Palo Alto Networks · OpenAPI Overlay 1.0.0

API Evangelist conversational phrasing for Threat Prevention API

9 actions 9 updates phrasing extends openapi/palo-alto-networks-threat-prevention-api-openapi.yml
Generated by API Evangelist Written by API Evangelist tooling for Palo Alto Networks's API. It is a proposal applied on top of the contract, not a document Palo Alto Networks publishes.
View Overlay File View on GitHub Overlay Specification

What the actions change

x-apievangelist-phrasing

Targets 9

$.info
$.paths['/threats/cve-coverage'].get
$.paths['/release-notes'].get
$.paths['/threats'].get
$.paths['/threats'].post
$.paths['/threats/history'].get
$.paths['/edl'].get
$.paths['/ip-feed'].get
$.paths['/ip-feed'].post

OpenAPI Overlay

Raw ↑
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
  title: API Evangelist conversational phrasing for Threat Prevention API
  version: 1.0.0
extends: openapi/palo-alto-networks-threat-prevention-api-openapi.yml
actions:
- target: $.info
  update:
    x-apievangelist-phrasing:
      method: generated
      generated: '2026-10-01'
      generator: build-phrasing.py
      label: Generated by API Evangelist
      operations: 8
- target: $.paths['/threats/cve-coverage'].get
  update:
    x-apievangelist-phrasing:
      intent: Check threat coverage for a CVE
      effect: read
      questions:
      - Does Palo Alto Networks threat prevention cover a specific CVE?
      - Which signatures protect against a given CVE ID?
      instructions:
      - text: Check coverage for CVE {cve_id}.
        slots:
          cve_id: query.cve_id
      - text: Show which protections exist for {cve_id}.
        slots:
          cve_id: query.cve_id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/release-notes'].get
  update:
    x-apievangelist-phrasing:
      intent: Get content release notes
      effect: read
      questions:
      - What changed in a particular content release version?
      - Are release notes available for content versions older than 8000?
      instructions:
      - text: Get release notes for {type} version {version}.
        slots:
          type: query.type
          version: query.version
      - text: Show the content release notes of type {type} for version {version}.
        slots:
          type: query.type
          version: query.version
      method: generated
      generated: '2026-09-26'
- target: $.paths['/threats'].get
  update:
    x-apievangelist-phrasing:
      intent: Look up threat signatures
      effect: read
      questions:
      - Which Threat Vault signatures cover a given CVE?
      - Can I find signatures linked to a file's SHA-256 hash?
      - What antivirus signatures were released between two dates?
      instructions:
      - text: Find threat signatures for CVE {cve}.
        slots:
          cve: query.cve
      - text: Look up signatures matching hash {sha256}.
        slots:
          sha256: query.sha256
      - text: List {type} signatures released from {fromReleaseDate} to {toReleaseDate}.
        slots:
          type: query.type
          fromReleaseDate: query.fromReleaseDate
          toReleaseDate: query.toReleaseDate
      method: generated
      generated: '2026-10-01'
- target: $.paths['/threats'].post
  update:
    x-apievangelist-phrasing:
      intent: Batch look up threat signatures
      effect: read
      questions:
      - Can I look up up to 100 threat signatures at once by id or hash?
      - What's the batch limit when querying signature metadata by name?
      instructions:
      - text: Batch look up threat signatures with ids {id}.
        slots:
          id: requestBody.id
      - text: Get signature metadata in bulk for sample hashes {sha256}.
        slots:
          sha256: requestBody.sha256
      method: generated
      generated: '2026-09-26'
- target: $.paths['/threats/history'].get
  update:
    x-apievangelist-phrasing:
      intent: Get a signature's release history
      effect: read
      questions:
      - When was a threat signature first released and modified?
      - How far back does antivirus signature release history go?
      instructions:
      - text: Show the release history of signature {id} for package {type}.
        slots:
          id: query.id
          type: query.type
      - text: Get the {type} release history of threat {id} in {order} order.
        slots:
          type: query.type
          id: query.id
          order: query.order
      method: generated
      generated: '2026-09-26'
- target: $.paths['/edl'].get
  update:
    x-apievangelist-phrasing:
      intent: Get predefined external dynamic list content
      effect: read
      questions:
      - What IPs are in a predefined external dynamic list?
      - Is a specific IP address included in a Palo Alto Networks predefined EDL?
      instructions:
      - text: Get the contents of predefined EDL {name}.
        slots:
          name: query.name
      - text: Check whether {ipaddr} is in EDL {name}.
        slots:
          ipaddr: query.ipaddr
          name: query.name
      method: generated
      generated: '2026-09-26'
- target: $.paths['/ip-feed'].get
  update:
    x-apievangelist-phrasing:
      intent: Look up IP feed information
      effect: read
      questions:
      - Which IP feed is an address listed in?
      - Can I search the IP feed for a range of addresses?
      instructions:
      - text: Look up IP feed information for {ipaddr}.
        slots:
          ipaddr: query.ipaddr
      - text: Search the IP feed from {fromipaddr} to {toipaddr}.
        slots:
          fromipaddr: query.fromipaddr
          toipaddr: query.toipaddr
      method: generated
      generated: '2026-09-26'
- target: $.paths['/ip-feed'].post
  update:
    x-apievangelist-phrasing:
      intent: Batch look up IP feed entries
      effect: read
      questions:
      - Can I check up to 100 IP addresses against the IP feed in one request?
      - What is the batch limit for IP feed lookups?
      instructions:
      - text: Batch check IP addresses {ipaddr} against the IP feed.
        slots:
          ipaddr: requestBody.ipaddr
      - text: Look up IP feed entries in bulk for {ipaddr}.
        slots:
          ipaddr: requestBody.ipaddr
      method: generated
      generated: '2026-09-26'