cases

Manage Abnormal Security cases and analyze user-reported phishing email abuse reports.

39|17|Updated Feb 4, 2026
One-click install
npx skills add https://github.com/wyre-technology/msp-claude-plugins --skill cases
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cases
Source: https://github.com/wyre-technology/msp-claude-plugins/tree/main/msp-claude-plugins/abnormal/abnormal/skills/cases
Command: npx skills add https://github.com/wyre-technology/msp-claude-plugins --skill cases

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill streamlines the management of security investigations and user-reported threats within the Abnormal Security platform, reducing response times and improving threat containment.

Core Features & Use Cases

  • Case Management: List and filter active security cases by severity and status.
  • Abuse Report Processing: Ingest and analyze user-reported phishing emails for malicious activity.
  • Use Case: Automatically review all open, high-severity Abnormal Security cases from the past 24 hours to prioritize critical threats.

Quick Start

List all open security cases in Abnormal Security.

Frequently Asked Questions about cases

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I list and filter Abnormal Security cases by severity and status?

You can list Abnormal Security cases by applying specific filters for case severity and status. This allows security teams to isolate active investigations and prioritize incident response workflows based on the threat level of open cases.

Can I automatically review daily abuse reports and phishing emails?

Yes, you can automatically review daily abuse reports to process user-reported phishing emails. The system ingests these reports and analyzes them for malicious activity, supporting automated threat detection and daily incident response workflows.

What is the best way to retrieve abuse reports using time-based or verdict-based filtering?

The best way to retrieve abuse reports is by applying time-based or verdict-based filters. This mechanism queries user-reported threats based on when they were submitted or the analytical verdict assigned, streamlining malicious activity analysis.

Does this tool support filtering high-severity security cases from the past 24 hours?

Yes, the tool supports filtering high-severity security cases from the past 24 hours. This capability helps security teams automatically review critical threats and prioritize incident response efforts for recent, high-priority investigations.

How do I manage user-reported threats and incident response workflows for Abnormal Security?

You can manage user-reported threats by ingesting abuse reports and listing active security cases within Abnormal Security. This streamlines incident response workflows, reducing response times and improving overall threat containment.

What are the limitations when processing abuse reports for malicious activity?

The metadata does not specify explicit limitations for processing abuse reports, but the mechanism relies on time-based and verdict-based filtering. It is designed to analyze user-reported phishing emails to support incident response workflows.