WYRE-AI/msp-claude-plugins/msp-claude-plugins/sentinelone/sentinelone/skills/inventory/SKILL.md
SentinelOne Inventory
SentinelOne's unified asset inventory across four surface types — agent-managed endpoints, AWS/Azure/GCP cloud resources, AD/Entra identities, and Ranger-discovered network devices. Covers the read-only inventory tools, the REST (not GraphQL) offset-pagination and filter model, asset field reference, and agent-coverage audit workflows.
- Source repository stars
- 42
- Declared platforms
- 0
- Static risk flags
- 1
- Last source update
- 2026-08-28
- Source checked
- 2026-08-28
Decision brief
What it does: where it fits
SentinelOne's unified asset inventory across four surface types — agent-managed endpoints, AWS/Azure/GCP cloud resources, AD/Entra identities, and Ranger-discovered network devices. Covers the read-only inventory tools, the REST (not GraphQL) offset-pagination and filter model, asset field reference, and agent-coverage audit workflows.
Not for
- Tasks that require unconfirmed production actions or broad system permissions.
- Environments where the pinned source and install steps cannot be inspected.
Compatibility matrix
Platform support, with evidence labels
| Platform | Status | Evidence | What to check |
|---|---|---|---|
| Codex | Not declared | No explicit evidence | Portability before use |
| Claude Code | Not declared | No explicit evidence | Portability before use |
| Cursor | Not declared | No explicit evidence | Portability before use |
| Gemini CLI | Not declared | No explicit evidence | Portability before use |
Installation
Inspect first. Install second.
The source command is displayed only when detected. A safe inspection prompt is always available so your agent can explain every action before execution.
npx skills add https://github.com/WYRE-AI/msp-claude-plugins --skill "msp-claude-plugins/sentinelone/sentinelone/skills/inventory"Inspect the Agent Skill "SentinelOne Inventory" from https://github.com/WYRE-AI/msp-claude-plugins/blob/5005f73ba2f52cd299f58aa6bb79f4e70ae87103/msp-claude-plugins/sentinelone/sentinelone/skills/inventory/SKILL.md at commit 5005f73ba2f52cd299f58aa6bb79f4e70ae87103. List every install step, command, network request, credential, file read/write, external action, and rollback step. Explain whether it fits my task. Do not install or execute anything until I approve.
Workflow
What the source asks the agent to do
- 01
Anti-triggers
Dedicated network discovery. The NETWORKDISCOVERY surface is
Dedicated network discovery. The NETWORKDISCOVERY surface isWhat an endpoint detected. This skill covers the asset record andA Huntress or ThreatLocker agent. Different vendors' sensors are - 02
MCP Tools
Call listinventoryitems with optional parameters:
Filter by surface: Set surface to ENDPOINT, CLOUD, IDENTITY, or NETWORKDISCOVERYPaginate: Set limit (results per page) and offset (skip N results)Sort results: Set sortBy and sortOrder - 03
Available Tools
Review the “Available Tools” section in the pinned source before continuing.
Review and apply the “Available Tools” source section. - 04
List Inventory Items
Call listinventoryitems with optional parameters:
Filter by surface: Set surface to ENDPOINT, CLOUD, IDENTITY, or NETWORKDISCOVERYPaginate: Set limit (results per page) and offset (skip N results)Sort results: Set sortBy and sortOrder - 05
Search Inventory Items
Call searchinventoryitems with filters for targeted queries:
searchinventoryitems with surface=ENDPOINT, filters={"namecontains": "workstation-01"}searchinventoryitems with surface=ENDPOINT, filters={"osType": "WINDOWS", "machineType": "SERVER"}Call searchinventoryitems with filters for targeted queries:
Permission review
Static risk signals and limitations
Network access
The documentation includes network, browsing, or remote request actions.
*Example: Search for a specific endpoint by name:**Network access
The documentation includes network, browsing, or remote request actions.
For each client, query all four surfaces: ENDPOINT, CLOUD, IDENTITY, NETWORK_DISCOVERYEvidence record
Why each signal appears
| Signal | Value | Evidence type | Meaning |
|---|---|---|---|
| Quality score | 93/100 | Computed | Documentation, specificity, maintenance, and trust rules |
| Repository stars | 42 | Source | Repository attention, not individual Skill quality |
| Compatibility | 0 platforms | Source | Declared in the catalog source record |
| Usage guide | automated source guide | Editorial | Generated or reviewed according to the visible evidence level |
Pinned source
Provenance and original SKILL.md
- Repository
- WYRE-AI/msp-claude-plugins
- Skill path
- msp-claude-plugins/sentinelone/sentinelone/skills/inventory/SKILL.md
- Commit
- 5005f73ba2f52cd299f58aa6bb79f4e70ae87103
- License
- Apache-2.0
- Collected
- 2026-08-28
- Default branch
- main
View the original SKILL.md
SentinelOne Unified Asset Inventory
Overview
The SentinelOne unified asset inventory provides a single view of all assets across an organization's environment. Assets are categorized by surface type -- endpoints with SentinelOne agents, cloud resources in AWS/Azure/GCP, identity accounts from Active Directory and Entra ID, and network-discovered devices found by Ranger. For MSPs, the inventory is the foundation for security coverage -- ensuring every client device has an active agent, tracking cloud resource sprawl, and identifying unmanaged devices on client networks.
