diff --git a/apps/docs/content/docs/en/integrations/crowdstrike.mdx b/apps/docs/content/docs/en/integrations/crowdstrike.mdx index 8955937d342..77c0813bb26 100644 --- a/apps/docs/content/docs/en/integrations/crowdstrike.mdx +++ b/apps/docs/content/docs/en/integrations/crowdstrike.mdx @@ -1,6 +1,6 @@ --- title: CrowdStrike -description: Query CrowdStrike Identity Protection sensors and documented aggregates +description: Investigate and respond to CrowdStrike Falcon alerts, hosts, IOCs, and vulnerabilities --- import { BlockInfoCard } from "@/components/ui/block-info-card" @@ -11,29 +11,423 @@ import { BlockInfoCard } from "@/components/ui/block-info-card" /> {/* MANUAL-CONTENT-START:intro */} -[CrowdStrike](https://www.crowdstrike.com/) is a cybersecurity platform providing endpoint protection, threat intelligence, and identity security through its Falcon suite. This integration connects to the Falcon Identity Protection API to query sensor data. +[CrowdStrike](https://www.crowdstrike.com/) is a cybersecurity platform providing endpoint protection, threat intelligence, and identity security through its Falcon suite. This integration authenticates with a Falcon API client ID and secret against a chosen cloud region and covers the Alerts, Hosts, Host Groups, IOC Management, Spotlight, Real Time Response, Case Management, and Identity Protection APIs. With this integration, you can: -- **Search sensors**: Query CrowdStrike identity protection sensors by hostname, IP, or related fields using Falcon Query Language filters -- **Fetch sensor details**: Retrieve documented sensor details, including protection status, policy assignments, and protocol configuration, for one or more device IDs -- **Run sensor aggregates**: Execute documented JSON aggregate queries to summarize sensor data into buckets and metrics +- **Triage alerts**: Search Falcon alerts with Falcon Query Language, pull full alert records by composite ID, and update status, assignment, tags, comments, and console visibility +- **Respond on hosts**: Contain or lift containment on a host, and hide or unhide it from the Falcon console +- **Manage host groups**: Search groups, read group details, and add or remove hosts from static groups +- **Manage custom indicators**: Search, read, create, update, and delete indicators of compromise +- **Review vulnerabilities**: Query Spotlight vulnerabilities and read CVE, host, application, and remediation details +- **Run read-only Real Time Response**: Open a session, run a documented read-only command, poll for output, and close the session +- **Read cases**: Search Case Management cases and read case details +- **Query identity sensors**: Search Identity Protection sensors, fetch sensor details, and run aggregate queries -In Sim, the CrowdStrike integration allows your agents to search identity protection sensors, look up detailed sensor records by device ID, and run aggregate queries against sensor data—all authenticated with a Falcon API client ID and secret against a specified cloud region. This lets agents surface device protection status, policy coverage, and protocol configuration (Kerberos, LDAP, NTLM, RDP, SMB) as part of security monitoring and reporting workflows. +Each operation maps to a specific Falcon API scope — for example `Alerts: Read` and `Alerts: Write`, `Hosts: Write` for containment, `Host groups: Read`/`Write`, `IOC Management: Read`/`Write`, `Vulnerabilities: Read`, `Real time response: Read`, and `Cases: Read`. Containment and indicator deletion change live protection behavior, so scope the credential to only the operations your workflows need. + +Note that CrowdStrike decommissioned the legacy Detects API (September 30, 2025) and the CrowdScore Incidents API (March 9, 2026). This integration uses the current Alerts API and Case Management API in their place. {/* MANUAL-CONTENT-END */} ## Usage Instructions -Integrate CrowdStrike Identity Protection into workflows to search sensors, fetch documented sensor details by device ID, and run documented sensor aggregate queries. +Integrate CrowdStrike Falcon into workflows to triage alerts, contain hosts, manage host groups and custom indicators of compromise, review Spotlight vulnerabilities, run read-only Real Time Response commands, read Case Management cases, and query Identity Protection sensors. ## Actions +### CrowdStrike Create Indicators + +Create custom CrowdStrike Falcon indicators of compromise (POST /iocs/entities/indicators/v1). Each indicator can allow, detect, or block activity across the fleet, so a wrong value can suppress detections or break legitimate software. Requires the "IOC Management: Write" API scope. + +#### Input + +| Parameter | Type | Required | Description | +| --------- | ---- | -------- | ----------- | +| `clientId` | string | Yes | CrowdStrike Falcon API client ID | +| `clientSecret` | string | Yes | CrowdStrike Falcon API client secret | +| `cloud` | string | Yes | CrowdStrike Falcon cloud region | +| `indicators` | json | Yes | JSON array of indicators to create. Each entry requires type, value, and applied_globally \(boolean\). type is one of sha256, md5, domain, ipv4, ipv6; action is one of no_action, allow, prevent_no_ui, prevent, detect; severity is one of informational, low, medium, high, critical; platforms entries are windows, mac, or linux. Other documented fields: host_groups \(array\), description, source, tags \(array\), expiration \(ISO 8601\), mobile_action, metadata \(\{ filename \}\). Either applied_globally must be true or host_groups must be supplied. Tenants can extend these value sets, so treat them as the documented defaults rather than a closed list. | +| `comment` | string | No | Audit comment explaining why these indicators were created | +| `retrodetects` | boolean | No | Whether to generate retroactive detections for the new indicators | +| `ignoreWarnings` | boolean | No | Whether to create the indicators even when CrowdStrike returns warnings | + +#### Output + +| Parameter | Type | Description | +| --------- | ---- | ----------- | +| `indicators` | array | Created CrowdStrike indicator records | +| ↳ `id` | string | Indicator identifier | +| ↳ `type` | string | Indicator type | +| ↳ `value` | string | Indicator value | +| ↳ `action` | string | Action taken when the indicator matches | +| ↳ `mobileAction` | string | Action taken on mobile platforms when the indicator matches | +| ↳ `severity` | string | Indicator severity | +| ↳ `description` | string | Indicator description | +| ↳ `source` | string | Indicator source | +| ↳ `appliedGlobally` | boolean | Whether the indicator applies to all hosts | +| ↳ `platforms` | array | Platforms the indicator applies to | +| ↳ `hostGroups` | array | Host group IDs the indicator is scoped to | +| ↳ `tags` | array | Tags applied to the indicator | +| ↳ `expiration` | string | Indicator expiration timestamp | +| ↳ `expired` | boolean | Whether the indicator has expired | +| ↳ `deleted` | boolean | Whether the indicator is deleted | +| ↳ `fromParent` | boolean | Whether the indicator was inherited from a parent CID | +| ↳ `parentCidName` | string | Parent CID name | +| ↳ `createdBy` | string | User who created the indicator | +| ↳ `createdOn` | string | Indicator creation timestamp | +| ↳ `modifiedBy` | string | User who last modified the indicator | +| ↳ `modifiedOn` | string | Indicator modification timestamp | +| ↳ `metadata` | json | File metadata CrowdStrike resolved for the indicator | +| ↳ `avHits` | number | Antivirus hit count | +| ↳ `companyName` | string | Company name | +| ↳ `fileDescription` | string | File description | +| ↳ `fileVersion` | string | File version | +| ↳ `filename` | string | File name | +| ↳ `originalFilename` | string | Original file name | +| ↳ `productName` | string | Product name | +| ↳ `productVersion` | string | Product version | +| ↳ `signed` | boolean | Whether the file is signed | +| `count` | number | Number of indicators created | +| `errors` | array | Errors CrowdStrike returned alongside a partially successful response | +| ↳ `code` | number | CrowdStrike error code | +| ↳ `id` | string | Identifier the error applies to | +| ↳ `message` | string | Error message | + +### CrowdStrike Delete Indicators + +Permanently delete custom CrowdStrike Falcon indicators of compromise (DELETE /iocs/entities/indicators/v1). Cannot be undone; deleting a blocking indicator removes that protection from every host, and a broad filter can delete far more than intended. Supply an ID list or a filter, never both -- CrowdStrike lets a filter silently override the IDs, so this tool rejects that instead. Requires the "IOC Management: Write" API scope. + +#### Input + +| Parameter | Type | Required | Description | +| --------- | ---- | -------- | ----------- | +| `clientId` | string | Yes | CrowdStrike Falcon API client ID | +| `clientSecret` | string | Yes | CrowdStrike Falcon API client secret | +| `cloud` | string | Yes | CrowdStrike Falcon cloud region | +| `indicatorIds` | json | No | JSON array of CrowdStrike IOC IDs to delete. Cannot be combined with a filter. | +| `filter` | string | No | Falcon Query Language filter selecting indicators to delete in bulk. Cannot be combined with an ID list. | +| `comment` | string | No | Audit comment explaining why these indicators were deleted | + +#### Output + +| Parameter | Type | Description | +| --------- | ---- | ----------- | +| `deletedIds` | array | IOC IDs CrowdStrike deleted | +| `count` | number | Number of indicators deleted | +| `errors` | array | Errors CrowdStrike returned alongside a partially successful response | +| ↳ `code` | number | CrowdStrike error code | +| ↳ `id` | string | Identifier the error applies to | +| ↳ `message` | string | Error message | + +### CrowdStrike Delete RTR Session + +Close an open CrowdStrike Falcon Real Time Response session (DELETE /real-time-response/entities/sessions/v1). Requires the "Real time response: Read" API scope. + +#### Input + +| Parameter | Type | Required | Description | +| --------- | ---- | -------- | ----------- | +| `clientId` | string | Yes | CrowdStrike Falcon API client ID | +| `clientSecret` | string | Yes | CrowdStrike Falcon API client secret | +| `cloud` | string | Yes | CrowdStrike Falcon cloud region | +| `sessionId` | string | Yes | RTR session ID to close | + +#### Output + +| Parameter | Type | Description | +| --------- | ---- | ----------- | +| `sessionId` | string | RTR session ID that was closed | +| `deleted` | boolean | Whether CrowdStrike accepted the session deletion | +| `errors` | array | Errors CrowdStrike returned alongside a partially successful response | +| ↳ `code` | number | CrowdStrike error code | +| ↳ `id` | string | Identifier the error applies to | +| ↳ `message` | string | Error message | + +### CrowdStrike Execute RTR Command + +Run a read-only Real Time Response command in an open CrowdStrike Falcon session (POST /real-time-response/entities/command/v1). baseCommand names the family only (cat, cd, clear, csrutil, env, eventlog, filehash, getsid, help, history, ipconfig, ls, mount, netstat, ps, reg); subcommands go in commandString. Host-modifying commands need the Active Responder or Admin endpoints. Requires the "Real time response: Read" API scope. + +#### Input + +| Parameter | Type | Required | Description | +| --------- | ---- | -------- | ----------- | +| `clientId` | string | Yes | CrowdStrike Falcon API client ID | +| `clientSecret` | string | Yes | CrowdStrike Falcon API client secret | +| `cloud` | string | Yes | CrowdStrike Falcon cloud region | +| `sessionId` | string | Yes | RTR session ID returned by Init RTR Session | +| `baseCommand` | string | Yes | Read-only RTR base command family, one of: cat, cd, clear, csrutil, env, eventlog, filehash, getsid, help, history, ipconfig, ls, mount, netstat, ps, reg. Subcommands belong in commandString, not here. | +| `commandString` | string | Yes | Full command line to run, such as "ls C:\\Windows" or "reg query HKLM\\Software" | + +#### Output + +| Parameter | Type | Description | +| --------- | ---- | ----------- | +| `cloudRequestId` | string | Cloud request ID to poll for command output | +| `sessionId` | string | RTR session the command ran in | +| `queuedCommandOffline` | boolean | Whether the command was queued for an offline host | +| `errors` | array | Errors CrowdStrike returned alongside a partially successful response | +| ↳ `code` | number | CrowdStrike error code | +| ↳ `id` | string | Identifier the error applies to | +| ↳ `message` | string | Error message | + +### CrowdStrike Get Alert Details + +Get full CrowdStrike Falcon alert records for one or more composite alert IDs (POST /alerts/entities/alerts/v2). Requires the "Alerts: Read" API scope. + +#### Input + +| Parameter | Type | Required | Description | +| --------- | ---- | -------- | ----------- | +| `clientId` | string | Yes | CrowdStrike Falcon API client ID | +| `clientSecret` | string | Yes | CrowdStrike Falcon API client secret | +| `cloud` | string | Yes | CrowdStrike Falcon cloud region | +| `compositeIds` | json | Yes | JSON array of CrowdStrike composite alert IDs | +| `includeHidden` | boolean | No | Include previously hidden alerts \(CrowdStrike defaults this to true\) | + +#### Output + +| Parameter | Type | Description | +| --------- | ---- | ----------- | +| `alerts` | array | CrowdStrike alert records | +| ↳ `compositeId` | string | Composite alert ID | +| ↳ `id` | string | Alert ID | +| ↳ `cid` | string | CrowdStrike customer identifier | +| ↳ `aggregateId` | string | Aggregate identifier | +| ↳ `agentId` | string | Agent \(sensor\) identifier | +| ↳ `deviceId` | string | Device identifier from the alert device | +| ↳ `hostname` | string | Hostname from the alert device | +| ↳ `name` | string | Alert name | +| ↳ `displayName` | string | Alert display name | +| ↳ `description` | string | Alert description | +| ↳ `type` | string | Alert type | +| ↳ `product` | string | Falcon product that raised the alert | +| ↳ `platform` | string | Platform the alert was raised on | +| ↳ `severity` | number | Numeric severity | +| ↳ `severityName` | string | Severity name | +| ↳ `confidence` | number | Confidence score | +| ↳ `status` | string | Alert status | +| ↳ `assignedToName` | string | Assignee display name | +| ↳ `assignedToUid` | string | Assignee user ID | +| ↳ `assignedToUuid` | string | Assignee user UUID | +| ↳ `tactic` | string | MITRE ATT&CK tactic | +| ↳ `tacticId` | string | MITRE ATT&CK tactic ID | +| ↳ `technique` | string | MITRE ATT&CK technique | +| ↳ `techniqueId` | string | MITRE ATT&CK technique ID | +| ↳ `scenario` | string | Alert scenario | +| ↳ `objective` | string | Adversary objective | +| ↳ `resolution` | string | Alert resolution | +| ↳ `showInUi` | boolean | Whether the alert is shown in Falcon | +| ↳ `tags` | array | Tags applied to the alert | +| ↳ `filename` | string | Triggering file name | +| ↳ `filepath` | string | Triggering file path | +| ↳ `cmdline` | string | Triggering command line | +| ↳ `sha256` | string | SHA256 of the triggering file | +| ↳ `sha1` | string | SHA1 of the triggering file | +| ↳ `md5` | string | MD5 of the triggering file | +| ↳ `userName` | string | User name associated with the alert | +| ↳ `userId` | string | User ID associated with the alert | +| ↳ `patternId` | number | Detection pattern ID | +| ↳ `falconHostLink` | string | Deep link into the Falcon console | +| ↳ `controlGraphId` | string | Control graph identifier | +| ↳ `external` | boolean | Whether the alert is external | +| ↳ `emailSent` | boolean | Whether a notification email was sent | +| ↳ `isAggregated` | boolean | Whether the alert is aggregated | +| ↳ `isFalconPlatformIoa` | boolean | Whether the alert is a Falcon platform IOA | +| ↳ `dataDomains` | array | Data domains the alert belongs to | +| ↳ `iocValues` | array | Indicator values associated with the alert | +| ↳ `linkedCaseIds` | array | Case IDs linked to the alert | +| ↳ `linkedBehavioralDetections` | array | Behavioral detection IDs linked to the alert | +| ↳ `timestamp` | string | Alert timestamp | +| ↳ `createdTimestamp` | string | Alert creation timestamp | +| ↳ `updatedTimestamp` | string | Alert update timestamp | +| ↳ `crawledTimestamp` | string | Alert crawl timestamp | +| ↳ `contextTimestamp` | string | Alert context timestamp | +| `count` | number | Number of alerts returned | +| `errors` | array | Errors CrowdStrike returned alongside a partially successful response | +| ↳ `code` | number | CrowdStrike error code | +| ↳ `id` | string | Identifier the error applies to | +| ↳ `message` | string | Error message | + +### CrowdStrike Get Case Details + +Get CrowdStrike Falcon Case Management case records for one or more case IDs (POST /cases/entities/cases/v2). Requires the "Cases: Read" API scope. + +#### Input + +| Parameter | Type | Required | Description | +| --------- | ---- | -------- | ----------- | +| `clientId` | string | Yes | CrowdStrike Falcon API client ID | +| `clientSecret` | string | Yes | CrowdStrike Falcon API client secret | +| `cloud` | string | Yes | CrowdStrike Falcon cloud region | +| `caseIds` | json | Yes | JSON array of CrowdStrike case IDs | + +#### Output + +| Parameter | Type | Description | +| --------- | ---- | ----------- | +| `cases` | array | CrowdStrike Case Management case records | +| ↳ `id` | string | Case identifier | +| ↳ `cid` | string | CrowdStrike customer identifier | +| ↳ `name` | string | Case name | +| ↳ `description` | string | Case description | +| ↳ `descriptionFormat` | string | Format of the case description | +| ↳ `status` | string | Case status | +| ↳ `severity` | number | Numeric case severity | +| ↳ `severityLevel` | string | Case severity level name | +| ↳ `referenceId` | string | Human-readable case reference ID | +| ↳ `version` | number | Case version for optimistic concurrency | +| ↳ `tags` | array | Tags applied to the case | +| ↳ `assignedTo` | json | Falcon user the case is assigned to | +| ↳ `uuid` | string | Falcon user UUID | +| ↳ `email` | string | Falcon user email | +| ↳ `fullName` | string | Falcon user full name | +| ↳ `createdBy` | json | Falcon user who created the case | +| ↳ `uuid` | string | Falcon user UUID | +| ↳ `email` | string | Falcon user email | +| ↳ `fullName` | string | Falcon user full name | +| ↳ `lastUpdatedBy` | json | Falcon user who last updated the case | +| ↳ `uuid` | string | Falcon user UUID | +| ↳ `email` | string | Falcon user email | +| ↳ `fullName` | string | Falcon user full name | +| ↳ `createdTimestamp` | string | Case creation timestamp | +| ↳ `updatedTimestamp` | string | Case update timestamp | +| ↳ `startTimestamp` | string | Case start timestamp | +| ↳ `endTimestamp` | string | Case end timestamp | +| ↳ `templateId` | string | Case template identifier | +| ↳ `templateName` | string | Case template name | +| ↳ `slaId` | string | SLA identifier applied to the case | +| ↳ `slaName` | string | SLA name applied to the case | +| ↳ `isReadOnly` | boolean | Whether the case is read only | +| `count` | number | Number of cases returned | +| `errors` | array | Errors CrowdStrike returned alongside a partially successful response | +| ↳ `code` | number | CrowdStrike error code | +| ↳ `id` | string | Identifier the error applies to | +| ↳ `message` | string | Error message | + +### CrowdStrike Get Host Group Details + +Get CrowdStrike Falcon host group records for one or more group IDs (GET /devices/entities/host-groups/v1). Requires the "Host groups: Read" API scope. + +#### Input + +| Parameter | Type | Required | Description | +| --------- | ---- | -------- | ----------- | +| `clientId` | string | Yes | CrowdStrike Falcon API client ID | +| `clientSecret` | string | Yes | CrowdStrike Falcon API client secret | +| `cloud` | string | Yes | CrowdStrike Falcon cloud region | +| `hostGroupIds` | json | Yes | JSON array of CrowdStrike host group IDs | + +#### Output + +| Parameter | Type | Description | +| --------- | ---- | ----------- | +| `hostGroups` | array | CrowdStrike host group records | +| ↳ `id` | string | Host group identifier | +| ↳ `name` | string | Host group name | +| ↳ `description` | string | Host group description | +| ↳ `groupType` | string | Group type \(static, dynamic, staticByID\) | +| ↳ `assignmentRule` | string | FQL assignment rule for dynamic groups | +| ↳ `createdBy` | string | User who created the group | +| ↳ `createdTimestamp` | string | Group creation timestamp | +| ↳ `modifiedBy` | string | User who last modified the group | +| ↳ `modifiedTimestamp` | string | Group modification timestamp | +| `count` | number | Number of host groups returned | +| `errors` | array | Errors CrowdStrike returned alongside a partially successful response | +| ↳ `code` | number | CrowdStrike error code | +| ↳ `id` | string | Identifier the error applies to | +| ↳ `message` | string | Error message | + +### CrowdStrike Get Indicator Details + +Get custom CrowdStrike Falcon indicator of compromise (IOC) records for one or more IOC IDs (GET /iocs/entities/indicators/v1). Requires the "IOC Management: Read" API scope. + +#### Input + +| Parameter | Type | Required | Description | +| --------- | ---- | -------- | ----------- | +| `clientId` | string | Yes | CrowdStrike Falcon API client ID | +| `clientSecret` | string | Yes | CrowdStrike Falcon API client secret | +| `cloud` | string | Yes | CrowdStrike Falcon cloud region | +| `indicatorIds` | json | Yes | JSON array of CrowdStrike IOC IDs | + +#### Output + +| Parameter | Type | Description | +| --------- | ---- | ----------- | +| `indicators` | array | CrowdStrike indicator of compromise records | +| ↳ `id` | string | Indicator identifier | +| ↳ `type` | string | Indicator type | +| ↳ `value` | string | Indicator value | +| ↳ `action` | string | Action taken when the indicator matches | +| ↳ `mobileAction` | string | Action taken on mobile platforms when the indicator matches | +| ↳ `severity` | string | Indicator severity | +| ↳ `description` | string | Indicator description | +| ↳ `source` | string | Indicator source | +| ↳ `appliedGlobally` | boolean | Whether the indicator applies to all hosts | +| ↳ `platforms` | array | Platforms the indicator applies to | +| ↳ `hostGroups` | array | Host group IDs the indicator is scoped to | +| ↳ `tags` | array | Tags applied to the indicator | +| ↳ `expiration` | string | Indicator expiration timestamp | +| ↳ `expired` | boolean | Whether the indicator has expired | +| ↳ `deleted` | boolean | Whether the indicator is deleted | +| ↳ `fromParent` | boolean | Whether the indicator was inherited from a parent CID | +| ↳ `parentCidName` | string | Parent CID name | +| ↳ `createdBy` | string | User who created the indicator | +| ↳ `createdOn` | string | Indicator creation timestamp | +| ↳ `modifiedBy` | string | User who last modified the indicator | +| ↳ `modifiedOn` | string | Indicator modification timestamp | +| ↳ `metadata` | json | File metadata CrowdStrike resolved for the indicator | +| ↳ `avHits` | number | Antivirus hit count | +| ↳ `companyName` | string | Company name | +| ↳ `fileDescription` | string | File description | +| ↳ `fileVersion` | string | File version | +| ↳ `filename` | string | File name | +| ↳ `originalFilename` | string | Original file name | +| ↳ `productName` | string | Product name | +| ↳ `productVersion` | string | Product version | +| ↳ `signed` | boolean | Whether the file is signed | +| `count` | number | Number of indicators returned | +| `errors` | array | Errors CrowdStrike returned alongside a partially successful response | +| ↳ `code` | number | CrowdStrike error code | +| ↳ `id` | string | Identifier the error applies to | +| ↳ `message` | string | Error message | + +### CrowdStrike Get RTR Command Status + +Get the status and output of a Real Time Response command by cloud request ID (GET /real-time-response/entities/command/v1). Long output is chunked across sequences, so increment the sequence ID to read the next chunk. Requires the "Real time response: Read" API scope. + +#### Input + +| Parameter | Type | Required | Description | +| --------- | ---- | -------- | ----------- | +| `clientId` | string | Yes | CrowdStrike Falcon API client ID | +| `clientSecret` | string | Yes | CrowdStrike Falcon API client secret | +| `cloud` | string | Yes | CrowdStrike Falcon cloud region | +| `cloudRequestId` | string | Yes | Cloud request ID returned by Execute RTR Command | +| `sequenceId` | number | No | Output chunk to retrieve, starting at 0 | + +#### Output + +| Parameter | Type | Description | +| --------- | ---- | ----------- | +| `complete` | boolean | Whether the command has finished running | +| `stdout` | string | Standard output from the command | +| `stderr` | string | Standard error from the command | +| `baseCommand` | string | Base command that was run | +| `sessionId` | string | RTR session the command ran in | +| `taskId` | string | Task identifier for the command | +| `sequenceId` | number | Output chunk sequence this response covers | +| `errors` | array | Errors CrowdStrike returned alongside a partially successful response | +| ↳ `code` | number | CrowdStrike error code | +| ↳ `id` | string | Identifier the error applies to | +| ↳ `message` | string | Error message | + ### CrowdStrike Get Sensor Aggregates -Get documented CrowdStrike Identity Protection sensor aggregates from a JSON aggregate query body +Aggregate CrowdStrike Identity Protection sensors from a JSON aggregate query body (POST /identity-protection/aggregates/devices/GET/v1). These are the domain controllers Falcon Identity Protection monitors, not Falcon endpoint sensors. Requires the "Identity Protection Entities: Read" API scope. #### Input @@ -56,7 +450,7 @@ Get documented CrowdStrike Identity Protection sensor aggregates from a JSON agg | ↳ `label` | json | Bucket label object | | ↳ `stringFrom` | string | String lower bound | | ↳ `stringTo` | string | String upper bound | -| ↳ `subAggregates` | json | Nested aggregate results for this bucket | +| ↳ `subAggregates` | array | Nested aggregate results for this bucket | | ↳ `to` | number | Bucket upper bound | | ↳ `value` | number | Bucket metric value | | ↳ `valueAsString` | string | String representation of the bucket value | @@ -64,10 +458,14 @@ Get documented CrowdStrike Identity Protection sensor aggregates from a JSON agg | ↳ `name` | string | Aggregate result name | | ↳ `sumOtherDocCount` | number | Document count not included in the returned buckets | | `count` | number | Number of aggregate result groups returned | +| `errors` | array | Errors CrowdStrike returned alongside a partially successful response | +| ↳ `code` | number | CrowdStrike error code | +| ↳ `id` | string | Identifier the error applies to | +| ↳ `message` | string | Error message | ### CrowdStrike Get Sensor Details -Get documented CrowdStrike Identity Protection sensor details for one or more device IDs +Get CrowdStrike Identity Protection sensor details for one or more device IDs (POST /identity-protection/entities/devices/GET/v1). These are the domain controllers Falcon Identity Protection monitors, not Falcon endpoint sensors. Requires the "Identity Protection Entities: Read" API scope. #### Input @@ -103,14 +501,295 @@ Get documented CrowdStrike Identity Protection sensor details for one or more de | ↳ `statusCauses` | array | Documented causes behind the current status | | ↳ `tiEnabled` | string | Threat intelligence enablement status | | `count` | number | Number of sensors returned | -| `pagination` | json | Pagination metadata when