Abuseipdb api
Cyber Threat Intelligence Skills for each stage of the CTI Lifecycle.
npx -y skills add Liberty91LTD/cti-skills --skill abuseipdb-apiAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
One thing to look at
- 8 stars8 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
What its author says it does
Copied from the file, not written here
AbuseIPDB API reference. IP reputation and abuse report lookups.
SKILL.md
1.8 KB, as published. Nobody here has run it
AbuseIPDB API v2
Base URL
https://api.abuseipdb.com/api/v2
Authentication
Header: Key: $ABUSEIPDB_API_KEY
Also: Accept: application/json
Rate Limits
- Free: 1000 checks/day, 500 reports/day
- Premium: Higher limits
Key Endpoints
Check IP
curl -s "https://api.abuseipdb.com/api/v2/check" \
-G -d "ipAddress={ip}" -d "maxAgeInDays=90" -d "verbose" \
-H "Key: $ABUSEIPDB_API_KEY" -H "Accept: application/json"
Useful fields:
data.abuseConfidenceScore— 0-100 abuse confidencedata.totalReports— number of abuse reportsdata.numDistinctUsers— unique reportersdata.lastReportedAt— most recent reportdata.isp— ISP namedata.usageType— usage type (Data Center, ISP, etc.)data.countryCode— countrydata.domain— associated domaindata.isTor— Tor exit node flagdata.reports[]— individual reports (withverbose)
Check Network (CIDR)
curl -s "https://api.abuseipdb.com/api/v2/check-block" \
-G -d "network={cidr}" -d "maxAgeInDays=90" \
-H "Key: $ABUSEIPDB_API_KEY" -H "Accept: application/json"
Confidence Score Interpretation
| Score | Meaning |
|---|---|
| 0 | No reports, clean |
| 1-25 | Low confidence of abuse |
| 26-50 | Moderate — some reports |
| 51-75 | High — significant abuse reports |
| 76-100 | Very high — widely reported as abusive |
Response Summary Format
ip: <IP>
abuse_confidence: <0-100>
total_reports: <number>
distinct_reporters: <number>
last_reported: <date>
isp: <ISP>
usage_type: <type>
country: <country>
is_tor: <true/false>
verdict: clean|low-risk|suspicious|malicious