Server โข Abnormal
Abnormal Security
Abnormal Security - AI-powered email security, phishing detection, account takeover prevention
๐ Recommended MCP Server
Pair this plugin with the Abnormal Security MCP for direct API access alongside skills and commands.
Installation
Install this plugin individually:
/plugin marketplace add wyre-technology/msp-claude-plugins --plugin abnormal-security Or install all MSP plugins at once:
/plugin marketplace add wyre-technology/msp-claude-plugins Features
- Cases
- Messages
- Threats
Skills
This plugin provides 4 skills that teach Claude about Abnormal Security:
| Skill | Description |
|---|---|
cases | Abnormal Security abuse mailbox cases: user-reported email submissions, case statuses and judgments, the case lifecycle, bulk and remediation actions, and phishing simulation handling. |
messages | Abnormal Security message analysis: message retrieval, email header inspection, attachments, sender reputation, delivery context, and SPF/DKIM/DMARC authentication results. |
threats | Abnormal Security threat detection: threat types (BEC, phishing, malware, socially-engineered attacks, spam, graymail, credential theft), attack vectors, severity assessment, remediation actions, and investigation workflows. |
api-patterns | Abnormal Security REST API fundamentals: Bearer token authentication, base URLs, rate limiting, pagination, OData filtering, request/response formats, and error handling. |
Agents
This plugin provides 2 agents for autonomous task execution:
| Agent | Description |
|---|---|
email-threat-analyst | Use this agent when investigating email threats detected by Abnormal Security, analyzing attack chains, assessing user exposure, or managing per-message remediation across client tenants. |
threat-report-generator | Use this agent when generating periodic threat landscape reports from Abnormal Security data across the MSP client portfolio โ not for live threat investigation, but for summarizing attack trends, most targeted organizations, most common attack types, BEC attempt volumes, and remediation effectiveness over time. |
Commands
Available slash commands:
| Command | Description |
|---|---|
/case-review | Review and triage abuse mailbox cases in Abnormal Security |
/search-threats | Search for specific threat patterns in Abnormal Security by sender, recipient, attack type, or keywords |
/threat-triage | Triage recent email threats detected by Abnormal Security by severity and attack type |
API Reference
| Base URL | |
| Authentication | |
| Rate Limit | |
| Documentation |
Example Usage
Review and triage abuse mailbox cases in Abnormal Security
/case-review Search for specific threat patterns in Abnormal Security by sender, recipient, attack type, or keywords
/search-threats Triage recent email threats detected by Abnormal Security by severity and attack type
/threat-triage Using Skills
/skill abnormal-security:cases
Abnormal Security abuse mailbox cases: user-reported email submissions, case statuses and judgments, the case lifecycle, bulk and remediation actions, and phishing simulation handling.