From blackpoint
Use this skill when analyzing Blackpoint Cyber (CompassOne) exposure data — host vulnerability findings filtered by CVE and exploitability, vulnerability scan history, dark-web credential and data leaks, and external internet-facing exposures.
How this skill is triggered — by the user, by Claude, or both
Slash command
/blackpoint:vulnerability-managementWhen to use
When working with Blackpoint Cyber / CompassOne vulnerability data — host-level findings, scan history, dark-web exposures, and internet-facing external exposures — and building prioritized remediation views. Use when: blackpoint vulnerability, blackpoint vulnerabilities, compassone vulnerability, blackpoint scan, blackpoint dark web, blackpoint external exposure, blackpoint cve, or blackpoint exposure.
The summary Claude sees in its skill listing — used to decide when to auto-load this skill
CompassOne exposes four exposure lenses against a tenant's assets:
CompassOne exposes four exposure lenses against a tenant's assets: host-level vulnerabilities, scan history, dark-web leaks, and internet-facing external exposures. This skill covers all four and how to combine them into a prioritized remediation view.
| Tool | Purpose |
|---|---|
blackpoint_vulnerabilities_list | Host-level vulnerability findings |
blackpoint_vulnerabilities_scans_list | Vulnerability scan history and status |
blackpoint_vulnerabilities_darkweb_list | Dark-web exposures (leaked data) |
blackpoint_vulnerabilities_external_list | Internet-facing external exposures |
blackpoint_vulnerabilities_list accepts:
tenant_id, asset_id — scopeseverity — low, medium, high, criticalstatus — open, fixed, ignored, false_positivecve_id — pivot on a specific CVEpatch_available — is a fix published?exploit_available — is it weaponized in the wild?The fix-now cohort is the intersection: severity in
{high, critical}, status: open, exploit_available: true,
patch_available: true — a known, weaponized, fixable problem that
has not been fixed.
blackpoint_vulnerabilities_darkweb_list exposure types:
credentials, documents, data_breach, malware.
blackpoint_vulnerabilities_external_list exposure types:
open_port, vulnerable_service, certificate_issue,
misconfiguration.
blackpoint_vulnerabilities_scans_list status values:
pending, running, completed, failed.
blackpoint_vulnerabilities_scans_list — if the last
completed scan is stale or recent scans failed, say so; it
caps confidence in everything below.blackpoint_vulnerabilities_list for the tenant.blackpoint_vulnerabilities_darkweb_list for the tenant.credentials exposures, recommend forced password resets and
an MFA enforcement check.data_breach and malware exposures for follow-up.blackpoint_vulnerabilities_external_list for the tenant.vulnerable_service and
open_port on management ports as highest priority.certificate_issue findings for a complete edge view.npx claudepluginhub wyre-technology/msp-claude-plugins --plugin blackpointUse this skill when investigating a Blackpoint Cyber detection — drilling from a tenant to its assets, walking the detection list, pulling vulnerability and dark-web context, and assembling an incident timeline.
Tracks and analyzes SentinelOne XSPM CVEs, EPSS scores, exploit maturity, and vulnerability status. Generates vulnerability reports for MSP client environments.
Maps internet-facing assets ranked by risk, exposed ports/services, and attacker's-eye view of the environment.