returned by the underlying API | +| `errors` | array | Errors CrowdStrike returned alongside a partially successful response | +| ↳ `code` | number | CrowdStrike error code | +| ↳ `id` | string | Identifier the error applies to | +| ↳ `message` | string | Error message | + +### CrowdStrike Get Vulnerability Details + +Get CrowdStrike Falcon Spotlight vulnerability records for one or more vulnerability IDs, including CVE, affected host, application, and remediation details (GET /spotlight/entities/vulnerabilities/v2). Requires the spotlight-vulnerabilities:read API scope, shown as "Vulnerabilities: Read" in the Falcon API client UI. + +#### Input + +| Parameter | Type | Required | Description | +| --------- | ---- | -------- | ----------- | +| `clientId` | string | Yes | CrowdStrike Falcon API client ID | +| `clientSecret` | string | Yes | CrowdStrike Falcon API client secret | +| `cloud` | string | Yes | CrowdStrike Falcon cloud region | +| `vulnerabilityIds` | json | Yes | JSON array of Spotlight vulnerability IDs \(maximum 400 per request\) | + +#### Output + +| Parameter | Type | Description | +| --------- | ---- | ----------- | +| `vulnerabilities` | array | CrowdStrike Spotlight vulnerability records | +| ↳ `id` | string | Vulnerability identifier | +| ↳ `aid` | string | Agent identifier of the affected host | +| ↳ `cid` | string | CrowdStrike customer identifier | +| ↳ `status` | string | Vulnerability status \(open, closed, reopen\) | +| ↳ `confidence` | string | Detection confidence | +| ↳ `vulnerabilityId` | string | Underlying vulnerability ID | +| ↳ `createdTimestamp` | string | Creation timestamp | +| ↳ `updatedTimestamp` | string | Last update timestamp | +| ↳ `closedTimestamp` | string | Closure timestamp | +| ↳ `cve` | json | CVE details for the vulnerability | +| ↳ `id` | string | CVE identifier | +| ↳ `baseScore` | number | CVSS base score | +| ↳ `severity` | string | CVE severity | +| ↳ `exprtRating` | string | CrowdStrike ExPRT rating | +| ↳ `exploitStatus` | number | Exploit status code | +| ↳ `exploitabilityScore` | number | CVSS exploitability score | +| ↳ `impactScore` | number | CVSS impact score | +| ↳ `remediationLevel` | string | CVSS remediation level | +| ↳ `description` | string | CVE description | +| ↳ `publishedDate` | string | CVE publication date | +| ↳ `vector` | string | CVSS vector string | +| ↳ `types` | array | CVE types | +| ↳ `isCisaKev` | boolean | Whether the CVE is in the CISA Known Exploited Vulnerabilities catalog | +| ↳ `cisaDueDate` | string | CISA remediation due date | +| ↳ `app` | json | Affected application | +| ↳ `productNameNormalized` | string | Normalized product name | +| ↳ `productNameVersion` | string | Product name and version | +| ↳ `vendorNormalized` | string | Normalized vendor name | +| ↳ `hostInfo` | json | Affected host details | +| ↳ `hostname` | string | Host name | +| ↳ `localIp` | string | Local IP address | +| ↳ `machineDomain` | string | Machine domain | +| ↳ `osVersion` | string | Operating system version | +| ↳ `platform` | string | Platform name | +| ↳ `productTypeDesc` | string | Product type description | +| ↳ `assetCriticality` | string | Asset criticality | +| ↳ `internetExposure` | string | Internet exposure | +| ↳ `tags` | array | Host tags | +| ↳ `groups` | array | Host group names the host belongs to | +| ↳ `remediationIds` | array | Remediation IDs for the vulnerability | +| ↳ `remediations` | array | Remediation entities for the vulnerability | +| ↳ `id` | string | Remediation identifier | +| ↳ `title` | string | Remediation title | +| ↳ `action` | string | Remediation action | +| ↳ `type` | string | Remediation type | +| ↳ `link` | string | Remediation link | +| ↳ `reference` | string | Remediation reference | +| ↳ `vendorUrl` | string | Vendor advisory URL | +| ↳ `suppressionInfo` | json | Suppression state for the vulnerability | +| ↳ `isSuppressed` | boolean | Whether the finding is suppressed | +| ↳ `reason` | string | Suppression reason | +| `count` | number | Number of vulnerabilities returned | +| `errors` | array | Errors CrowdStrike returned alongside a partially successful response | +| ↳ `code` | number | CrowdStrike error code | +| ↳ `id` | string | Identifier the error applies to | +| ↳ `message` | string | Error message | + +### CrowdStrike Init RTR Session + +Open a CrowdStrike Falcon Real Time Response session against a host so read-only commands can be run on it (POST /real-time-response/entities/sessions/v1). This connects a live remote shell to the endpoint. Requires the "Real time response: Read" API scope. + +#### Input + +| Parameter | Type | Required | Description | +| --------- | ---- | -------- | ----------- | +| `clientId` | string | Yes | CrowdStrike Falcon API client ID | +| `clientSecret` | string | Yes | CrowdStrike Falcon API client secret | +| `cloud` | string | Yes | CrowdStrike Falcon cloud region | +| `deviceId` | string | Yes | CrowdStrike host agent ID \(AID\) to open the session against | +| `queueOffline` | boolean | No | Queue the session so it runs when an offline host comes back online | +| `origin` | string | No | Optional session origin string recorded by CrowdStrike | + +#### Output + +| Parameter | Type | Description | +| --------- | ---- | ----------- | +| `sessionId` | string | RTR session ID to use for subsequent commands | +| `deviceId` | string | Host agent ID for the session | +| `platform` | string | Platform of the connected host | +| `pwd` | string | Working directory the session started in | +| `offlineQueued` | boolean | Whether the session was queued for an offline host | +| `existingAidSessions` | number | Number of sessions already open against this host | +| `createdAt` | string | Session creation timestamp | +| `errors` | array | Errors CrowdStrike returned alongside a partially successful response | +| ↳ `code` | number | CrowdStrike error code | +| ↳ `id` | string | Identifier the error applies to | +| ↳ `message` | string | Error message | + +### CrowdStrike Perform Host Action + +Act on CrowdStrike Falcon hosts (POST /devices/entities/devices-actions/v2). Actions: contain, lift_containment, hide_host, unhide_host, detection_suppress, detection_unsuppress. contain network-isolates the host so it can only reach the Falcon cloud; hide_host removes the host record from the console. Both are immediately disruptive. Up to 100 host IDs per call. Requires the "Hosts: Write" API scope. + +#### Input + +| Parameter | Type | Required | Description | +| --------- | ---- | -------- | ----------- | +| `clientId` | string | Yes | CrowdStrike Falcon API client ID | +| `clientSecret` | string | Yes | CrowdStrike Falcon API client secret | +| `cloud` | string | Yes | CrowdStrike Falcon cloud region | +| `actionName` | string | Yes | Action to take: contain, lift_containment, hide_host, unhide_host, detection_suppress, or detection_unsuppress. "contain" network-isolates the host; "hide_host" removes it from the Falcon console. | +| `deviceIds` | json | Yes | JSON array of up to 100 CrowdStrike host agent IDs \(AIDs\) to act on | + +#### Output + +| Parameter | Type | Description | +| --------- | ---- | ----------- | +| `affected` | array | Entities affected by the action | +| ↳ `id` | string | Affected entity identifier | +| ↳ `path` | string | API path of the affected entity | +| `count` | number | Number of hosts the action was applied to | +| `errors` | array | Errors CrowdStrike returned alongside a partially successful response | +| ↳ `code` | number | CrowdStrike error code | +| ↳ `id` | string | Identifier the error applies to | +| ↳ `message` | string | Error message | + +### CrowdStrike Perform Host Group Action + +Add hosts to or remove hosts from a CrowdStrike Falcon static host group (POST /devices/entities/host-group-actions/v1). Group membership drives policy assignment, so changing it changes which policies apply to those hosts. Requires the "Host groups: Write" API scope. + +#### Input + +| Parameter | Type | Required | Description | +| --------- | ---- | -------- | ----------- | +| `clientId` | string | Yes | CrowdStrike Falcon API client ID | +| `clientSecret` | string | Yes | CrowdStrike Falcon API client secret | +| `cloud` | string | Yes | CrowdStrike Falcon cloud region | +| `actionName` | string | Yes | Action to take: add-hosts or remove-hosts | +| `hostGroupId` | string | Yes | CrowdStrike host group ID to modify \(static groups only\) | +| `deviceIds` | json | Yes | JSON array of CrowdStrike host agent IDs \(AIDs\) to add to or remove from the group | + +#### Output + +| Parameter | Type | Description | +| --------- | ---- | ----------- | +| `hostGroups` | array | Host group records returned after the action | +| ↳ `id` | string | Host group identifier | +| ↳ `name` | string | Host group name | +| ↳ `description` | string | Host group description | +| ↳ `groupType` | string | Group type \(static, dynamic, staticByID\) | +| ↳ `assignmentRule` | string | FQL assignment rule for dynamic groups | +| ↳ `createdBy` | string | User who created the group | +| ↳ `createdTimestamp` | string | Group creation timestamp | +| ↳ `modifiedBy` | string | User who last modified the group | +| ↳ `modifiedTimestamp` | string | Group modification timestamp | +| `count` | number | Number of host group records returned | +| `errors` | array | Errors CrowdStrike returned alongside a partially successful response | +| ↳ `code` | number | CrowdStrike error code | +| ↳ `id` | string | Identifier the error applies to | +| ↳ `message` | string | Error message | + +### CrowdStrike Query Alerts + +Search CrowdStrike Falcon alerts with a Falcon Query Language filter and return their composite IDs. Uses the current Alerts API (GET /alerts/queries/alerts/v2), which supersedes the deprecated Detects API. Requires the "Alerts: Read" API scope. + +#### Input + +| Parameter | Type | Required | Description | +| --------- | ---- | -------- | ----------- | +| `clientId` | string | Yes | CrowdStrike Falcon API client ID | +| `clientSecret` | string | Yes | CrowdStrike Falcon API client secret | +| `cloud` | string | Yes | CrowdStrike Falcon cloud region | +| `filter` | string | No | Falcon Query Language filter over alert fields | +| `q` | string | No | Free-text search across all alert metadata | +| `limit` | number | No | Maximum number of alert IDs to return \(max 10000\) | +| `offset` | number | No | Pagination offset for the alert query | +| `sort` | string | No | Sort expression such as "created_timestamp\|desc" | +| `includeHidden` | boolean | No | Include previously hidden alerts \(CrowdStrike defaults this to true\) | + +#### Output + +| Parameter | Type | Description | +| --------- | ---- | ----------- | +| `alertIds` | array | Composite alert IDs matching the query, ready for Get Alert Details | +| `count` | number | Number of alert IDs returned | +| `pagination` | json | Pagination metadata \(limit, offset, total\) | +| ↳ `limit` | number | Page size used for the query | +| ↳ `offset` | number | Offset returned by CrowdStrike | +| ↳ `total` | number | Total records available | + +### CrowdStrike Query Cases + +Search CrowdStrike Falcon Case Management cases with a Falcon Query Language filter and return their IDs (GET /cases/queries/cases/v1). Case Management supersedes the CrowdScore Incidents API, which CrowdStrike has removed from its published API spec. Requires the "Cases: Read" API scope. + +#### Input + +| Parameter | Type | Required | Description | +| --------- | ---- | -------- | ----------- | +| `clientId` | string | Yes | CrowdStrike Falcon API client ID | +| `clientSecret` | string | Yes | CrowdStrike Falcon API client secret | +| `cloud` | string | Yes | CrowdStrike Falcon cloud region | +| `filter` | string | No | Falcon Query Language filter. Exact-match fields include cid and id; wildcard fields include assigned_to_name and assigned_to_uuid; range fields include created_timestamp and updated_timestamp. | +| `q` | string | No | Free-text search across all case metadata | +| `limit` | number | No | Maximum number of case IDs to return \(max 10000, default 100\) | +| `offset` | number | No | Pagination offset for the case query | +| `sort` | string | No | Sort expression such as "created_timestamp\|desc" or "status\|asc" | + +#### Output + +| Parameter | Type | Description | +| --------- | ---- | ----------- | +| `caseIds` | array | Case IDs matching the query | +| `count` | number | Number of case IDs returned | +| `pagination` | json | Pagination metadata \(limit, offset, total\) | | ↳ `limit` | number | Page size used for the query | | ↳ `offset` | number | Offset returned by CrowdStrike | | ↳ `total` | number | Total records available | +### CrowdStrike Query Host Groups + +Search CrowdStrike Falcon host groups with a Falcon Query Language filter and return their IDs (GET /devices/queries/host-groups/v1). Requires the "Host groups: Read" API scope. + +#### Input + +| Parameter | Type | Required | Description | +| --------- | ---- | -------- | ----------- | +| `clientId` | string | Yes | CrowdStrike Falcon API client ID | +| `clientSecret` | string | Yes | CrowdStrike Falcon API client secret | +| `cloud` | string | Yes | CrowdStrike Falcon cloud region | +| `filter` | string | No | Falcon Query Language filter over host group fields | +| `limit` | number | No | Maximum number of host group IDs to return \(1-5000\) | +| `offset` | number | No | Pagination offset for the host group query | +| `sort` | string | No | Sort expression such as "name.asc" or "modified_timestamp.desc" | + +#### Output + +| Parameter | Type | Description | +| --------- | ---- | ----------- | +| `hostGroupIds` | array | Host group IDs matching the query | +| `count` | number | Number of host group IDs returned | +| `pagination` | json | Pagination