AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified MIT Self-run

Greynoise Api

skill-liberty91ltd-cti-skills-greynoise-api · by Liberty91LTD

GreyNoise API reference. Internet scanner/noise classification for IPs.

— No reviews yet
0 installs
31 views
0.0% view→install

Install

$ agentstack add skill-liberty91ltd-cti-skills-greynoise-api

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • ✓ Prompt-injection patterns
  • ✓ Secret / credential exfiltration
  • ✓ Dangerous shell & filesystem operations
  • ✓ Untrusted network calls
  • ✓ Known-malicious package signatures

What it can access

  • ● Network access Used
  • ✓ Filesystem access No
  • ✓ Shell / process execution No
  • ✓ Environment & secrets No
  • ✓ Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-liberty91ltd-cti-skills-greynoise-api)

Reliability & compatibility

✓ Security review passed
0 installs to date
— no reviews yet
● 2mo ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Greynoise Api? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

GreyNoise API

Base URL

  • Community: https://api.greynoise.io/v3/community
  • Enterprise: https://api.greynoise.io/v3

Authentication

Header: key: $GREYNOISE_API_KEY

Rate Limits

  • Community (free): 50 requests/day
  • Enterprise: Based on plan

Key Endpoints

Community IP Lookup (Free)

curl -s "https://api.greynoise.io/v3/community/{ip}" \
  -H "key: $GREYNOISE_API_KEY"

Response fields:

  • noise — true if IP is a known internet scanner
  • riot — true if IP belongs to a known benign service (CDN, DNS, etc.)
  • classification — benign|malicious|unknown
  • name — actor name if identified
  • last_seen — last observation date
  • message — human-readable summary

Enterprise Context (Paid)

curl -s "https://api.greynoise.io/v3/noise/context/{ip}" \
  -H "key: $GREYNOISE_API_KEY"

Additional fields: tags, cve, os, ports, raw_data

Classification Meaning

| Classification | Meaning | Action | |---------------|---------|--------| | benign + noise:true | Known benign scanner (Shodan, Censys, etc.) | Likely false positive — deprioritise | | malicious + noise:true | Known malicious scanner | Real threat, but opportunistic, not targeted | | unknown + noise:true | Unclassified scanner | Investigate further | | noise:false + riot:false | Not a known scanner | May be targeted — investigate | | riot:true | Known benign service | Definitely deprioritise |

CTI Value

GreyNoise answers: "Is this IP scanning the whole internet, or is it specifically targeting us?"

  • If noise:true → opportunistic, not targeted
  • If noise:false → potentially targeted, higher priority

Response Summary Format

ip: 
noise: 
riot: 
classification: benign|malicious|unknown
name: 
last_seen: 
message: 
verdict: benign-scanner|malicious-scanner|not-scanner|benign-service

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.