The inventory uses the REST API (not GraphQL), with offset-based pagination and direct filter parameters. All inventory tools are read-only.
Anti-triggers
- Dedicated network discovery. The
NETWORK_DISCOVERYsurface is Ranger's passive by-product of the agents you already have. A question about scanning a subnet, fingerprinting an unmanaged device, or inventorying OT/IoT gear belongs torunzero-assets; live topology and interface state belong toauvik-devices. - What an endpoint detected. This skill covers the asset record and
its agent health; findings on that asset are
sentinelone-alerts,sentinelone-vulnerabilities, orsentinelone-misconfigurations. - A Huntress or ThreatLocker agent. Different vendors' sensors are
different fleets with no shared record — use
huntress-agentsorthreatlocker-computers.
MCP Tools
Available Tools
| Tool | Description | Key Parameters |
|---|---|---|
get_inventory_item | Get a single inventory item by ID | itemId (required) |
list_inventory_items | List inventory items with filters | surface, limit, offset, sortBy, sortOrder |
search_inventory_items | Search inventory with REST filters | filters, surface, limit, offset |
List Inventory Items
Call list_inventory_items with optional parameters:
- Filter by surface: Set
surfacetoENDPOINT,CLOUD,IDENTITY, orNETWORK_DISCOVERY - Paginate: Set
limit(results per page) andoffset(skip N results) - Sort results: Set
sortByandsortOrder
Example: List all endpoints:
list_inventory_itemswithsurface=ENDPOINT,limit=100
Example: List cloud resources:
list_inventory_itemswithsurface=CLOUD,limit=100
Example: List network-discovered devices:
list_inventory_itemswithsurface=NETWORK_DISCOVERY,limit=100
Search Inventory Items
Call search_inventory_items with filters for targeted queries:
Example: Search for a specific endpoint by name:
search_inventory_itemswithsurface=ENDPOINT,filters={"name__contains": "workstation-01"}
Example: Search for Windows servers:
search_inventory_itemswithsurface=ENDPOINT,filters={"osType": "WINDOWS", "machineType": "SERVER"}
Get Inventory Item Details
Call get_inventory_item with the itemId to retrieve full details including agent status, OS information, network details, and security posture.
Key Concepts
Surface Types
| Surface | Description | Data Sources |
|---|---|---|
ENDPOINT | Managed endpoints with SentinelOne agents | Workstations, servers, laptops, VMs |
CLOUD | Cloud infrastructure resources | AWS EC2, Azure VMs, GCP instances, S3 buckets, etc. |
IDENTITY | User and service accounts | Active Directory, Entra ID (Azure AD), Okta |
NETWORK_DISCOVERY | Network-discovered devices (Ranger) | Switches, printers, IoT, unmanaged devices |
Endpoint Types
| Type | Description |
|---|---|
WORKSTATION | Desktop or laptop workstation |
SERVER | Server (physical or virtual) |
LAPTOP | Laptop (may overlap with WORKSTATION) |
VIRTUAL_MACHINE | Cloud or on-premises VM |
CONTAINER | Container workload |
Agent Status
| Status | Description |
|---|---|
ACTIVE | Agent is running and communicating |
INACTIVE | Agent installed but not communicating |
DISCONNECTED | Agent has lost connection to the console |
DECOMMISSIONED | Agent has been decommissioned |
PENDING | Agent installation in progress |
REST API Pagination
The inventory uses offset-based pagination (unlike the cursor-based GraphQL tools):
| Parameter | Description | Default |
|---|---|---|
limit | Results per page | 50 |
offset | Number of results to skip | 0 |
To iterate through all results:
- Call with
offset=0,limit=100 - If 100 results returned, call with
offset=100,limit=100 - Continue incrementing offset until fewer results than limit are returned
REST Filter Types
| Filter Type | Syntax | Description |
|---|---|---|
| Exact match | fieldName=value | Direct value comparison |
| Contains | fieldName__contains=value | Substring matching |
| Greater than or equal | fieldName__gte=value | Minimum value (dates, numbers) |
| Less than or equal | fieldName__lte=value | Maximum value (dates, numbers) |
| Not equal | fieldName__ne=value | Exclude matches |
| In list | ids=id1,id2,id3 | Match multiple IDs |
Field Reference
Core Inventory Fields
| Field | Type | Description |
|---|---|---|
itemId | string | Unique inventory item identifier |
name | string | Asset name/hostname |
surface | string | ENDPOINT/CLOUD/IDENTITY/NETWORK_DISCOVERY |
siteName | string | SentinelOne site (MSP client) |
accountName | string | SentinelOne account |
lastSeen | datetime | Last communication timestamp |
Endpoint-Specific Fields