metadata \(limit, offset, total\) | +| ↳ `limit` | number | Page size used for the query | +| ↳ `offset` | number | Offset returned by CrowdStrike | +| ↳ `total` | number | Total records available | + +### CrowdStrike Query Indicators + +Search custom CrowdStrike Falcon indicators of compromise (IOCs) with a Falcon Query Language filter and return their IDs (GET /iocs/queries/indicators/v1). Requires the "IOC Management: Read" API scope. + +#### Input + +| Parameter | Type | Required | Description | +| --------- | ---- | -------- | ----------- | +| `clientId` | string | Yes | CrowdStrike Falcon API client ID | +| `clientSecret` | string | Yes | CrowdStrike Falcon API client secret | +| `cloud` | string | Yes | CrowdStrike Falcon cloud region | +| `filter` | string | No | Falcon Query Language filter over IOC fields | +| `limit` | number | No | Maximum number of IOC IDs to return \(1-500, default 100\) | +| `offset` | number | No | Pagination offset. Mutually exclusive with the after cursor; use after beyond 10,000 IOCs. | +| `after` | string | No | Pagination cursor from a previous response. Mutually exclusive with offset. | +| `sort` | string | No | Sort expression. Supported fields include action, applied_globally, created_by, created_on, expiration, expired, modified_by, modified_on, severity_number, source, type, and value. | + +#### Output + +| Parameter | Type | Description | +| --------- | ---- | ----------- | +| `indicatorIds` | array | IOC IDs matching the query | +| `count` | number | Number of IOC IDs returned | +| `pagination` | json | Pagination metadata \(limit, offset, total, after\) | +| ↳ `limit` | number | Page size used for the query | +| ↳ `offset` | number | Offset returned by CrowdStrike | +| ↳ `total` | number | Total records available | +| ↳ `after` | string | Cursor for the next page | + ### CrowdStrike Query Sensors -Search CrowdStrike identity protection sensors by hostname, IP, or related fields +Search CrowdStrike Identity Protection sensors -- the domain controllers Falcon Identity Protection monitors, not Falcon endpoint sensors -- and return their device IDs (GET /identity-protection/queries/devices/v1). Sort uses the dot form, for example status.desc. Requires the "Identity Protection Entities: Read" API scope, a separate entitlement from Hosts and Alerts. #### Input @@ -153,5 +832,130 @@ Search CrowdStrike identity protection sensors by hostname, IP, or related field | ↳ `limit` | number | Page size used for the query | | ↳ `offset` | number | Offset returned by CrowdStrike | | ↳ `total` | number | Total records available | +| `errors` | array | Errors CrowdStrike returned alongside a partially successful response | +| ↳ `code` | number | CrowdStrike error code | +| ↳ `id` | string | Identifier the error applies to | +| ↳ `message` | string | Error message | + +### CrowdStrike Query Vulnerabilities + +Search CrowdStrike Falcon Spotlight vulnerabilities with a required Falcon Query Language filter and return their IDs (GET /spotlight/queries/vulnerabilities/v1). Requires the spotlight-vulnerabilities:read API scope, shown as "Vulnerabilities: Read" in the Falcon API client UI. + +#### Input + +| Parameter | Type | Required | Description | +| --------- | ---- | -------- | ----------- | +| `clientId` | string | Yes | CrowdStrike Falcon API client ID | +| `clientSecret` | string | Yes | CrowdStrike Falcon API client secret | +| `cloud` | string | Yes | CrowdStrike Falcon cloud region | +| `filter` | string | Yes | Falcon Query Language filter \(required by Spotlight\). Filterable fields include status, aid, cid, last_seen_within, cve.id, cve.severity, cve.exprt_rating, cve.is_cisa_kev, cve.base_score, host_info.platform_name, host_info.groups, host_info.tags, host_info.internet_exposure, and suppression_info.is_suppressed. | +| `limit` | number | No | Maximum number of vulnerability IDs to return \(1-400, default 100\) | +| `after` | string | No | Pagination cursor from a previous response. Spotlight does not support offset. | +| `sort` | string | No | Sort expression such as "updated_timestamp\|desc" or "closed_timestamp\|asc" | + +#### Output + +| Parameter | Type | Description | +| --------- | ---- | ----------- | +| `vulnerabilityIds` | array | Spotlight vulnerability IDs matching the query | +| `count` | number | Number of vulnerability IDs returned | +| `pagination` | json | Cursor pagination metadata \(limit, total, after\) | +| ↳ `limit` | number | Page size used for the query | +| ↳ `total` | number | Total records available | +| ↳ `after` | string | Cursor for the next page | + +### CrowdStrike Update Alerts + +Update CrowdStrike Falcon alerts by composite ID: change status, assign or unassign an analyst, add or remove tags, append a comment, or toggle visibility (PATCH /alerts/entities/alerts/v3). This modifies live alerts in the Falcon console. Requires the "Alerts: Write" API scope. + +#### Input + +| Parameter | Type | Required | Description | +| --------- | ---- | -------- | ----------- | +| `clientId` | string | Yes | CrowdStrike Falcon API client ID | +| `clientSecret` | string | Yes | CrowdStrike Falcon API client secret | +| `cloud` | string | Yes | CrowdStrike Falcon cloud region | +| `compositeIds` | json | Yes | JSON array of CrowdStrike composite alert IDs to update | +| `updateStatus` | string | No | New alert status: new, in_progress, reopened, or closed | +| `assignToUuid` | string | No | Assign the alert to this Falcon user UUID | +| `assignToUserId` | string | No | Assign the alert to this Falcon user ID, such as user@example.com | +| `assignToName` | string | No | Assign the alert to this Falcon username, such as John Doe | +| `unassign` | boolean | No | Clear the assigned user UUID, user ID, and username from the alert | +| `appendComment` | string | No | Comment to append to the alert in the Falcon console | +| `addTag` | string | No | Tag to add to the alert | +| `removeTag` | string | No | Tag to remove from the alert | +| `removeTagsByPrefix` | string | No | Remove every tag on the alert that starts with this prefix | +| `showInUi` | boolean | No | Whether the alert is displayed in the Falcon console | +| `actionParameters` | json | No | Raw JSON array of additional CrowdStrike action parameters, each shaped \{ "name": string, "value": string \} | +| `includeHidden` | boolean | No | Include previously hidden alerts \(CrowdStrike defaults this to true\) | + +#### Output + +| Parameter | Type | Description | +| --------- | ---- | ----------- | +| `updatedIds` | array | Composite alert IDs the update was submitted for | +| `count` | number | Number of alerts the update was submitted for | +| `errors` | array | Errors CrowdStrike returned alongside a partially successful response | +| ↳ `code` | number | CrowdStrike error code | +| ↳ `id` | string | Identifier the error applies to | +| ↳ `message` | string | Error message | + +### CrowdStrike Update Indicators + +Update custom CrowdStrike Falcon indicators of compromise by ID (PATCH /iocs/entities/indicators/v1). DESTRUCTIVE: CrowdStrike blanks out any field you omit, so read each indicator with crowdstrike_get_indicator_details first and resend its full field set with your edits applied. Changing action or scope changes prevention behavior fleet-wide. type and value are immutable. Requires the "IOC Management: Write" API scope. + +#### Input + +| Parameter | Type | Required | Description | +| --------- | ---- | -------- | ----------- | +| `clientId` | string | Yes | CrowdStrike Falcon API client ID | +| `clientSecret` | string | Yes | CrowdStrike Falcon API client secret | +| `cloud` | string | Yes | CrowdStrike Falcon cloud region | +| `indicators` | json | Yes | JSON array of indicators to update. Each entry requires id, and must also repeat every field it wants to keep: CrowdStrike blanks out any updatable field the entry omits. Updatable fields: action, severity, description, source, tags \(array\), platforms \(array\), applied_globally \(boolean\), host_groups \(array\), expiration \(ISO 8601\), mobile_action, metadata \(\{ filename \}\). type and value cannot be changed. | +| `comment` | string | No | Audit comment explaining why these indicators were updated | +| `retrodetects` | boolean | No | Whether to generate retroactive detections for the updated indicators | +| `ignoreWarnings` | boolean | No | Whether to apply the updates even when CrowdStrike returns warnings | + +#### Output + +| Parameter | Type | Description | +| --------- | ---- | ----------- | +| `indicators` | array | Updated CrowdStrike indicator records | +| ↳ `id` | string | Indicator identifier | +| ↳ `type` | string | Indicator type | +| ↳ `value` | string | Indicator value | +| ↳ `action` | string | Action taken when the indicator matches | +| ↳ `mobileAction` | string | Action taken on mobile platforms when the indicator matches | +| ↳ `severity` | string | Indicator severity | +| ↳ `description` | string | Indicator description | +| ↳ `source` | string | Indicator source | +| ↳ `appliedGlobally` | boolean | Whether the indicator applies to all hosts | +| ↳ `platforms` | array | Platforms the indicator applies to | +| ↳ `hostGroups` | array | Host group IDs the indicator is scoped to | +| ↳ `tags` | array | Tags applied to the indicator | +| ↳ `expiration` | string | Indicator expiration timestamp | +| ↳ `expired` | boolean | Whether the indicator has expired | +| ↳ `deleted` | boolean | Whether the indicator is deleted | +| ↳ `fromParent` | boolean | Whether the indicator was inherited from a parent CID | +| ↳ `parentCidName` | string | Parent CID name | +| ↳ `createdBy` | string | User who created the indicator | +| ↳ `createdOn` | string | Indicator creation timestamp | +| ↳ `modifiedBy` | string | User who last modified the indicator | +| ↳ `modifiedOn` | string | Indicator modification timestamp | +| ↳ `metadata` | json | File metadata CrowdStrike resolved for the indicator | +| ↳ `avHits` | number | Antivirus hit count | +| ↳ `companyName` | string | Company name | +| ↳ `fileDescription` | string | File description | +| ↳ `fileVersion` | string | File version | +| ↳ `filename` | string | File name | +| ↳ `originalFilename` | string | Original file name | +| ↳ `productName` | string | Product name | +| ↳ `productVersion` | string | Product version | +| ↳ `signed` | boolean | Whether the file is signed | +| `count` | number | Number of indicators updated | +| `errors` | array | Errors CrowdStrike returned alongside a partially successful response | +| ↳ `code` | number | CrowdStrike error code | +| ↳ `id` | string | Identifier the error applies to | +| ↳ `message` | string | Error message | diff --git a/apps/sim/app/api/tools/crowdstrike/query/falcon.ts b/apps/sim/app/api/tools/crowdstrike/query/falcon.ts new file mode 100644 index 00000000000..d5a5efaa167 --- /dev/null +++ b/apps/sim/app/api/tools/crowdstrike/query/falcon.ts @@ -0,0 +1,243 @@ +import { isRecordLike } from '@sim/utils/object' +import type { CrowdStrikeBaseParams, CrowdStrikeCloud } from '@/tools/crowdstrike/types' + +export type JsonRecord = Record + +const CLOUD_BASE_URLS: Record = { + 'eu-1': 'https://api.eu-1.crowdstrike.com', + 'us-1': 'https://api.crowdstrike.com', + 'us-2': 'https://api.us-2.crowdstrike.com', + 'us-3': 'https://api.us-3.crowdstrike.com', + 'us-gov-1': 'https://api.laggar.gcw.crowdstrike.com', + 'us-gov-2': 'https://api.us-gov-2.crowdstrike.mil', +} + +export function getCloudBaseUrl(cloud: CrowdStrikeCloud): string { + return CLOUD_BASE_URLS[cloud] +} + +export function getString(value: unknown): string | null { + return typeof value === 'string' ? value : null +} + +export function getNumber(value: unknown): number | null { + return typeof value === 'number' ? value : null +} + +export function getBoolean(value: unknown): boolean | null { + return typeof value === 'boolean' ? value : null +} + +export function getStringArray(value: unknown): string[] { + if (!Array.isArray(value)) { + return [] + } + + return value.filter((entry): entry is string => typeof entry === 'string') +} + +export function getRecordArray(value: unknown): JsonRecord[] { + if (!Array.isArray(value)) { + return [] + } + + return value.filter(isRecordLike) +} + +export function getRecord(value: unknown): JsonRecord | null { + return isRecordLike(value) ? value : null +} + +/** + * Every Falcon endpoint this integration calls answers with a flat + * `{ meta, resources, errors }` envelope, so the envelope readers below and + * `getFalconErrorMessage` both read the payload root directly. + */ +export function getResourcesArray(data: unknown): unknown[] { + if (!isRecordLike(data) || !Array.isArray(data.resources)) { + return [] + } + + return data.resources +} + +export function getRecordResources(data: unknown): JsonRecord[] { + return getResourcesArray(data).filter(isRecordLike) +} + +export function getStringResources(data: unknown): string[] { + return getStringArray(getResourcesArray(data)) +} + +export function getFirstRecordResource(data: unknown): JsonRecord | null { + return getRecordResources(data)[0] ?? null +} + +export function getPagination(data: unknown) { + if (!isRecordLike(data) || !isRecordLike(data.meta) || !isRecordLike(data.meta.pagination)) { + return null + } + + const { pagination } = data.meta + + return { + limit: getNumber(pagination.limit), + offset: getNumber(pagination.offset), + total: getNumber(pagination.total), + } +} + +/** Offset pagination plus the `after` cursor the IOC Management API returns. */ +export function getCursorPagination(data: unknown) { + if (!isRecordLike(data) || !isRecordLike(data.meta) || !isRecordLike(data.meta.pagination)) { + return null + } + + const { pagination } = data.meta + + return { + after: getString(pagination.after), + limit: getNumber(pagination.limit), + offset: getNumber(pagination.offset), + total: getNumber(pagination.total), + } +} + +/** Spotlight paginates by cursor only — it returns no offset. */ +export function getSpotlightPagination(data: unknown) { + if (!isRecordLike(data) || !isRecordLike(data.meta) || !isRecordLike(data.meta.pagination)) { + return null + } + + const { pagination } = data.meta + + return { + after: getString(pagination.after), + limit: getNumber(pagination.limit), + total: getNumber(pagination.total), + } +} + +/** + * CrowdStrike returns `{ meta, resources, errors }` on every endpoint, and a 200 + * can still carry a populated `errors` array for the IDs that failed. + */ +export function getEnvelopeErrors(data: unknown) { + if (!isRecordLike(data)) { + return [] + } + + return getRecordArray(data.errors).map((entry) => ({ + code: getNumber(entry.code), + id: getString(entry.id), + message: getString(entry.message), + })) +} + +export function getFalconErrorMessage(data: unknown, fallback: string): string { + if (!isRecordLike(data)) { + return fallback + } + + const errors = Array.isArray(data.errors) ? data.errors : [] + const firstError = errors[0] + if (isRecordLike(firstError)) { + const firstMessage = getString(firstError.message) ?? getString(firstError.code) + if (firstMessage) { + return firstMessage + } + } + + return ( + getString(data.message) ?? + getString(data.error_description) ?? + getString(data.error) ?? + fallback + ) +} + +export async function getAccessToken(params: CrowdStrikeBaseParams): Promise { + const baseUrl = getCloudBaseUrl(params.cloud) + const response = await fetch(`${baseUrl}/oauth2/token`, { + method: 'POST', + headers: { + Accept: 'application/json', + 'Content-Type': 'application/x-www-form-urlencoded', + }, + body: new URLSearchParams({ + client_id: params.clientId, + client_secret: params.clientSecret, + grant_type: 'client_credentials', + }).toString(), + cache: 'no-store', + }) + + const data: unknown = await response.json().catch(() => null) + if (!response.ok) { + throw new Error(getFalconErrorMessage(data, 'Failed to authenticate with CrowdStrike')) + } + + if (!isRecordLike(data) || typeof data.access_token !== 'string') { + throw new Error('CrowdStrike authentication did not return an access token') + } + + return data.access_token +} + +interface CrowdStrikeRequestOptions { + method: 'GET' | 'POST' | 'PATCH' | 'DELETE' + path: string + query?: Record + repeatedQuery?: Record + body?: unknown +} + +export interface CrowdStrikeCallResult { + ok: boolean + status: number + data: unknown +} + +export function buildUrl(baseUrl: string, options: CrowdStrikeRequestOptions): string { + const url = new URL(options.path, baseUrl) + + for (const [key, value] of Object.entries(options.query ?? {})) { + if (value !== undefined) { + url.searchParams.set(key, String(value)) + } + } + + for (const [key, values] of Object.entries(options.repeatedQuery ?? {})) { + for (const value of values ?? []) { + url.searchParams.append(key, value) + } + } + + return url.toString() +} + +export async function callCrowdStrike( + baseUrl: string, + accessToken: string, + options: CrowdStrikeRequestOptions +): Promise { + const headers: Record = { + Accept: 'application/json', + Authorization: `Bearer ${accessToken}`, + } + + if (options.body !== undefined) { + headers['Content-Type'] = 'application/json' + } + + const response = await fetch(buildUrl(baseUrl, options), { + method: options.method, + headers, + body: options.body === undefined ? undefined : JSON.stringify(options.body), + cache: 'no-store', + }) + + const data: unknown = await response.json().catch(() => null) + + return { ok: response.ok, status: response.status, data } +} diff --git a/apps/sim/app/api/tools/crowdstrike/query/normalize.ts b/apps/sim/app/api/tools/crowdstrike/query/normalize.ts new file mode 100644 index 00000000000..d8784d077ef --- /dev/null +++ b/apps/sim/app/api/tools/crowdstrike/query/normalize.ts @@ -0,0 +1,266 @@ +import { + getBoolean, + getNumber, + getRecord, + getRecordArray, + getString, + getStringArray, + type JsonRecord, +} from '@/app/api/tools/crowdstrike/query/falcon' +import type { + CrowdStrikeAffectedEntity, + CrowdStrikeAlert, + CrowdStrikeCase, + CrowdStrikeFalconUser, + CrowdStrikeHostGroup, + CrowdStrikeIndicator, + CrowdStrikeVulnerability, +} from '@/tools/crowdstrike/types' + +export function normalizeAlert(resource: JsonRecord): CrowdStrikeAlert { + const device = getRecord(resource.device) + + return { + compositeId: getString(resource.composite_id), + id: getString(resource.id), + cid: getString(resource.cid), + aggregateId: getString(resource.aggregate_id), + agentId: getString(resource.agent_id), + deviceId: device ? getString(device.device_id) : null, + hostname: device ? getString(device.hostname) : null, + name: getString(resource.name), + displayName: getString(resource.display_name), + description: getString(resource.description), + type: getString(resource.type), + product: getString(resource.product), + platform: getString(resource.platform), + severity: getNumber(resource.severity), + severityName: getString(resource.severity_name), + confidence: getNumber(resource.confidence), + status: getString(resource.status), + assignedToName: getString(resource.assigned_to_name), + assignedToUid: getString(resource.assigned_to_uid), + assignedToUuid: getString(resource.assigned_to_uuid), + tactic: getString(resource.tactic), + tacticId: getString(resource.tactic_id), + technique: getString(resource.technique), + techniqueId: getString(resource.technique_id), + scenario: getString(resource.scenario), + objective: getString(resource.objective), + resolution: getString(resource.resolution), + showInUi: getBoolean(resource.show_in_ui), + tags: getStringArray(resource.tags), + filename: getString(resource.filename), + filepath: getString(resource.filepath), + cmdline: getString(resource.cmdline), + sha256: getString(resource.sha256), + sha1: getString(resource.sha1), + md5: getString(resource.md5), + userName: getString(resource.user_name), + userId: getString(resource.user_id), + patternId: getNumber(resource.pattern_id), + falconHostLink: getString(resource.falcon_host_link), + controlGraphId: getString(resource.control_graph_id), + external: getBoolean(resource.external), + emailSent: getBoolean(resource.email_sent), + isAggregated: getBoolean(resource.is_aggregated), + isFalconPlatformIoa: getBoolean(resource.is_falcon_platform_ioa), + dataDomains: getStringArray(resource.data_domains), + iocValues: getStringArray(resource.ioc_values), + linkedCaseIds: getStringArray(resource.linked_case_ids), + linkedBehavioralDetections: getStringArray(resource.linked_behavioral_detections), + timestamp: getString(resource.timestamp), + createdTimestamp: getString(resource.created_timestamp), + updatedTimestamp: getString(resource.updated_timestamp), + crawledTimestamp: getString(resource.crawled_timestamp), + contextTimestamp: getString(resource.context_timestamp), + } +} + +export function normalizeAffectedEntity(resource: JsonRecord): CrowdStrikeAffectedEntity { + return { + id: getString(resource.id), + path: getString(resource.path), + } +} + +export function normalizeHostGroup(resource: JsonRecord): CrowdStrikeHostGroup { + return { + id: getString(resource.id), + name: getString(resource.name), + description: getString(resource.description), + groupType: getString(resource.group_type), + assignmentRule: getString(resource.assignment_rule), + createdBy: getString(resource.created_by), + createdTimestamp: getString(resource.created_timestamp), + modifiedBy: getString(resource.modified_by), + modifiedTimestamp: getString(resource.modified_timestamp), + } +} + +export function normalizeIndicator(resource: JsonRecord): CrowdStrikeIndicator { + const metadata = getRecord(resource.metadata) + + return { + id: getString(resource.id), + type: getString(resource.type), + value: getString(resource.value), + action: getString(resource.action), + mobileAction: getString(resource.mobile_action), + severity: getString(resource.severity), + description: getString(resource.description), + source: getString(resource.source), + appliedGlobally: getBoolean(resource.applied_globally), + platforms: getStringArray(resource.platforms), + hostGroups: getStringArray(resource.host_groups), + tags: getStringArray(resource.tags), + expiration: getString(resource.expiration), + expired: getBoolean(resource.expired), + deleted: getBoolean(resource.deleted), + fromParent: getBoolean(resource.from_parent), + parentCidName: getString(resource.parent_cid_name), + createdBy: getString(resource.created_by), + createdOn: getString(resource.created_on), + modifiedBy: getString(resource.modified_by), + modifiedOn: getString(resource.modified_on), + metadata: metadata + ? { + avHits: getNumber(metadata.av_hits), + companyName: getString(metadata.company_name), + fileDescription: getString(metadata.file_description), + fileVersion: getString(metadata.file_version), + filename: getString(metadata.filename), + originalFilename: getString(metadata.original_filename), + productName: getString(metadata.product_name), + productVersion: getString(metadata.product_version), + signed: getBoolean(metadata.signed), + } + : null, + } +} + +export function normalizeVulnerability(resource: JsonRecord): CrowdStrikeVulnerability { + const cve = getRecord(resource.cve) + const cisaInfo = cve ? getRecord(cve.cisa_info) : null + const app = getRecord(resource.app) + const hostInfo = getRecord(resource.host_info) + const remediation = getRecord(resource.remediation) + const suppressionInfo = getRecord(resource.suppression_info) + + return { + id: getString(resource.id), + aid: getString(resource.aid), + cid: getString(resource.cid), + status: getString(resource.status), + confidence: getString(resource.confidence), + vulnerabilityId: getString(resource.vulnerability_id), + createdTimestamp: getString(resource.created_timestamp), + updatedTimestamp: getString(resource.updated_timestamp), + closedTimestamp: getString(resource.closed_timestamp), + cve: cve + ? { + id: getString(cve.id), + baseScore: getNumber(cve.base_score), + severity: getString(cve.severity), + exprtRating: getString(cve.exprt_rating), + exploitStatus: getNumber(cve.exploit_status), + exploitabilityScore: getNumber(cve.exploitability_score), + impactScore: getNumber(cve.impact_score), + remediationLevel: getString(cve.remediation_level), + description: getString(cve.description), + publishedDate: getString(cve.published_date), + vector: getString(cve.vector), + types: getStringArray(cve.types), + isCisaKev: cisaInfo ? getBoolean(cisaInfo.is_cisa_kev) : null, + cisaDueDate: cisaInfo ? getString(cisaInfo.due_date) : null, + } + : null, + app: app + ? { + productNameNormalized: getString(app.product_name_normalized), + productNameVersion: getString(app.product_name_version), + vendorNormalized: getString(app.vendor_normalized), + } + : null, + hostInfo: hostInfo + ? { + hostname: getString(hostInfo.hostname), + localIp: getString(hostInfo.local_ip), + machineDomain: getString(hostInfo.machine_domain), + osVersion: getString(hostInfo.os_version), + platform: getString(hostInfo.platform), + productTypeDesc: getString(hostInfo.product_type_desc), + assetCriticality: getString(hostInfo.asset_criticality), + internetExposure: getString(hostInfo.internet_exposure), + tags: getStringArray(hostInfo.tags), + groups: getRecordArray(hostInfo.groups) + .map((group) => getString(group.name)) + .filter((name): name is string => name !== null), + } + : null, + remediationIds: remediation ? getStringArray(remediation.ids) : [], + remediations: remediation + ? getRecordArray(remediation.entities).map((entity) => ({ + id: getString(entity.id), + title: getString(entity.title), + action: getString(entity.action), + type: getString(entity.type), + link: getString(entity.link), + reference: getString(entity.reference), + vendorUrl: getString(entity.vendor_url), + })) + : [], + suppressionInfo: suppressionInfo + ? { + isSuppressed: getBoolean(suppressionInfo.is_suppressed), + reason: getString(suppressionInfo.reason), + } + : null, + } +} + +function normalizeFalconUser(value: unknown): CrowdStrikeFalconUser | null { + const user = getRecord(value) + if (!user) { + return null + } + + return { + uuid: getString(user.uuid), + email: getString(user.email), + fullName: getString(user.full_name), + } +} + +export function normalizeCase(resource: JsonRecord): CrowdStrikeCase { + const severityInfo = getRecord(resource.severity_info) + const template = getRecord(resource.template) + const sla = getRecord(resource.sla) + const readOnly = getRecord(resource.read_only) + + return { + id: getString(resource.id), + cid: getString(resource.cid), + name: getString(resource.name), + description: getString(resource.description), + descriptionFormat: getString(resource.description_format), + status: getString(resource.status), + severity: getNumber(resource.severity), + severityLevel: severityInfo ? getString(severityInfo.level) : null, + referenceId: getString(resource.reference_id), + version: getNumber(resource.version), + tags: getStringArray(resource.tags), + assignedTo: normalizeFalconUser(resource.assigned_to), + createdBy: normalizeFalconUser(resource.created_by), + lastUpdatedBy: normalizeFalconUser(resource.last_updated_by), + createdTimestamp: getString(resource.created_timestamp), + updatedTimestamp: getString(resource.updated_timestamp), + startTimestamp: getString(resource.start_timestamp), + endTimestamp: getString(resource.end_timestamp), + templateId: template ? getString(template.id) : null, + templateName: template ? getString(template.name) : null, + slaId: sla ? getString(sla.id) : null, + slaName: sla ? getString(sla.name) : null, + isReadOnly: readOnly ? getBoolean(readOnly.is_read_only) : null, + } +} diff --git a/apps/sim/app/api/tools/crowdstrike/query/operations.test.ts b/apps/sim/app/api/tools/crowdstrike/query/operations.test.ts new file mode 100644 index 00000000000..89a3b81992c --- /dev/null +++ b/apps/sim/app/api/tools/crowdstrike/query/operations.test.ts @@ -0,0 +1,936 @@ +/** + * @vitest-environment node + */ +import { createMockRequest, hybridAuthMockFns } from '@sim/testing' +import { beforeEach, describe, expect, it, vi } from 'vitest' + +const { fetchMock } = vi.hoisted(() => ({ + fetchMock: vi.fn(), +})) + +import { POST } from '@/app/api/tools/crowdstrike/query/route' + +function jsonResponse(body: unknown, status = 200): Response { + return new Response(JSON.stringify(body), { + status, + headers: { 'Content-Type': 'application/json' }, + }) +} + +const credentials = { + clientId: 'client-id', + clientSecret: 'client-secret', + cloud: 'us-1' as const, +} + +function requestFor(body: Record) { + return createMockRequest('POST', { ...credentials, ...body }) +} + +describe('CrowdStrike extended operations', () => { + beforeEach(() => { + vi.clearAllMocks() + fetchMock.mockReset() + vi.stubGlobal('fetch', fetchMock) + + hybridAuthMockFns.mockCheckInternalAuth.mockResolvedValue({ + success: true, + userId: 'user-123', + authType: 'internal_jwt', + }) + + fetchMock.mockResolvedValueOnce(jsonResponse({ access_token: 'token-123' })) + }) + + it('queries alerts and returns composite ids with pagination', async () => { + fetchMock.mockResolvedValueOnce( + jsonResponse({ + meta: { pagination: { limit: 2, offset: 0, total: 7 } }, + resources: ['cid:aid:alert-1', 'cid:aid:alert-2'], + }) + ) + + const response = await POST( + requestFor({ operation: 'crowdstrike_query_alerts', filter: 'status:"new"', limit: 2 }) + ) + const data = await response.json() + + expect(response.status).toBe(200) + expect(data.output).toEqual({ + alertIds: ['cid:aid:alert-1', 'cid:aid:alert-2'], + count: 2, + pagination: { limit: 2, offset: 0, total: 7 }, + }) + + const queryUrl = new URL(fetchMock.mock.calls[1][0]) + expect(queryUrl.pathname).toBe('/alerts/queries/alerts/v2') + expect(queryUrl.searchParams.get('filter')).toBe('status:"new"') + expect(queryUrl.searchParams.get('limit')).toBe('2') + }) + + it('normalizes alert details from documented fields', async () => { + fetchMock.mockResolvedValueOnce( + jsonResponse({ + resources: [ + { + composite_id: 'cid:aid:alert-1', + id: 'alert-1', + severity: 70, + severity_name: 'High', + status: 'new', + tags: ['triage'], + device: { device_id: 'a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1', hostname: 'web-01' }, + }, + ], + }) + ) + + const response = await POST( + requestFor({ + operation: 'crowdstrike_get_alert_details', + compositeIds: ['cid:aid:alert-1'], + }) + ) + const data = await response.json() + + expect(response.status).toBe(200) + expect(data.output.count).toBe(1) + expect(data.output.alerts[0]).toMatchObject({ + compositeId: 'cid:aid:alert-1', + id: 'alert-1', + severity: 70, + severityName: 'High', + status: 'new', + tags: ['triage'], + deviceId: 'a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1', + hostname: 'web-01', + }) + + const [, detailsCall] = fetchMock.mock.calls + expect(JSON.parse(detailsCall[1].body)).toEqual({ composite_ids: ['cid:aid:alert-1'] }) + }) + + it('builds documented action parameters when updating alerts', async () => { + fetchMock.mockResolvedValueOnce(jsonResponse({ meta: {}, errors: [] })) + + const response = await POST( + requestFor({ + operation: 'crowdstrike_update_alerts', + compositeIds: ['cid:aid:alert-1'], + updateStatus: 'closed', + appendComment: 'Resolved by automation', + showInUi: false, + }) + ) + const data = await response.json() + + expect(response.status).toBe(200) + expect(data.output.updatedIds).toEqual(['cid:aid:alert-1']) + + const [, updateCall] = fetchMock.mock.calls + expect(updateCall[1].method).toBe('PATCH') + expect(JSON.parse(updateCall[1].body)).toEqual({ + action_parameters: [ + { name: 'update_status', value: 'closed' }, + { name: 'append_comment', value: 'Resolved by automation' }, + { name: 'show_in_ui', value: 'false' }, + ], + composite_ids: ['cid:aid:alert-1'], + }) + }) + + it('rejects an alert update that carries no action', async () => { + const response = await POST( + requestFor({ + operation: 'crowdstrike_update_alerts', + compositeIds: ['cid:aid:alert-1'], + }) + ) + + expect(response.status).toBe(400) + expect(fetchMock).toHaveBeenCalledTimes(0) + }) + + it('contains hosts through the documented action endpoint', async () => { + fetchMock.mockResolvedValueOnce( + jsonResponse( + { + resources: [ + { id: 'a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1', path: '/devices/entities/devices/v1' }, + ], + }, + 202 + ) + ) + + const response = await POST( + requestFor({ + operation: 'crowdstrike_perform_host_action', + actionName: 'contain', + deviceIds: ['a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1'], + }) + ) + const data = await response.json() + + expect(response.status).toBe(200) + expect(data.output.affected).toEqual([ + { id: 'a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1', path: '/devices/entities/devices/v1' }, + ]) + + const actionUrl = new URL(fetchMock.mock.calls[1][0]) + expect(actionUrl.pathname).toBe('/devices/entities/devices-actions/v2') + expect(actionUrl.searchParams.get('action_name')).toBe('contain') + expect(JSON.parse(fetchMock.mock.calls[1][1].body)).toEqual({ + ids: ['a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1'], + }) + }) + + it('rejects an unsupported host action', async () => { + const response = await POST( + requestFor({ + operation: 'crowdstrike_perform_host_action', + actionName: 'delete_host', + deviceIds: ['a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1'], + }) + ) + + expect(response.status).toBe(400) + expect(fetchMock).toHaveBeenCalledTimes(0) + }) + + it('adds hosts to a group with a device_id FQL filter', async () => { + fetchMock.mockResolvedValueOnce(jsonResponse({ resources: [{ id: 'group-1', name: 'SOC' }] })) + + const response = await POST( + requestFor({ + operation: 'crowdstrike_perform_host_group_action', + actionName: 'add-hosts', + hostGroupId: 'group-1', + deviceIds: ['a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1', 'b2b2b2b2b2b2b2b2b2b2b2b2b2b2b2b2'], + }) + ) + const data = await response.json() + + expect(response.status).toBe(200) + expect(data.output.hostGroups[0]).toMatchObject({ id: 'group-1', name: 'SOC' }) + + const groupUrl = new URL(fetchMock.mock.calls[1][0]) + expect(groupUrl.pathname).toBe('/devices/entities/host-group-actions/v1') + expect(groupUrl.searchParams.get('action_name')).toBe('add-hosts') + expect(JSON.parse(fetchMock.mock.calls[1][1].body)).toEqual({ + action_parameters: [ + { + name: 'filter', + value: + "(device_id:['a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1','b2b2b2b2b2b2b2b2b2b2b2b2b2b2b2b2'])", + }, + ], + ids: ['group-1'], + }) + }) + + it('treats a 200 with only envelope errors as a failure', async () => { + fetchMock.mockResolvedValueOnce( + jsonResponse({ + resources: [], + errors: [{ code: 404, id: 'ioc-1', message: 'Indicator not found' }], + }) + ) + + const response = await POST( + requestFor({ operation: 'crowdstrike_get_indicator_details', indicatorIds: ['ioc-1'] }) + ) + const data = await response.json() + + expect(response.status).toBe(404) + expect(data.success).toBe(false) + expect(data.error).toBe('Indicator not found') + }) + + it('falls back to 502 when a 200 carries errors without a usable code', async () => { + fetchMock.mockResolvedValueOnce( + jsonResponse({ resources: [], errors: [{ message: 'Upstream unavailable' }] }) + ) + + const response = await POST( + requestFor({ operation: 'crowdstrike_get_indicator_details', indicatorIds: ['ioc-1'] }) + ) + const data = await response.json() + + expect(response.status).toBe(502) + expect(data.success).toBe(false) + expect(data.error).toBe('Upstream unavailable') + }) + + it('fails an alert update when the meta-only envelope reports any error', async () => { + fetchMock.mockResolvedValueOnce( + jsonResponse({ meta: {}, errors: [{ code: 403, message: 'Alert is read only' }] }) + ) + + const response = await POST( + requestFor({ + operation: 'crowdstrike_update_alerts', + compositeIds: ['cid:aid:alert-1'], + updateStatus: 'closed', + }) + ) + const data = await response.json() + + expect(response.status).toBe(403) + expect(data.success).toBe(false) + expect(data.error).toBe('Alert is read only') + }) + + it('sends remove_tags_by_prefix using the documented action parameter name', async () => { + fetchMock.mockResolvedValueOnce(jsonResponse({ meta: {}, errors: [] })) + + const response = await POST( + requestFor({ + operation: 'crowdstrike_update_alerts', + compositeIds: ['cid:aid:alert-1'], + removeTagsByPrefix: 'auto-', + }) + ) + + expect(response.status).toBe(200) + + const [, updateCall] = fetchMock.mock.calls + expect(JSON.parse(updateCall[1].body).action_parameters).toEqual([ + { name: 'remove_tags_by_prefix', value: 'auto-' }, + ]) + }) + + it('surfaces envelope errors alongside partial indicator results', async () => { + fetchMock.mockResolvedValueOnce( + jsonResponse({ + resources: [{ id: 'ioc-1', type: 'sha256', value: 'abc', action: 'prevent' }], + errors: [{ code: 404, id: 'ioc-2', message: 'Indicator not found' }], + }) + ) + + const response = await POST( + requestFor({ + operation: 'crowdstrike_get_indicator_details', + indicatorIds: ['ioc-1', 'ioc-2'], + }) + ) + const data = await response.json() + + expect(data.success).toBe(true) + expect(data.output.count).toBe(1) + expect(data.output.errors).toEqual([{ code: 404, id: 'ioc-2', message: 'Indicator not found' }]) + }) + + it('deletes indicators by filter without an ids list', async () => { + fetchMock.mockResolvedValueOnce(jsonResponse({ resources: ['ioc-1'] })) + + const response = await POST( + requestFor({ + operation: 'crowdstrike_delete_indicators', + filter: "source:'automation'", + comment: 'cleanup', + }) + ) + const data = await response.json() + + expect(data.output.deletedIds).toEqual(['ioc-1']) + + const deleteUrl = new URL(fetchMock.mock.calls[1][0]) + expect(fetchMock.mock.calls[1][1].method).toBe('DELETE') + expect(deleteUrl.searchParams.get('filter')).toBe("source:'automation'") + expect(deleteUrl.searchParams.getAll('ids')).toEqual([]) + expect(deleteUrl.searchParams.get('comment')).toBe('cleanup') + }) + + it('rejects a delete that supplies both ids and a filter', async () => { + const response = await POST( + requestFor({ + operation: 'crowdstrike_delete_indicators', + filter: "source:'automation'", + indicatorIds: ['ioc-9'], + }) + ) + + expect(response.status).toBe(400) + expect(fetchMock).toHaveBeenCalledTimes(0) + }) + + it('rejects a host agent ID that is not a 32-character AID', async () => { + const response = await POST( + requestFor({ + operation: 'crowdstrike_perform_host_action', + actionName: 'contain', + deviceIds: ["not-an-aid') or (device_id:['*'"], + }) + ) + + expect(response.status).toBe(400) + expect(fetchMock).toHaveBeenCalledTimes(0) + }) + + it('rejects an alert update that both assigns and unassigns', async () => { + const response = await POST( + requestFor({ + operation: 'crowdstrike_update_alerts', + compositeIds: ['cid:aid:alert-1'], + assignToUuid: 'user-uuid', + unassign: true, + }) + ) + + expect(response.status).toBe(400) + expect(fetchMock).toHaveBeenCalledTimes(0) + }) + + it('rejects an indicator update whose entry carries no id', async () => { + const response = await POST( + requestFor({ + operation: 'crowdstrike_update_indicators', + indicators: [{ action: 'prevent' }], + }) + ) + + expect(response.status).toBe(400) + expect(await response.json()).toMatchObject({ error: expect.stringContaining('id') }) + expect(fetchMock).toHaveBeenCalledTimes(0) + }) + + it('rejects an indicator update that tries to change the immutable type or value', async () => { + const response = await POST( + requestFor({ + operation: 'crowdstrike_update_indicators', + indicators: [{ id: 'ioc-1', value: 'evil.example' }], + }) + ) + + expect(response.status).toBe(400) + expect(fetchMock).toHaveBeenCalledTimes(0) + }) + + it('rejects an indicator create that omits the required applied_globally scope', async () => { + const response = await POST( + requestFor({ + operation: 'crowdstrike_create_indicators', + indicators: [{ type: 'sha256', value: 'a'.repeat(64), action: 'prevent' }], + }) + ) + + expect(response.status).toBe(400) + expect(fetchMock).toHaveBeenCalledTimes(0) + }) + + it('rejects a write-tier RTR base command on the read-scoped endpoint', async () => { + const response = await POST( + requestFor({ + operation: 'crowdstrike_execute_rtr_command', + sessionId: 'session-1', + baseCommand: 'eventlog backup', + commandString: 'eventlog backup Security', + }) + ) + + expect(response.status).toBe(400) + expect(fetchMock).toHaveBeenCalledTimes(0) + }) + + it('routes an aggregate request to the US-3 cloud', async () => { + fetchMock.mockResolvedValueOnce(jsonResponse({ resources: [] })) + + const response = await POST( + createMockRequest('POST', { + clientId: 'client-id', + clientSecret: 'client-secret', + cloud: 'us-3', + operation: 'crowdstrike_query_sensors', + }) + ) + + expect(response.status).toBe(200) + expect(String(fetchMock.mock.calls[0][0])).toBe('https://api.us-3.crowdstrike.com/oauth2/token') + expect(new URL(fetchMock.mock.calls[1][0]).host).toBe('api.us-3.crowdstrike.com') + }) + + it('rejects an aggregate query that names neither a field nor a type', async () => { + const response = await POST( + requestFor({ + operation: 'crowdstrike_get_sensor_aggregates', + aggregateQuery: { size: 10 }, + }) + ) + + expect(response.status).toBe(400) + expect(fetchMock).toHaveBeenCalledTimes(0) + }) + + it('forwards