๐Ÿงช Community โœ“ Claude Code โœ“ Claude Desktop ๐Ÿ”Œ Requires MCP Server โ€ข Abnormal

Abnormal Security

Abnormal Security - AI-powered email security, phishing detection, account takeover prevention

๐Ÿ”Œ Recommended MCP Server

Pair this plugin with the Abnormal Security MCP for direct API access alongside skills and commands.

Installation

Install this plugin individually:

/plugin marketplace add wyre-technology/msp-claude-plugins --plugin abnormal-security

Or install all MSP plugins at once:

/plugin marketplace add wyre-technology/msp-claude-plugins

Features

  • Cases
  • Messages
  • Threats

Skills

This plugin provides 4 skills that teach Claude about Abnormal Security:

Skill Description
cases Abnormal Security abuse mailbox cases: user-reported email submissions, case statuses and judgments, the case lifecycle, bulk and remediation actions, and phishing simulation handling.
messages Abnormal Security message analysis: message retrieval, email header inspection, attachments, sender reputation, delivery context, and SPF/DKIM/DMARC authentication results.
threats Abnormal Security threat detection: threat types (BEC, phishing, malware, socially-engineered attacks, spam, graymail, credential theft), attack vectors, severity assessment, remediation actions, and investigation workflows.
api-patterns Abnormal Security REST API fundamentals: Bearer token authentication, base URLs, rate limiting, pagination, OData filtering, request/response formats, and error handling.

Agents

This plugin provides 2 agents for autonomous task execution:

Agent Description
email-threat-analyst Use this agent when investigating email threats detected by Abnormal Security, analyzing attack chains, assessing user exposure, or managing per-message remediation across client tenants.
threat-report-generator Use this agent when generating periodic threat landscape reports from Abnormal Security data across the MSP client portfolio โ€” not for live threat investigation, but for summarizing attack trends, most targeted organizations, most common attack types, BEC attempt volumes, and remediation effectiveness over time.

Commands

Available slash commands:

Command Description
/case-review Review and triage abuse mailbox cases in Abnormal Security
/search-threats Search for specific threat patterns in Abnormal Security by sender, recipient, attack type, or keywords
/threat-triage Triage recent email threats detected by Abnormal Security by severity and attack type

API Reference

Base URL
Authentication
Rate Limit
Documentation

Example Usage

Review and triage abuse mailbox cases in Abnormal Security

/case-review

Search for specific threat patterns in Abnormal Security by sender, recipient, attack type, or keywords

/search-threats

Triage recent email threats detected by Abnormal Security by severity and attack type

/threat-triage

Using Skills

/skill abnormal-security:cases

Abnormal Security abuse mailbox cases: user-reported email submissions, case statuses and judgments, the case lifecycle, bulk and remediation actions, and phishing simulation handling.