| Field | Type | Description |
|---|---|---|
osType | string | WINDOWS/MACOS/LINUX |
osName | string | Full OS name (e.g., "Windows 11 Enterprise") |
osVersion | string | OS version string |
machineType | string | WORKSTATION/SERVER/LAPTOP/VIRTUAL_MACHINE |
agentVersion | string | SentinelOne agent version |
agentStatus | string | ACTIVE/INACTIVE/DISCONNECTED |
isUpToDate | boolean | Whether agent is on the latest version |
externalIp | string | External/public IP address |
internalIp | string | Internal/private IP address |
domain | string | AD domain membership |
lastLoggedInUser | string | Last logged-in user |
encryptionStatus | string | Disk encryption status |
firewallStatus | string | Firewall enabled/disabled |
Cloud-Specific Fields
| Field | Type | Description |
|---|---|---|
cloudProvider | string | AWS/AZURE/GCP |
region | string | Cloud region |
resourceType | string | Resource type (EC2, VM, S3, etc.) |
resourceId | string | Cloud resource identifier |
tags | object | Cloud resource tags |
Identity-Specific Fields
| Field | Type | Description |
|---|---|---|
identityProvider | string | AD/ENTRA_ID/OKTA |
email | string | User email address |
department | string | Department |
lastLogin | datetime | Last login timestamp |
mfaEnabled | boolean | Whether MFA is enabled |
accountStatus | string | Active/Disabled/Locked |
Network Discovery Fields
| Field | Type | Description |
|---|---|---|
deviceType | string | Discovered device type |
manufacturer | string | Device manufacturer |
macAddress | string | MAC address |
ipAddress | string | Discovered IP address |
managed | boolean | Whether a SentinelOne agent is installed |
firstSeen | datetime | When Ranger first discovered the device |
Common Workflows
Asset Audit
- Call
list_inventory_itemswithsurface=ENDPOINT,limit=100 - Paginate through all results using
offset - Count by OS type, agent status, and machine type
- Identify endpoints with inactive or disconnected agents
- Identify endpoints with outdated agent versions
Endpoint Health Check
- Call
list_inventory_itemswithsurface=ENDPOINT - Filter for agents not on the latest version:
isUpToDate=false - Filter for disconnected agents:
agentStatus=DISCONNECTED - Group by client (siteName) to identify which clients have unhealthy endpoints
- Generate a health report with upgrade and reconnection recommendations
Cloud Resource Inventory
- Call
list_inventory_itemswithsurface=CLOUD - Group by cloud provider and resource type
- Count resources per client (siteName)
- Identify resources not tagged according to client standards
- Cross-reference with misconfigurations for exposed resources
Unmanaged Device Discovery
- Call
list_inventory_itemswithsurface=NETWORK_DISCOVERY - Filter for
managed=falseto find devices without SentinelOne agents - Group by client (siteName) and device type
- Generate a list of unmanaged devices for agent deployment
Identity Inventory
- Call
list_inventory_itemswithsurface=IDENTITY - Check for accounts without MFA enabled
- Identify stale accounts (no login in 90+ days)
- Group by identity provider and department
- Generate an identity hygiene report
Client Coverage Report
- For each client, query all four surfaces: ENDPOINT, CLOUD, IDENTITY, NETWORK_DISCOVERY
- Count managed vs. unmanaged assets
- Calculate coverage percentage
- Identify gaps in agent deployment
- Present as a security coverage dashboard for QBR
Response Examples
Endpoint Inventory Item:
{
"itemId": "inv-endpoint-001",
"name": "ACME-WS-042",
"surface": "ENDPOINT",
"siteName": "Acme Corporation",
"osType": "WINDOWS",
"osName": "Windows 11 Enterprise",
"osVersion": "23H2",
"machineType": "WORKSTATION",
"agentVersion": "24.1.2.345",
"agentStatus": "ACTIVE",
"isUpToDate": true,
"externalIp": "203.0.113.10",
"internalIp": "192.168.1.42",
"domain": "acme.local",
"lastLoggedInUser": "jsmith",
"lastSeen": "2026-02-24T10:00:00.000Z",
"encryptionStatus": "ENCRYPTED",
"firewallStatus": "ENABLED"
}
Network Discovery Item:
{
"itemId": "inv-ranger-005",
"name": "Unknown Device",
"surface": "NETWORK_DISCOVERY",
"siteName": "Acme Corporation",
"deviceType": "Network Printer",
"manufacturer": "HP",
"macAddress": "AA:BB:CC:DD:EE:FF",
"ipAddress": "192.168.1.200",
"managed": false,
"firstSeen": "2026-02-20T14:00:00.000Z",
"lastSeen": "2026-02-24T09:30:00.000Z"
}
Error Handling
Common Errors
| Error | Cause | Resolution |
|---|---|---|
| Item not found | Invalid itemId | Verify the ID with list_inventory_items |