the percents and filters_spec aggregate fields instead of stripping them', async () => { + fetchMock.mockResolvedValueOnce(jsonResponse({ resources: [] })) + + const aggregateQuery = { + field: 'status', + name: 'by-status', + percents: [50, 95], + filters_spec: { filters: { stale: "status:'inactive'" }, other_bucket: true }, + } + + await POST(requestFor({ operation: 'crowdstrike_get_sensor_aggregates', aggregateQuery })) + + expect(JSON.parse(fetchMock.mock.calls[1][1].body)).toEqual(aggregateQuery) + }) + + it('rejects a delete with neither ids nor a filter', async () => { + const response = await POST(requestFor({ operation: 'crowdstrike_delete_indicators' })) + + expect(response.status).toBe(400) + expect(fetchMock).toHaveBeenCalledTimes(0) + }) + + it('requires a filter for Spotlight vulnerability queries', async () => { + const response = await POST(requestFor({ operation: 'crowdstrike_query_vulnerabilities' })) + + expect(response.status).toBe(400) + expect(fetchMock).toHaveBeenCalledTimes(0) + }) + + it('returns Spotlight cursor pagination', async () => { + fetchMock.mockResolvedValueOnce( + jsonResponse({ + meta: { pagination: { after: 'cursor-1', limit: 1, total: 12 } }, + resources: ['vuln-1'], + }) + ) + + const response = await POST( + requestFor({ operation: 'crowdstrike_query_vulnerabilities', filter: 'status:"open"' }) + ) + const data = await response.json() + + expect(data.output).toEqual({ + vulnerabilityIds: ['vuln-1'], + count: 1, + pagination: { after: 'cursor-1', limit: 1, total: 12 }, + }) + }) + + it('normalizes nested vulnerability details', async () => { + fetchMock.mockResolvedValueOnce( + jsonResponse({ + resources: [ + { + id: 'vuln-1', + aid: 'a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1', + status: 'open', + cve: { + id: 'CVE-2026-0001', + base_score: 9.8, + severity: 'CRITICAL', + cisa_info: { is_cisa_kev: true, due_date: '2026-09-01' }, + }, + host_info: { hostname: 'web-01', groups: [{ id: 'g1', name: 'SOC' }], tags: ['prod'] }, + remediation: { ids: ['rem-1'], entities: [{ id: 'rem-1', title: 'Patch now' }] }, + }, + ], + }) + ) + + const response = await POST( + requestFor({ + operation: 'crowdstrike_get_vulnerability_details', + vulnerabilityIds: ['vuln-1'], + }) + ) + const data = await response.json() + + const vulnerability = data.output.vulnerabilities[0] + expect(vulnerability.cve).toMatchObject({ + id: 'CVE-2026-0001', + baseScore: 9.8, + severity: 'CRITICAL', + isCisaKev: true, + cisaDueDate: '2026-09-01', + }) + expect(vulnerability.hostInfo).toMatchObject({ hostname: 'web-01', groups: ['SOC'] }) + expect(vulnerability.remediationIds).toEqual(['rem-1']) + expect(vulnerability.remediations[0]).toMatchObject({ id: 'rem-1', title: 'Patch now' }) + }) + + it('opens and closes a Real Time Response session', async () => { + fetchMock.mockResolvedValueOnce( + jsonResponse( + { + resources: [ + { + session_id: 'session-1', + device_id: 'a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1', + pwd: 'C:\\', + offline_queued: false, + existing_aid_sessions: 0, + created_at: '2026-08-15T00:00:00Z', + }, + ], + }, + 201 + ) + ) + + const initResponse = await POST( + requestFor({ + operation: 'crowdstrike_init_rtr_session', + deviceId: 'a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1', + }) + ) + const initData = await initResponse.json() + + expect(initData.output).toMatchObject({ + sessionId: 'session-1', + deviceId: 'a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1', + pwd: 'C:\\', + }) + expect(JSON.parse(fetchMock.mock.calls[1][1].body)).toEqual({ + device_id: 'a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1', + }) + + fetchMock.mockResolvedValueOnce(jsonResponse({ access_token: 'token-123' })) + fetchMock.mockResolvedValueOnce(jsonResponse({ meta: {} })) + + const deleteResponse = await POST( + requestFor({ operation: 'crowdstrike_delete_rtr_session', sessionId: 'session-1' }) + ) + const deleteData = await deleteResponse.json() + + expect(deleteData.output).toMatchObject({ sessionId: 'session-1', deleted: true }) + const deleteUrl = new URL(fetchMock.mock.calls[3][0]) + expect(deleteUrl.pathname).toBe('/real-time-response/entities/sessions/v1') + expect(deleteUrl.searchParams.get('session_id')).toBe('session-1') + }) + + it('defaults the RTR command status sequence to zero', async () => { + fetchMock.mockResolvedValueOnce( + jsonResponse({ + resources: [ + { + session_id: 'session-1', + complete: true, + stdout: 'Directory listing', + stderr: '', + base_command: 'ls', + sequence_id: 0, + }, + ], + }) + ) + + const response = await POST( + requestFor({ operation: 'crowdstrike_get_rtr_command_status', cloudRequestId: 'req-1' }) + ) + const data = await response.json() + + expect(data.output).toMatchObject({ complete: true, stdout: 'Directory listing' }) + const statusUrl = new URL(fetchMock.mock.calls[1][0]) + expect(statusUrl.searchParams.get('cloud_request_id')).toBe('req-1') + expect(statusUrl.searchParams.get('sequence_id')).toBe('0') + }) + + it('normalizes Case Management case details', async () => { + fetchMock.mockResolvedValueOnce( + jsonResponse({ + resources: [ + { + id: 'case-1', + name: 'Suspicious login', + status: 'In Progress', + severity: 3, + severity_info: { level: 'High' }, + reference_id: 'CASE-42', + assigned_to: { uuid: 'u-1', email: 'a@example.com', full_name: 'Analyst One' }, + template: { id: 't-1', name: 'Triage' }, + read_only: { is_read_only: false }, + tags: ['phishing'], + }, + ], + }) + ) + + const response = await POST( + requestFor({ operation: 'crowdstrike_get_case_details', caseIds: ['case-1'] }) + ) + const data = await response.json() + + expect(data.output.cases[0]).toMatchObject({ + id: 'case-1', + name: 'Suspicious login', + status: 'In Progress', + severity: 3, + severityLevel: 'High', + referenceId: 'CASE-42', + assignedTo: { uuid: 'u-1', email: 'a@example.com', fullName: 'Analyst One' }, + templateName: 'Triage', + isReadOnly: false, + tags: ['phishing'], + }) + expect(JSON.parse(fetchMock.mock.calls[1][1].body)).toEqual({ ids: ['case-1'] }) + }) + + it('propagates a CrowdStrike error status', async () => { + fetchMock.mockResolvedValueOnce( + jsonResponse({ errors: [{ code: 403, message: 'access denied' }] }, 403) + ) + + const response = await POST( + requestFor({ operation: 'crowdstrike_query_host_groups', filter: 'name:"SOC"' }) + ) + const data = await response.json() + + expect(response.status).toBe(403) + expect(data).toEqual({ success: false, error: 'access denied' }) + }) + + it('fails an alert query whose 200 envelope carries only errors', async () => { + fetchMock.mockResolvedValueOnce( + jsonResponse({ + resources: [], + errors: [{ code: 403, id: null, message: 'insufficient scope' }], + }) + ) + + const response = await POST( + requestFor({ operation: 'crowdstrike_query_alerts', filter: 'status:"new"' }) + ) + const data = await response.json() + + expect(response.status).toBe(403) + expect(data).toEqual({ success: false, error: 'insufficient scope' }) + }) + + it('fails a case query whose 200 envelope carries only errors', async () => { + fetchMock.mockResolvedValueOnce( + jsonResponse({ + resources: [], + errors: [{ code: 500, id: null, message: 'case service unavailable' }], + }) + ) + + const response = await POST(requestFor({ operation: 'crowdstrike_query_cases' })) + const data = await response.json() + + expect(response.status).toBe(500) + expect(data).toEqual({ success: false, error: 'case service unavailable' }) + }) + + it('still reports a genuinely empty alert query as a success', async () => { + fetchMock.mockResolvedValueOnce(jsonResponse({ resources: [], errors: [] })) + + const response = await POST( + requestFor({ operation: 'crowdstrike_query_alerts', filter: 'status:"new"' }) + ) + const data = await response.json() + + expect(response.status).toBe(200) + expect(data.output.alertIds).toEqual([]) + expect(data.output.count).toBe(0) + }) + + it('rejects an indicator query that combines offset and after pagination', async () => { + const response = await POST( + requestFor({ operation: 'crowdstrike_query_indicators', offset: 0, after: 'cursor-1' }) + ) + + expect(response.status).toBe(400) + expect(fetchMock).toHaveBeenCalledTimes(0) + }) + + it('rejects a blank alert filter so Falcon never sees an empty FQL expression', async () => { + const response = await POST( + requestFor({ operation: 'crowdstrike_query_alerts', filter: ' ' }) + ) + + expect(response.status).toBe(400) + expect(fetchMock).toHaveBeenCalledTimes(0) + }) + + it('rejects a blank sensor filter instead of sending an empty FQL expression', async () => { + const response = await POST( + requestFor({ operation: 'crowdstrike_query_sensors', filter: ' ' }) + ) + + expect(response.status).toBe(400) + expect(fetchMock).toHaveBeenCalledTimes(0) + }) + + it('rejects a blank sensor sort instead of sending an empty sort expression', async () => { + const response = await POST(requestFor({ operation: 'crowdstrike_query_sensors', sort: '' })) + + expect(response.status).toBe(400) + expect(fetchMock).toHaveBeenCalledTimes(0) + }) + + it('forwards trimmed sensor filter and sort values', async () => { + fetchMock.mockResolvedValueOnce(jsonResponse({ resources: [] })) + + const response = await POST( + requestFor({ + operation: 'crowdstrike_query_sensors', + filter: ' hostname:"dc-01" ', + sort: ' hostname.asc ', + }) + ) + + expect(response.status).toBe(200) + + const queryUrl = new URL(fetchMock.mock.calls[1][0]) + expect(queryUrl.pathname).toBe('/identity-protection/queries/devices/v1') + expect(queryUrl.searchParams.get('filter')).toBe('hostname:"dc-01"') + expect(queryUrl.searchParams.get('sort')).toBe('hostname.asc') + }) + + it('fails an RTR session close whose 200 envelope reports an error', async () => { + fetchMock.mockResolvedValueOnce( + jsonResponse({ meta: {}, errors: [{ code: 404, message: 'session not found' }] }) + ) + + const response = await POST( + requestFor({ operation: 'crowdstrike_delete_rtr_session', sessionId: 'session-1' }) + ) + const data = await response.json() + + expect(response.status).toBe(404) + expect(data.success).toBe(false) + expect(data.error).toBe('session not found') + }) + + it('fails a sensor query whose 200 envelope carries only errors', async () => { + fetchMock.mockResolvedValueOnce( + jsonResponse({ + resources: [], + errors: [{ code: 403, message: 'access denied for Identity Protection' }], + }) + ) + + const response = await POST(requestFor({ operation: 'crowdstrike_query_sensors' })) + const data = await response.json() + + expect(response.status).toBe(403) + expect(data.success).toBe(false) + expect(data.error).toBe('access denied for Identity Protection') + }) + + it('fails a sensor detail lookup whose 200 envelope carries only errors', async () => { + fetchMock.mockResolvedValueOnce( + jsonResponse({ resources: [], errors: [{ code: 403, message: 'access denied' }] }) + ) + + const response = await POST( + requestFor({ + operation: 'crowdstrike_get_sensor_details', + ids: ['a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1'], + }) + ) + const data = await response.json() + + expect(response.status).toBe(403) + expect(data.success).toBe(false) + }) + + it('fails a sensor aggregate whose 200 envelope carries only errors', async () => { + fetchMock.mockResolvedValueOnce( + jsonResponse({ resources: [], errors: [{ code: 403, message: 'access denied' }] }) + ) + + const response = await POST( + requestFor({ + operation: 'crowdstrike_get_sensor_aggregates', + aggregateQuery: { field: 'status', name: 'by_status', type: 'terms' }, + }) + ) + const data = await response.json() + + expect(response.status).toBe(403) + expect(data.success).toBe(false) + }) + + it('surfaces partial sensor errors alongside the sensors that resolved', async () => { + fetchMock.mockResolvedValueOnce( + jsonResponse({ + resources: [{ device_id: 'a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1', hostname: 'dc-01' }], + errors: [ + { code: 404, id: 'b2b2b2b2b2b2b2b2b2b2b2b2b2b2b2b2', message: 'sensor not found' }, + ], + }) + ) + + const response = await POST( + requestFor({ + operation: 'crowdstrike_get_sensor_details', + ids: ['a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1', 'b2b2b2b2b2b2b2b2b2b2b2b2b2b2b2b2'], + }) + ) + const data = await response.json() + + expect(response.status).toBe(200) + expect(data.output.count).toBe(1) + expect(data.output.errors).toEqual([ + { code: 404, id: 'b2b2b2b2b2b2b2b2b2b2b2b2b2b2b2b2', message: 'sensor not found' }, + ]) + }) + + it('preserves a scalar aggregate bucket label', async () => { + fetchMock.mockResolvedValueOnce( + jsonResponse({ + resources: [{ name: 'by_status', buckets: [{ label: 'contained', count: 3 }] }], + }) + ) + + const response = await POST( + requestFor({ + operation: 'crowdstrike_get_sensor_aggregates', + aggregateQuery: { field: 'status', name: 'by_status', type: 'terms' }, + }) + ) + const data = await response.json() + + expect(data.output.aggregates[0].buckets[0].label).toBe('contained') + }) + + it('rejects an indicator payload whose blank field would clear stored data', async () => { + const response = await POST( + requestFor({ + operation: 'crowdstrike_update_indicators', + indicators: [{ id: 'ioc-1', description: '' }], + }) + ) + + expect(response.status).toBe(400) + expect(fetchMock).toHaveBeenCalledTimes(0) + }) + + it('rejects a host action targeting more than the documented 100 hosts', async () => { + const response = await POST( + requestFor({ + operation: 'crowdstrike_perform_host_action', + actionName: 'contain', + deviceIds: Array.from({ length: 101 }, (_, index) => `aid-${index}`), + }) + ) + + expect(response.status).toBe(400) + expect(fetchMock).toHaveBeenCalledTimes(0) + }) + + it('accepts the documented