编程

IP地址归属、信誉、风控查询

试用

在本地或经确认的外部查询中核查单个已授权公网IP的归属、路由与网络风险信号

它能做什么

核查单个已授权公网 IPv4/IPv6 的归属、路由、信誉与代理/欺诈风控信号,覆盖跨境电商与社媒矩阵、广告与本地 SEO、调研比价、品牌与网站测试、AI 账号、直播和多环境运营;默认本地处理,外部查询需明确确认。

技能文档

IP Intelligence Fusion

Use this skill for a single public IPv4 or IPv6 address that the operator owns, that is publicly documented, or that the operator is explicitly authorized to investigate. The result is a time-stamped evidence report for human review. It is not an identity lookup, an automatic allow/deny decision, a location guarantee, or a platform-review tool.

Mandatory boundaries

  • Accept exactly one public IP. Reject hostnames, private addresses, reserved addresses, batches, customer login logs, account logs, cookies, device identifiers, and device fingerprints.
  • Treat an IP as potentially personal information when it is linked with a person, account, customer, employee, or login record. Do not infer that command-line possession proves authority.
  • Supported work is limited to owned/public/authorized asset checks, public-information verification, authorized security operations, abnormal-request triage, and provider delivery acceptance testing.
  • Do not assist with unauthorized person investigation, bulk personal-IP collection, location spoofing, account farming, bulk registration, platform-review evasion, CAPTCHA or login bypass, access-control bypass, port scanning, exploitation, attacks, or proxy forwarding.
  • Do not log in, submit forms, handle CAPTCHA, defeat rate limits, or use a mirror when reading a provider's public page. Stop when a page requires access beyond ordinary read-only viewing.
  1. Validate that the user supplied one public IP. If no IP is present, ask for it. Do not resolve a hostname on the user's behalf.
  2. Start with local-only processing. The default CLI mode must not call a remote service. It may read a local evidence JSON file and render JSON, Markdown, or HTML.
  3. Before any external query, explain the target IP, providers/domains, fields sent, and that the transfer may cross borders. Ask for explicit confirmation. This is an operational record, not proof of legal authorization.
  4. Only after confirmation use --external. In an interactive terminal the CLI presents a YES prompt. In a non-interactive process pass --confirm-external as well. --self requires both flags; the IP discovery request is made only after confirmation.
  5. Use the default fast profile unless the user explicitly requests --profile comprehensive. Do not silently expand the set of recipients.
  6. If confirmation is absent or refused, produce a local report with not-requested source states where appropriate. Do not turn that state into error, zero risk, or a negative finding.

Examples:

Local-only JSON:
python scripts/ip_intelligence.py 8.8.8.8 --format json

Interactive external lookup:
python scripts/ip_intelligence.py 8.8.8.8 --external --profile fast

Non-interactive external lookup:
python scripts/ip_intelligence.py 8.8.8.8 --external --confirm-external --format json

The removed --include-raw option must not be suggested or accepted.

Provider and evidence rules

The CLI request layer permits only audited HTTPS hosts and rejects credentials in URLs, user information, non-standard ports, and unapproved redirect destinations. The current domains and collection methods are listed in references/providers.md.

IPinfo and AbuseIPDB credentials, when independently configured, are request headers. IPQualityScore, Scamalytics, and ipdata API adapters are disabled; those services can appear only as validated official public-page evidence. The old plaintext IP-API adapter is removed.

Public-page evidence must contain the exact target IP, an official HTTPS source URL, an observation time, and only the allowlisted normalized fields. Do not include raw responses, fn, email, abuse-contact, analysis, or personalized-hostname fields. Use the local evidence import only after the host has actually observed the official page.

Keep these distinctions in every report:

  • success: validated structured evidence was returned;
  • skipped: an enabled provider needs a missing configured credential;
  • not-requested: external collection was disabled, or an API adapter is intentionally disabled;
  • unavailable: an experimental source could not be read or parsed;
  • error: an enabled source failed validation, transport, or upstream processing.

Absence of evidence is not low risk. Numeric risk comes only from upstream numeric scores. Boolean proxy, VPN, Tor, hosting, abuse, and bot signals remain contextual or unscored. Preserve provider identity, consensus, alternatives, conflicts, and timestamps.

Report handling

Generate the requested representation with the CLI. Reports may contain the complete IP, geographic region, organization/ISP, allocation or route prefixes, and network-risk labels. Set restrictive file permissions; do not place reports in public Issues, demo sites, public logs, or uncontrolled shared storage. Delete them under the operator's retention schedule.

The JSON report must include policy metadata and the data_policy declaration. In external mode, record external-confirmed and the provider domains that actually started a request. Reports must not contain upstream raw payloads, contact details, credentials, or API keys. Never call an IP safe based only on this report and never present it as proof of abuse.

Completion brief

Return a concise summary in the user's language containing the normalized target, risk score or unknown, confidence, contributing numeric sources, consensus facts, material conflicts, contextual signals, source-state counts, timestamp, and absolute paths to generated reports. State that the report is an aid for authorized human review, not a legal conclusion or an automatic platform decision.

If a network is unavailable, preserve explicit provider failures and continue with local evidence. If a public page is blocked or changes layout, keep it unavailable and report the gap. Do not invent values or bypass the restriction.

Compliance reminder

External requests may transmit an IP to a service provider outside China. The operator is responsible for checking authorization, notice, lawful basis, personal-information handling, data-export requirements, retention/deletion, and third-party terms. This skill and its MIT license are not legal advice and cannot establish compliance by themselves. Future support for customer or account logs requires a separate personal-information impact assessment and data-export design; it must not be added directly to v2.0.

相关技能

多源核查公网IP归属、信誉与代理风控,覆盖跨境电商与社媒矩阵、广告投放、本地SEO、调研比价、品牌网站测试、AI账号、直播、多环境及代理运维

IPQualityScore (ipqualityscore.com). Use this skill for ANY IPQualityScore request — searching and reading data. Whenever a task involves IPQualityScore, use...

9 次安装

Query the public MyIPChecker IP information API and explain or return the geolocation and network fields it provides. Use when Codex needs to look up metadat...

18 次安装1 星标

IP快速筛查(尽调初筛)工具。面向技术尽调场景,对企业的专利组合进行快速筛查和风险预警。当用户需要快速了解企业的专利布局、专利质量初筛、技术领域分布、专利风险预警,或提到IP尽调、专利尽调、知识产权筛查、技术尽职调查、专利风险评估、专利组合分析等意图时使用此技能。

1 次安装

研发IP全栈加速器——面向全行业研发创新型企业,输入企业名称自动驱动六大IP模块(全部内置,用户只需安装本技能): ①诉讼情报预警、②友商情报监控(完整内置tech-intel-monitor逻辑·Eureka Monitor风格)、③FTO产品防侵权、 ④技术方案探索(5改进+4创新+6白点+工程可靠性)、⑤查新检索(8步严谨分析·PatentBench认证X检出率81%)、 ⑥技术交底书(九章标准格式+3实施例+Word自动下载),形成从IP意识唤醒到高质量专利申请的完整闭环。 无需安装其他技能,一包搞定全部功能。

调查企业诉讼、处罚、制裁、信用及其他公开合作风险信号