| Invalid surface filter | Wrong surface value | Use ENDPOINT, CLOUD, IDENTITY, or NETWORK_DISCOVERY |
| Empty results | No matching assets | Widen filters or check scope |
| Authentication error | Invalid token | Verify Service User token is Account or Site level |
| Timeout | Query too broad | Add surface or site filters to reduce result set |
Best Practices
- Always specify surface type - Filter by ENDPOINT, CLOUD, IDENTITY, or NETWORK_DISCOVERY for focused results
- Monitor agent health - Regularly check for INACTIVE or DISCONNECTED endpoints
- Track unmanaged devices - Use NETWORK_DISCOVERY to find devices without agents
- Scope to clients - Filter by siteName when reviewing a specific client's inventory
- Check agent versions - Identify endpoints with outdated agents for upgrade scheduling
- Cross-reference with alerts - Use inventory data to enrich alert investigations with asset context
- Paginate consistently - Use offset-based pagination for large inventories
- Cache inventory data - Asset data changes less frequently than alerts; cache for short periods
- Generate coverage reports - Calculate agent deployment coverage per client for QBRs
- Identify shadow IT - Network-discovered devices may reveal unauthorized equipment
Related Skills
- Alerts - Alerts affecting inventory assets
- Vulnerabilities - Vulnerabilities on inventory endpoints
- Misconfigurations - Misconfigurations on inventory resources
- API Patterns - MCP tools reference and REST API details
- Purple AI - Investigate threats on specific assets
Frequently asked questions
What to verify before installation and use
What does the SentinelOne Inventory source document cover?
SentinelOne's unified asset inventory across four surface types — agent-managed endpoints, AWS/Azure/GCP cloud resources, AD/Entra identities, and Ranger-discovered network devices. Covers the read-only inventory tools, the REST (not GraphQL) offset-pagination and filter model, asset field reference, and agent-coverage audit workflows.
How do I install SentinelOne Inventory?
The source record exposes this install command: npx skills add https://github.com/WYRE-AI/msp-claude-plugins --skill "msp-claude-plugins/sentinelone/sentinelone/skills/inventory". Inspect the command and pinned source before running it.
Which permission-related actions were detected?
Static rules flagged network in the source; the page lists the matching lines and excerpts.
Alternatives
Compare before choosing
coreyhaines31/marketingskills
ab-testing
When the user wants to plan, design, or implement an A/B test or experiment, or build a growth experimentation program. Also use when the user mentions "A/B test," "split test," "experiment," "test this change," "variant copy," "multivariate test," "hypothesis," "should I test this," "which version is better," "test two versions," "statistical significance," "how long should I run this test," "growth experiments," "experiment velocity," "experiment backlog," "ICE score," "experimentation program
garrytan/gbrain
bulk-ingestion
End-to-end discipline for turning any large data source (audio libraries, email takeouts, document corpora, chat exports, API dumps) into brain pages at scale. The lifecycle spine: SCHEMA → ACCESS → TRIAL → EVALUATE → IMPROVE → CODIFY → TEST → SKILLIFY → BULK → MONITOR. State is tracked in a durable JSON manifest (see MANIFEST-PATTERN.md) so any crash, session boundary, or subagent fan-out resumes from ground truth instead of memory.
alirezarezvani/claude-skills
app-store-optimization
App Store Optimization (ASO) toolkit for researching keywords, analyzing competitor rankings, generating metadata suggestions, and improving app visibility on Apple App Store and Google Play Store. Use when the user asks about ASO, app store rankings, app metadata, app titles and descriptions, app store listings, app visibility, or mobile app marketing on iOS or Android. Supports keyword research and scoring, competitor keyword analysis, metadata optimization, A/B test planning, launch checklist
dotnet/skills
migrate-vstest-to-mtp
Migrates .NET test projects from VSTest to Microsoft.Testing.Platform (MTP). Use when user asks to "migrate to MTP", "switch from VSTest", "enable Microsoft.Testing.Platform", "use MTP runner", set OutputType=Exe only for test projects in Directory.Build.props, or mentions EnableMSTestRunner, EnableNUnitRunner, or UseMicrosoftTestingPlatformRunner. USE FOR: MTP behavioral differences vs VSTest (exit code 8, zero tests discovered, --ignore-exit-code, TESTINGPLATFORM_EXITCODE_IGNORE); centralizing