Abuseipdb api
AbuseIPDB API reference. IP reputation and abuse report lookups.From its SKILL.md
npx -y skills add Liberty91LTD/cti-skills --skill abuseipdb-apiAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
3 things to look at
- reads credentialsReads from 1 credential source: `ABUSEIPDB_API_KEY`.
- 16 stars16 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
- fetches URLsInstructs the agent to fetch 2 URLs, including https://api.abuseipdb.com/api/v2/check and 1 more.
SKILL.md
1.8 KB, 519 tokens by cl100k_base, as published. Nobody here has run it
AbuseIPDB API v2
Base URL
https://api.abuseipdb.com/api/v2
Authentication
Header: Key: $ABUSEIPDB_API_KEY
Also: Accept: application/json
Rate Limits
- Free: 1000 checks/day, 500 reports/day
- Premium: Higher limits
Key Endpoints
Check IP
curl -s "https://api.abuseipdb.com/api/v2/check" \
-G -d "ipAddress={ip}" -d "maxAgeInDays=90" -d "verbose" \
-H "Key: $ABUSEIPDB_API_KEY" -H "Accept: application/json"
Useful fields:
data.abuseConfidenceScore— 0-100 abuse confidencedata.totalReports— number of abuse reportsdata.numDistinctUsers— unique reportersdata.lastReportedAt— most recent reportdata.isp— ISP namedata.usageType— usage type (Data Center, ISP, etc.)data.countryCode— countrydata.domain— associated domaindata.isTor— Tor exit node flagdata.reports[]— individual reports (withverbose)
Check Network (CIDR)
curl -s "https://api.abuseipdb.com/api/v2/check-block" \
-G -d "network={cidr}" -d "maxAgeInDays=90" \
-H "Key: $ABUSEIPDB_API_KEY" -H "Accept: application/json"
Confidence Score Interpretation
| Score | Meaning |
|---|---|
| 0 | No reports, clean |
| 1-25 | Low confidence of abuse |
| 26-50 | Moderate — some reports |
| 51-75 | High — significant abuse reports |
| 76-100 | Very high — widely reported as abusive |
Response Summary Format
ip: <IP>
abuse_confidence: <0-100>
total_reports: <number>
distinct_reporters: <number>
last_reported: <date>
isp: <ISP>
usage_type: <type>
country: <country>
is_tor: <true/false>
verdict: clean|low-risk|suspicious|malicious
What ships with it
Read from the repository
Just SKILL.md. No reference files, no scripts.