generated: '2026-08-04' method: generated source: >- openapi/malwarebytes-threatdown-nebula-openapi.json, openapi/malwarebytes-threatdown-oneview-openapi.json summary: >- Packaged Agent Skills for the ThreatDown Nebula and OneView APIs, generated by API Evangelist. Malwarebytes publishes no AGENTS.md, no skills, and no MCP server, so these are authored from the harvested OpenAPI definitions. Every operationId referenced was verified to exist in the source spec — none are invented. Each skill carries the cross-cutting rules the spec omits: the two-gate authorization model, the undeclared error envelope, the 360 req/min budget, and the absence of any idempotency key on destructive writes. provider_published_skills: false provider_agents_md: false skills: - name: malwarebytes-detection-triage file: skills/malwarebytes-detection-triage.md api: ThreatDown Nebula API flow: >- Investigate a detection end to end — search, pull the record, inspect the endpoint and its correlated EDR activity, then either submit a false positive or issue a containment job and track it to completion. operations: - api.oauth2.token - api.v2.nebula.search.detections - api.v2.nebula.get.detections.id - api.v2.nebula.get.endpoint.id - api.nebula.endpoint.id.sa - api.v2.nebula.detections.submit.fp - api.v2.nebula.post.jobs - api.v2.nebula.get.jobs.id scopes: [read, write, execute] consequence: destructive note: Issues real actions (Scan/Isolate/Remediate/Reboot) against production machines. - name: malwarebytes-webhook-subscription file: skills/malwarebytes-webhook-subscription.md api: ThreatDown Nebula API and ThreatDown OneView API flow: >- Register a webhook subscription, verify the HMAC signature on every delivery, handle the envelope, acknowledge correctly, and manage the subscription lifecycle. operations: - api.oauth2.token - api.v2.nebula.post.webhooks.subscriptions - api.v2.nebula.webhooks.subscriptions.get - api.v2.nebula.webhooks.subscriptions.get.id - api.v2.nebula.post.webhooks.subscriptions.update - api.v2.nebula.post.webhooks.subscriptions.delete - api.v2.rmm.post.webhooks.subscriptions scopes: [read, write] consequence: write note: >- The foundational skill — ThreatDown steers every integration off polling and onto webhooks, and subscriptions can only be created through the API. - name: malwarebytes-vulnerability-review file: skills/malwarebytes-vulnerability-review.md api: ThreatDown Nebula API flow: >- Size CVE exposure with groupBy, page the rows that matter, pull detail in bulk, tie findings to the software inventory, suppress accepted risk, and export asynchronously. operations: - api.oauth2.token - api.nebula.search.cve - api.nebula.search.cve.group - api.nebula.get.cve.id - api.nebula.get.cves.bulk - api.nebula.ignore.cve - api.nebula.post.export.cve.async - api.v2.nebula.get.endpoint.id.assets scopes: [read, write] consequence: write note: The most rate-limit-hostile workflow on the API; the skill leads with budget discipline. - name: malwarebytes-msp-site-onboarding file: skills/malwarebytes-msp-site-onboarding.md api: ThreatDown OneView API flow: >- Onboard a managed customer — create the Site, attach the subscription that mints the account_id, provision users at least privilege, then register per-account webhooks. operations: - api.oneview.oauth2.token - api.oneview.create.customer - api.oneview.get.all.customers - api.oneview.get.customer - api.v2.oneview.create.subscription.id - api.v2.oneview.get.subscription.all - api.oneview.create.contact - api.oneview.get-all.contact - api.oneview.get.customer.by.nebula-account - api.v2.rmm.post.webhooks.subscriptions scopes: [read, write] consequence: write warning: >- All six per-site subscription operations are marked deprecated in the current definition, with no replacement, no Sunset header and no removal date. cross_cutting_rules_every_skill_carries: - >- Two independent authorization gates — OAuth2 scope (read/write/execute) AND the granular user permission held by the application's creating user. Both fail as a bare 403 with no discriminator. - >- The spec declares NO 4xx or 5xx responses on any of its 841 operations. The live envelope is {statusCode, error, message}. Agents must not assume calls succeed. - >- 360 requests/minute, leaky bucket, 429 on exhaustion, no Retry-After and no RateLimit-* headers. Backoff must be blind. Prefer groupBy, bulk, async export and webhooks. - >- NO idempotency key exists anywhere. Job issuance, Site creation and user provisioning are all unsafe to blind-retry. Read back before reissuing. - >- Validation runs before authentication, so 400s are returned to unauthenticated callers. related_artifacts: - conventions/malwarebytes-conventions.yml - errors/malwarebytes-problem-types.yml - rate-limits/malwarebytes-rate-limits.yml - scopes/malwarebytes-scopes.yml - authentication/malwarebytes-authentication.yml - asyncapi/malwarebytes-threatdown-webhooks.yml - data-model/malwarebytes-data-model.yml