generated: '2026-08-11' method: generated source: openapi/corestack-external-api-openapi-original.json + https://docs.corestack.io/ provider: CoreStack api: CoreStack External API base_url: https://api.corestack.io spec: openapi/corestack-external-api-openapi-original.json note: >- Packaged Agent Skills for the three marquee CoreStack flows. Every operationId named in these skills was verified present in the live published Swagger 2.0 document before being written — none is invented. CoreStack publishes no AGENTS.md and no skills of its own; these are generated by API Evangelist from the provider's contract and documentation. skills: - name: corestack-authenticate-and-scope file: corestack-authenticate-and-scope.md description: >- Mint a CoreStack auth token, set the two required headers, confirm the session's roles, and resolve the master account and tenant context every other operation needs. operations: - authToken - RefreshToken - UserSessionDetails - SwitchMasterAccount prerequisite_for: all - name: corestack-investigate-cost-anomaly file: corestack-investigate-cost-anomaly.md description: >- Find a spend spike, drill to the resources causing it, read its trend at daily granularity, and check it against the budget it broke. operations: - CostAnomalySummary - CostAnomalyResources - GetCostAggregation - GetCostAggregationTrend - ListDimensions - ListBudget - ViewBudget requires_skill: corestack-authenticate-and-scope - name: corestack-triage-graphion-findings file: corestack-triage-graphion-findings.md description: >- Walk the Graphion portfolio hierarchy to the top actionable issues, resolve the offending SBOM components and container findings, and rank by organisational prevalence rather than severity alone. operations: - ListPortfolio - PortfolioHierarchy - TopActionableIssues - SummarySbomVulnerabilities - BatchSbomComponents - ListContainerFindings - OrganizationalVulnerabilityPrevalence requires_skill: corestack-authenticate-and-scope cross_references: conventions: conventions/corestack-conventions.yml errors: errors/corestack-problem-types.yml authentication: authentication/corestack-authentication.yml rate_limits: rate-limits/corestack-rate-limits.yml mcp_alternative: mcp/corestack-mcp.yml tool_crosswalk: mcp/corestack-tool-crosswalk.yml mcp_note: >- Where an MCP client is available and the account has the MCP server enabled, the same three flows are reachable as tools — authenticate / set_active_tenant, then get_anomalies + get_anomaly_resources + get_cost_aggregation_trend, then dashboard_top_actionable_issues + vulnerability_get_prevalence. The MCP path carries a session model and a build_filter_query helper that the REST path does not. See mcp/corestack-tool-crosswalk.yml for the binding.