ironscales_incidents

Manage Ironscales phishing incidents via API for triage, classification, and remediation.

39|17|Updated Feb 4, 2026
One-click install
npx skills add https://github.com/wyre-technology/msp-claude-plugins --skill ironscales-incidents
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: ironscales_incidents
Source: https://github.com/wyre-technology/msp-claude-plugins/tree/main/msp-claude-plugins/ironscales/ironscales/skills/incidents
Command: npx skills add https://github.com/wyre-technology/msp-claude-plugins --skill ironscales-incidents

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This Skill streamlines the management of phishing incidents within Ironscales, enabling efficient triaging, classification, and remediation of email threats.

Core Features & Use Cases

  • Incident Triage: List and review open phishing incidents, prioritizing based on AI confidence.
  • Email Classification: Classify emails as phishing, spam, or legitimate to trigger automated remediation.
  • Remediation Actions: Execute actions like removing emails, blocking senders/domains, or allowlisting.
  • Dashboarding: View company-wide statistics on phishing trends and user reporting rates.
  • Use Case: Automatically classify a high-confidence phishing incident reported by a user, remove the malicious email from all mailboxes, and block the sender's domain.

Quick Start

List all open phishing incidents reported by users.

Frequently Asked Questions about ironscales_incidents

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate phishing incident response and email remediation?

Classify emails as phishing, spam, or legitimate to trigger automated remediation workflows. This classification enables the system to automatically remove malicious emails from mailboxes and block sender domains.

How do I remove malicious emails from all user mailboxes after a phishing attack?

Block malicious senders and domains by executing remediation actions on triaged phishing incidents. The workflow also supports managing sender allowlists to prevent false positives during threat response.

Can I view company-wide phishing trends and user reporting rates?

List and review open phishing incidents by prioritizing them based on AI confidence scores. This triage process helps security administrators identify high-priority threats for immediate remediation.

What is needed to integrate with Ironscales for automated threat detection?

The Ironscales integration supports automated threat response workflows for security administrators by providing incident data access. It allows classifying emails and executing remediation actions like blocking senders or managing allowlists.