api-patterns
3CX's native PBX MCP server: the per-PBX endpoint shape (every PBX is its own FQDN and its own OAuth authorization server — there is no shared mcp.3cx.com),…
KnowBe4 phishing simulations: campaign creation and lifecycle, security test management, recipient interaction tracking (sent, opened, clicked, reported), phish-prone percentage calculation, template selection, landing pages, and click tracking.
$ npx -y skills add wyre-technology/msp-claude-plugins --skill phishing --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/phishingContext preview
The summary Claude sees to decide when to auto-load this skill.
KnowBe4 phishing simulations: campaign creation and lifecycle, security test management, recipient interaction tracking (sent, opened, clicked, reported), phish-prone percentage calculation, template selection, landing pages, and click tracking.
name: "KnowBe4 Phishing" description: > KnowBe4 phishing simulations: campaign creation and lifecycle, security test management, recipient interaction tracking (sent, opened, clicked, reported), phish-prone percentage calculation, template selection, landing pages, and click tracking. when_to_use: >- When creating, managing, or analyzing KnowBe4 phishing simulation campaigns. Use when: knowbe4 phishing, phishing campaign, phishing simulation, phish-prone percentage, security test knowbe4, phishing template, click tracking, phishing results, simulated phishing, phishing report, recipient tracking, phishing landing page, or phishing test.
KnowBe4 phishing simulations are the core mechanism for testing and improving an organization's resilience to social engineering attacks. Campaigns deliver simulated phishing emails to users and track their interactions -- whether they opened the email, clicked the link, submitted data on the landing page, reported it via the Phish Alert Button, or took no action. The phish-prone percentage is the key metric derived from these campaigns.
click, and "failure" here is a simulation the MSP sent on purpose. Genuine inbound phishing is detected by the mail-security vendor: `proofpoint-tap`, `avanan-threats`, or `abnormal-security-threats`.
KnowBe4 never touches production mail flow. Use `proofpoint-quarantine` or `avanan-quarantine` to release, and `proofpoint-forensics` to remove delivered mail.
skill counts PAB reports as a pass/fail signal on a simulation; the real user-reported phishing triage queue is `ironscales-incidents`.
enrollment side is `knowbe4-training`.
breakdowns** — per-campaign results are here; rolled-up metrics and benchmarks are `knowbe4-reporting`.
CREATED ──> SCHEDULED ──> IN_PROGRESS ──> COMPLETED
│ │
└──── CANCELLED └──> ARCHIVED| Type | Description | Use Case | |------|-------------|----------| | **Phishing** | Standard email with link to landing page | Most common, baseline testing | | **Vishing** | Voice-based social engineering simulation | Phone-based attack awareness | | **Smishing** | SMS-based phishing simulation | Mobile threat awareness | | **USB** | Physical USB drop test | Physical security awareness | | **QR Code** | QR code-based phishing | Emerging threat vector |
Each recipient in a campaign progresses through trackable states:
| State | Description | Indicates | |-------|-------------|-----------| | **Delivered** | Email successfully delivered | Baseline count | | **Opened** | Recipient opened the email | Curiosity/engagement | | **Clicked** | Recipient clicked the phishing link | Failed the test | | **Replied** | Recipient replied to the email | Failed the test (data leakage risk) | | **Attachment Opened** | Recipient opened an attachment | Failed the test | | **Macro Enabled** | Recipient enabled macros in attachment | Critical failure | | **Data Entered** | Recipient submitted data on landing page | Critical failure | | **Reported** | Recipient reported via Phish Alert Button | Passed the test | | **No Action** | No interaction recorded | Neutral (may not have seen it) |
The phish-prone percentage (PPP) is the primary metric for organizational risk:
function calculatePhishPronePercentage(campaign) {
const totalDelivered = campaign.recipients.filter(r => r.delivered).length;
const totalFailed = campaign.recipients.filter(r =>
r.clicked || r.replied || r.attachmentOpened || r.macroEnabled || r.dataEntered
).length;
if (totalDelivered === 0) return 0;
return ((totalFailed / totalDelivered) * 100).toFixed(1);
}**Industry Benchmarks:** | PPP Range | Rating | Context | |-----------|--------|---------| | 0-5% | Excellent | Well-trained organization | | 5-15% | Good | Regular training in place | | 15-30% | Average | Industry baseline for new programs | | 30-50% | Poor | Needs immediate attention | | 50%+ | Critical | High-risk organization |
| Field | Type | Description | |-------|------|-------------| | `campaign_id` | int | Unique campaign identifier | | `name` | string | Campaign name | | `status` | string | Current status (created, scheduled, in_progress, completed) | | `create_date` | datetime | When campaign was created | | `start_date` | datetime | Scheduled start date | | `end_date` | datetime | Campaign end date | | `duration_type` | string | How long the campaign runs (e.g., one_week, two_weeks) | | `send_duration` | string | Email delivery spread period | | `track_duration` | string | How long to track interactions after delivery | | `frequency_type` | string | One-time, weekly, bi-weekly, monthly | | `phishing_template_id` | int | Template used for the phishing email | | `landing_page_id` | int | Landing page shown after click | | `groups` | array | Target groups for the campaign |
| Field | Type | Description | |-------|------|-------------| | `pst_id` | int | Unique se
One command to supercharge Claude Code for MSP workflows. Then restart Claude Code. That's it. Documentation: mcp.wyre.ai
Repo: wyre-technology/msp-claude-plugins
3CX's native PBX MCP server: the per-PBX endpoint shape (every PBX is its own FQDN and its own OAuth authorization server — there is no shared mcp.3cx.com),…
3CX's live-operations surface: read-only visibility into active calls, recordings, voicemail, department and queue membership, and forwarding/presence…
3CX's read-only directory surface: resolving a caller by email or by exact extension, searching the PBX's own phonebooks, searching contacts synced from an…
3CX's system-and-configuration surface: server time, PBX event log and application log search, service status, database schema and the read-only SELECT-only…
Abnormal Security abuse mailbox cases: user-reported email submissions, case statuses and judgments, the case lifecycle, bulk and remediation actions, and…
Abnormal Security message analysis: message retrieval, email header inspection, attachments, sender reputation, delivery context, and SPF/DKIM/DMARC…