api-patterns
3CX's native PBX MCP server: the per-PBX endpoint shape (every PBX is its own FQDN and its own OAuth authorization server — there is no shared mcp.3cx.com),…
RocketCyber application inventory: detecting, categorizing, and monitoring applications across managed endpoints, including approved-vs-unapproved software, app-level threat detection, and software compliance reporting.
$ npx -y skills add wyre-technology/msp-claude-plugins --skill apps --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/appsContext preview
The summary Claude sees to decide when to auto-load this skill.
RocketCyber application inventory: detecting, categorizing, and monitoring applications across managed endpoints, including approved-vs-unapproved software, app-level threat detection, and software compliance reporting.
name: "RocketCyber Apps" description: > RocketCyber application inventory: detecting, categorizing, and monitoring applications across managed endpoints, including approved-vs-unapproved software, app-level threat detection, and software compliance reporting. when_to_use: >- When working with RocketCyber application inventory. Use when: rocketcyber app, rocketcyber application, rocketcyber software, rocketcyber inventory, application detection rocketcyber, software compliance rocketcyber, rocketcyber installed software, or app monitoring rocketcyber.
RocketCyber tracks applications detected across managed endpoints through its agent telemetry. The application inventory provides visibility into what software is installed and running in customer environments, supporting security compliance, threat investigation, and software governance.
Key capabilities:
RMM audit is the fuller inventory; use `datto-rmm-audit`.
`rocketcyber-agents`.
`rocketcyber-incidents`.
RocketAgent continuously monitors endpoints and reports detected applications back to the RocketCyber platform. Detection covers:
Applications may be categorized by type (verify categories against API docs):
| Category | Description | Examples | |----------|-------------|---------| | **Security** | Security and antivirus tools | Windows Defender, CrowdStrike, SentinelOne | | **Remote Access** | Remote control and access tools | TeamViewer, AnyDesk, LogMeIn | | **Productivity** | Business and productivity software | Microsoft Office, Google Workspace | | **Communication** | Messaging and collaboration | Slack, Teams, Zoom | | **Development** | Development tools and IDEs | Visual Studio, VS Code, Git | | **System** | OS and system utilities | Windows Update, .NET Runtime | | **Unknown/Other** | Uncategorized applications | Custom or niche software |
Application inventory matters for security because:
| Field | Type | Description | |-------|------|-------------| | `id` | integer | Unique application record identifier (verify against API docs) | | `name` | string | Application name | | `version` | string | Application version (verify against API docs) | | `publisher` | string | Application publisher/vendor (verify against API docs) | | `category` | string | Application category (verify against API docs) | | `accountId` | integer | Customer account where the app was detected | | `agentId` | integer | Agent/endpoint where the app was detected (verify against API docs) | | `hostname` | string | Endpoint hostname (verify against API docs) | | `detectedAt` | datetime | When the application was first detected (verify against API docs) | | `lastSeen` | datetime | Most recent detection timestamp (verify against API docs) |
> **Note:** Field names are inferred from common SOC platform conventions. Verify exact field names against RocketCyber API responses.
# Applications for a specific customer
curl -s "https://api-${ROCKETCYBER_REGION:-us}.rocketcyber.com/v3/apps?accountId=12345" \
-H "Authorization: Bearer ${ROCKETCYBER_API_KEY}"**Response (verify against API docs):**
{
"data": [
{
"id": 7001,
"name": "TeamViewer",
"version": "15.40.0",
"publisher": "TeamViewer GmbH",
"category": "Remote Access",
"accountId": 12345,
"hostname": "WORKSTATION-01",
"detectedAt": "2026-01-15T08:00:00Z",
"lastSeen": "2026-02-23T09:00:00Z"
},
{
"id": 7002,
"name": "Windows Defender",
"version": "4.18.24010",
"publisher": "Microsoft",
"category": "Security",
"accountId": 12345,
"hostname": "WORKSTATION-01",
"detectedAt": "2025-06-15T09:00:00Z",
"lastSeen": "2026-02-23T09:00:00Z"
}
],
"totalCount": 150,
"page": 1,
"limit": 50
}# All applications across all customer accounts
curl -s "https://api-us.rocketcyber.com/v3/apps" \
-H "Authorization: Bearer ${ROCKETCYBER_API_KEY}"1. **List all applications** across accounts (or for a specific account) 2. **Filter for remote access tools** -- TeamViewer, AnyDesk, LogMeIn, Splashtop, etc. 3. **Cross-reference** against approved remote access policy 4. **Flag unauthorized** remote access tools for investigation 5. **Check incidents** -- correlate with any security incidents on the same endpoints
1. **List all agents** for a customer account 2. **List all applications** for the same account 3. **For each agent/endpoint**, check for require
One command to supercharge Claude Code for MSP workflows. Then restart Claude Code. That's it. Documentation: mcp.wyre.ai
Repo: wyre-technology/msp-claude-plugins
3CX's native PBX MCP server: the per-PBX endpoint shape (every PBX is its own FQDN and its own OAuth authorization server — there is no shared mcp.3cx.com),…
3CX's live-operations surface: read-only visibility into active calls, recordings, voicemail, department and queue membership, and forwarding/presence…
3CX's read-only directory surface: resolving a caller by email or by exact extension, searching the PBX's own phonebooks, searching contacts synced from an…
3CX's system-and-configuration surface: server time, PBX event log and application log search, service status, database schema and the read-only SELECT-only…
Abnormal Security abuse mailbox cases: user-reported email submissions, case statuses and judgments, the case lifecycle, bulk and remediation actions, and…
Abnormal Security message analysis: message retrieval, email header inspection, attachments, sender reputation, delivery context, and SPF/DKIM/DMARC…