Abuselpdb

Learn how to use Abuselpdb with Composio

Overview

SLUG: ABUSELPDB

Description

AbuseIPDB is a project dedicated to helping make the internet safer by providing a central repository for reporting and checking IP addresses associated with malicious activities.

Authentication Details

generic_api_key
stringRequired

Connecting to Abuselpdb

Create an auth config

Use the dashboard to create an auth config for the Abuselpdb toolkit. This allows you to connect multiple Abuselpdb accounts to Composio for agents to use.

1

Select App

Navigate to the Abuselpdb toolkit page and click “Setup Integration”.

2

Configure Auth Config Settings

Select among the supported auth schemes of and configure them here.

3

Create and Get auth config ID

Click “Create Integration”. After creation, copy the displayed ID starting with ac_. This is your auth config ID. This is not a sensitive ID — you can save it in environment variables or a database. This ID will be used to create connections to the toolkit for a given user.

Connect Your Account

Using API Key

1from composio import Composio
2from composio.types import auth_scheme
3
4# Replace these with your actual values
5abuselpdb_auth_config_id = "ac_YOUR_ABUSELPDB_CONFIG_ID" # Auth config ID created above
6user_id = "0000-0000-0000" # UUID from database/app
7
8composio = Composio()
9
10def authenticate_toolkit(user_id: str, auth_config_id: str):
11 # Replace this with a method to retrieve an API key from the user.
12 # Or supply your own.
13 user_api_key = input("[!] Enter API key")
14
15 connection_request = composio.connected_accounts.initiate(
16 user_id=user_id,
17 auth_config_id=auth_config_id,
18 config={"auth_scheme": "API_KEY", "val": user_api_key}
19 )
20
21 # API Key authentication is immediate - no redirect needed
22 print(f"Successfully connected Abuselpdb for user {user_id}")
23 print(f"Connection status: {connection_request.status}")
24
25 return connection_request.id
26
27
28connection_id = authenticate_toolkit(user_id, abuselpdb_auth_config_id)
29
30# You can verify the connection using:
31connected_account = composio.connected_accounts.get(connection_id)
32print(f"Connected account: {connected_account}")

Tools

Executing tools

To prototype you can execute some tools to see the responses and working on the Abuselpdb toolkit’s playground

Python
1from composio import Composio
2from openai import OpenAI
3import json
4
5openai = OpenAI()
6composio = Composio()
7
8# User ID must be a valid UUID format
9user_id = "0000-0000-0000" # Replace with actual user UUID from your database
10
11tools = composio.tools.get(user_id=user_id, toolkits=["ABUSELPDB"])
12
13print("[!] Tools:")
14print(json.dumps(tools))
15
16def invoke_llm(task = "What can you do?"):
17 completion = openai.chat.completions.create(
18 model="gpt-4o",
19 messages=[
20 {
21 "role": "user",
22 "content": task, # Your task here!
23 },
24 ],
25 tools=tools,
26 )
27
28 # Handle Result from tool call
29 result = composio.provider.handle_tool_calls(user_id=user_id, response=completion)
30 print(f"[!] Completion: {completion}")
31 print(f"[!] Tool call result: {result}")
32
33invoke_llm()

Tool List

Tool Name: Check IP Reputation

Description

Tool to check the reputation of an ip address. use when you need to determine if an ip address has been reported for abusive activity within a specified look-back period. example: checkip(ipaddress='8.8.8.8', maxageindays=90).

Action Parameters

ipAddress
stringRequired
maxAgeInDays
integerDefaults to 30
verbose
boolean

Action Response

data
objectRequired
error
string
successful
booleanRequired

Tool Name: Get Abuse Reports

Description

Tool to retrieve a list of abuse reports for a specific ip address. use when you need to fetch historic reports with optional filtering by status, date range, reporter, and pagination.

Action Parameters

dateFrom
string
dateTo
string
ipAddress
stringRequired
limit
integer
maxAgeInDays
integer
offset
integer
reporterId
integer
status
string

Action Response

data
arrayRequired
error
string
meta
objectRequired
successful
booleanRequired

Tool Name: Retrieve IP Blacklist

Description

Tool to retrieve a list of the most reported ip addresses. use when building dynamic blocklists or threat intelligence feeds.

Action Parameters

confidenceMinimum
integer
exceptCountries
ipVersion
integer
limit
integer
onlyCountries
plaintext
boolean

Action Response

data
arrayRequired
error
string
meta
objectRequired
successful
booleanRequired

Tool Name: Bulk Report

Description

Tool to submit multiple ip abuse reports in bulk. use when you need to report a large set of ips at once by uploading a csv file with required headers. csv must include columns: ip, categories, reportdate, comment.

Action Parameters

csv
stringRequired

Action Response

data
objectRequired
error
string
successful
booleanRequired

Tool Name: Check Block

Description

Tool to check the reputation of all ip addresses in a cidr range. use when you need aggregated abuse data for a network block.

Action Parameters

maxAgeInDays
integerDefaults to 30
network
stringRequired

Action Response

data
objectRequired
error
string
successful
booleanRequired

Tool Name: Clear Address Reports

Description

Tool to remove all reports associated with a specific ip address. use when you need to purge your own abuse records after verifying control of the ip.

Action Parameters

ipAddress
stringRequired

Action Response

data
objectRequired
error
string
successful
booleanRequired