detection suppression host actions', async () => { + fetchMock.mockResolvedValueOnce( + jsonResponse({ resources: [{ id: 'a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1' }] }) + ) + + const response = await POST( + requestFor({ + operation: 'crowdstrike_perform_host_action', + actionName: 'detection_suppress', + deviceIds: ['a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1'], + }) + ) + + expect(response.status).toBe(200) + expect(new URL(fetchMock.mock.calls[1][0]).searchParams.get('action_name')).toBe( + 'detection_suppress' + ) + }) +}) diff --git a/apps/sim/app/api/tools/crowdstrike/query/operations.ts b/apps/sim/app/api/tools/crowdstrike/query/operations.ts new file mode 100644 index 00000000000..f712dbf4505 --- /dev/null +++ b/apps/sim/app/api/tools/crowdstrike/query/operations.ts @@ -0,0 +1,626 @@ +import type { CrowdstrikeQueryBody } from '@/lib/api/contracts/tools/crowdstrike' +import { + type CrowdStrikeCallResult, + callCrowdStrike, + getBoolean, + getCursorPagination, + getEnvelopeErrors, + getFalconErrorMessage, + getFirstRecordResource, + getNumber, + getPagination, + getRecordResources, + getSpotlightPagination, + getString, + getStringResources, +} from '@/app/api/tools/crowdstrike/query/falcon' +import { + normalizeAffectedEntity, + normalizeAlert, + normalizeCase, + normalizeHostGroup, + normalizeIndicator, + normalizeVulnerability, +} from '@/app/api/tools/crowdstrike/query/normalize' +import type { CrowdStrikeActionParameter } from '@/tools/crowdstrike/types' + +type ExtendedOperation = Exclude< + CrowdstrikeQueryBody['operation'], + | 'crowdstrike_query_sensors' + | 'crowdstrike_get_sensor_details' + | 'crowdstrike_get_sensor_aggregates' +> + +type ExtendedBody = Extract + +export interface OperationFailure { + ok: false + status: number + error: string +} + +export interface OperationSuccess { + ok: true + output: Record +} + +export type OperationResult = OperationSuccess | OperationFailure + +/** + * CrowdStrike can answer 200 while the envelope carries only errors. Reporting + * that as HTTP 200 would read as a success, so fall back to the per-item error + * code the envelope supplies, and to 502 when it supplies none. + */ +export function failureStatus(result: CrowdStrikeCallResult): number { + if (!result.ok) { + return result.status + } + + const envelopeCode = getEnvelopeErrors(result.data)[0]?.code + if (envelopeCode != null && envelopeCode >= 400 && envelopeCode <= 599) { + return envelopeCode + } + + return 502 +} + +function fail(result: CrowdStrikeCallResult, fallback: string): OperationFailure { + return { + ok: false, + status: failureStatus(result), + error: getFalconErrorMessage(result.data, fallback), + } +} + +/** + * CrowdStrike answers 200 with a populated `errors` array when only some IDs + * fail. Treat that as an outright failure only when nothing came back at all. + */ +export function failedWithoutResources( + result: CrowdStrikeCallResult, + resourceCount: number +): boolean { + return resourceCount === 0 && getEnvelopeErrors(result.data).length > 0 +} + +function buildAlertActionParameters( + body: Extract +) { + const parameters: CrowdStrikeActionParameter[] = [] + + const push = (name: string, value: string | undefined) => { + if (value !== undefined) { + parameters.push({ name, value }) + } + } + + push('update_status', body.updateStatus) + push('assign_to_uuid', body.assignToUuid) + push('assign_to_user_id', body.assignToUserId) + push('assign_to_name', body.assignToName) + push('append_comment', body.appendComment) + push('add_tag', body.addTag) + push('remove_tag', body.removeTag) + push('remove_tags_by_prefix', body.removeTagsByPrefix) + + if (body.unassign === true) { + parameters.push({ name: 'unassign', value: '' }) + } + + if (body.showInUi !== undefined) { + parameters.push({ name: 'show_in_ui', value: String(body.showInUi) }) + } + + for (const parameter of body.actionParameters ?? []) { + parameters.push({ name: parameter.name, value: parameter.value }) + } + + return parameters +} + +/** + * CrowdStrike's host-group action endpoint selects the hosts to add or remove + * with an FQL `device_id` filter rather than an ID list. + */ +function buildDeviceIdFilter(deviceIds: string[]): string { + const values = deviceIds.map((id) => `'${id.replaceAll("'", "\\'")}'`).join(',') + return `(device_id:[${values}])` +} + +export async function executeCrowdStrikeOperation( + body: ExtendedBody, + baseUrl: string, + accessToken: string +): Promise { + switch (body.operation) { + case 'crowdstrike_query_alerts': { + const result = await callCrowdStrike(baseUrl, accessToken, { + method: 'GET', + path: '/alerts/queries/alerts/v2', + query: { + filter: body.filter, + include_hidden: body.includeHidden, + limit: body.limit, + offset: body.offset, + q: body.q, + sort: body.sort, + }, + }) + if (!result.ok) return fail(result, 'Failed to query CrowdStrike alerts') + + const alertIds = getStringResources(result.data) + if (failedWithoutResources(result, alertIds.length)) { + return fail(result, 'Failed to query CrowdStrike alerts') + } + + return { + ok: true, + output: { alertIds, count: alertIds.length, pagination: getPagination(result.data) }, + } + } + + case 'crowdstrike_get_alert_details': { + const result = await callCrowdStrike(baseUrl, accessToken, { + method: 'POST', + path: '/alerts/entities/alerts/v2', + query: { include_hidden: body.includeHidden }, + body: { composite_ids: body.compositeIds }, + }) + if (!result.ok) return fail(result, 'Failed to fetch CrowdStrike alert details') + + const alerts = getRecordResources(result.data).map(normalizeAlert) + if (failedWithoutResources(result, alerts.length)) { + return fail(result, 'Failed to fetch CrowdStrike alert details') + } + + return { + ok: true, + output: { alerts, count: alerts.length, errors: getEnvelopeErrors(result.data) }, + } + } + + case 'crowdstrike_update_alerts': { + const result = await callCrowdStrike(baseUrl, accessToken, { + method: 'PATCH', + path: '/alerts/entities/alerts/v3', + query: { include_hidden: body.includeHidden }, + body: { + action_parameters: buildAlertActionParameters(body), + composite_ids: body.compositeIds, + }, + }) + if (!result.ok) return fail(result, 'Failed to update CrowdStrike alerts') + + const errors = getEnvelopeErrors(result.data) + if (errors.length > 0) { + return fail(result, 'Failed to update CrowdStrike alerts') + } + + return { + ok: true, + output: { updatedIds: body.compositeIds, count: body.compositeIds.length, errors }, + } + } + + case 'crowdstrike_perform_host_action': { + const result = await callCrowdStrike(baseUrl, accessToken, { + method: 'POST', + path: '/devices/entities/devices-actions/v2', + query: { action_name: body.actionName }, + body: { ids: body.deviceIds }, + }) + if (!result.ok) return fail(result, 'Failed to perform CrowdStrike host action') + + const affected = getRecordResources(result.data).map(normalizeAffectedEntity) + if (failedWithoutResources(result, affected.length)) { + return fail(result, 'Failed to perform CrowdStrike host action') + } + + return { + ok: true, + output: { affected, count: affected.length, errors: getEnvelopeErrors(result.data) }, + } + } + + case 'crowdstrike_query_host_groups': { + const result = await callCrowdStrike(baseUrl, accessToken, { + method: 'GET', + path: '/devices/queries/host-groups/v1', + query: { + filter: body.filter, + limit: body.limit, + offset: body.offset, + sort: body.sort, + }, + }) + if (!result.ok) return fail(result, 'Failed to query CrowdStrike host groups') + + const hostGroupIds = getStringResources(result.data) + if (failedWithoutResources(result, hostGroupIds.length)) { + return fail(result, 'Failed to query CrowdStrike host groups') + } + + return { + ok: true, + output: { + hostGroupIds, + count: hostGroupIds.length, + pagination: getPagination(result.data), + }, + } + } + + case 'crowdstrike_get_host_group_details': { + const result = await callCrowdStrike(baseUrl, accessToken, { + method: 'GET', + path: '/devices/entities/host-groups/v1', + repeatedQuery: { ids: body.hostGroupIds }, + }) + if (!result.ok) return fail(result, 'Failed to fetch CrowdStrike host group details') + + const hostGroups = getRecordResources(result.data).map(normalizeHostGroup) + if (failedWithoutResources(result, hostGroups.length)) { + return fail(result, 'Failed to fetch CrowdStrike host group details') + } + + return { + ok: true, + output: { + hostGroups, + count: hostGroups.length, + errors: getEnvelopeErrors(result.data), + }, + } + } + + case 'crowdstrike_perform_host_group_action': { + const result = await callCrowdStrike(baseUrl, accessToken, { + method: 'POST', + path: '/devices/entities/host-group-actions/v1', + query: { action_name: body.actionName }, + body: { + action_parameters: [{ name: 'filter', value: buildDeviceIdFilter(body.deviceIds) }], + ids: [body.hostGroupId], + }, + }) + if (!result.ok) return fail(result, 'Failed to perform CrowdStrike host group action') + + const hostGroups = getRecordResources(result.data).map(normalizeHostGroup) + if (failedWithoutResources(result, hostGroups.length)) { + return fail(result, 'Failed to perform CrowdStrike host group action') + } + + return { + ok: true, + output: { + hostGroups, + count: hostGroups.length, + errors: getEnvelopeErrors(result.data), + }, + } + } + + case 'crowdstrike_query_indicators': { + const result = await callCrowdStrike(baseUrl, accessToken, { + method: 'GET', + path: '/iocs/queries/indicators/v1', + query: { + after: body.after, + filter: body.filter, + limit: body.limit, + offset: body.offset, + sort: body.sort, + }, + }) + if (!result.ok) return fail(result, 'Failed to query CrowdStrike indicators') + + const indicatorIds = getStringResources(result.data) + if (failedWithoutResources(result, indicatorIds.length)) { + return fail(result, 'Failed to query CrowdStrike indicators') + } + + return { + ok: true, + output: { + indicatorIds, + count: indicatorIds.length, + pagination: getCursorPagination(result.data), + }, + } + } + + case 'crowdstrike_get_indicator_details': { + const result = await callCrowdStrike(baseUrl, accessToken, { + method: 'GET', + path: '/iocs/entities/indicators/v1', + repeatedQuery: { ids: body.indicatorIds }, + }) + if (!result.ok) return fail(result, 'Failed to fetch CrowdStrike indicator details') + + const indicators = getRecordResources(result.data).map(normalizeIndicator) + if (failedWithoutResources(result, indicators.length)) { + return fail(result, 'Failed to fetch CrowdStrike indicator details') + } + + return { + ok: true, + output: { + indicators, + count: indicators.length, + errors: getEnvelopeErrors(result.data), + }, + } + } + + case 'crowdstrike_create_indicators': + case 'crowdstrike_update_indicators': { + const isCreate = body.operation === 'crowdstrike_create_indicators' + const result = await callCrowdStrike(baseUrl, accessToken, { + method: isCreate ? 'POST' : 'PATCH', + path: '/iocs/entities/indicators/v1', + query: { + ignore_warnings: body.ignoreWarnings, + retrodetects: body.retrodetects, + }, + body: { + comment: body.comment, + indicators: body.indicators, + }, + }) + if (!result.ok) { + return fail( + result, + isCreate + ? 'Failed to create CrowdStrike indicators' + : 'Failed to update CrowdStrike indicators' + ) + } + + const indicators = getRecordResources(result.data).map(normalizeIndicator) + if (failedWithoutResources(result, indicators.length)) { + return fail( + result, + isCreate + ? 'Failed to create CrowdStrike indicators' + : 'Failed to update CrowdStrike indicators' + ) + } + + return { + ok: true, + output: { + indicators, + count: indicators.length, + errors: getEnvelopeErrors(result.data), + }, + } + } + + case 'crowdstrike_delete_indicators': { + const result = await callCrowdStrike(baseUrl, accessToken, { + method: 'DELETE', + path: '/iocs/entities/indicators/v1', + query: { comment: body.comment, filter: body.filter }, + repeatedQuery: { ids: body.filter ? undefined : body.indicatorIds }, + }) + if (!result.ok) return fail(result, 'Failed to delete CrowdStrike indicators') + + const deletedIds = getStringResources(result.data) + if (failedWithoutResources(result, deletedIds.length)) { + return fail(result, 'Failed to delete CrowdStrike indicators') + } + + return { + ok: true, + output: { + deletedIds, + count: deletedIds.length, + errors: getEnvelopeErrors(result.data), + }, + } + } + + case 'crowdstrike_query_vulnerabilities': { + const result = await callCrowdStrike(baseUrl, accessToken, { + method: 'GET', + path: '/spotlight/queries/vulnerabilities/v1', + query: { + after: body.after, + filter: body.filter, + limit: body.limit, + sort: body.sort, + }, + }) + if (!result.ok) return fail(result, 'Failed to query CrowdStrike vulnerabilities') + + const vulnerabilityIds = getStringResources(result.data) + if (failedWithoutResources(result, vulnerabilityIds.length)) { + return fail(result, 'Failed to query CrowdStrike vulnerabilities') + } + + return { + ok: true, + output: { + vulnerabilityIds, + count: vulnerabilityIds.length, + pagination: getSpotlightPagination(result.data), + }, + } + } + + case 'crowdstrike_get_vulnerability_details': { + const result = await callCrowdStrike(baseUrl, accessToken, { + method: 'GET', + path: '/spotlight/entities/vulnerabilities/v2', + repeatedQuery: { ids: body.vulnerabilityIds }, + }) + if (!result.ok) return fail(result, 'Failed to fetch CrowdStrike vulnerability details') + + const vulnerabilities = getRecordResources(result.data).map(normalizeVulnerability) + if (failedWithoutResources(result, vulnerabilities.length)) { + return fail(result, 'Failed to fetch CrowdStrike vulnerability details') + } + + return { + ok: true, + output: { + vulnerabilities, + count: vulnerabilities.length, + errors: getEnvelopeErrors(result.data), + }, + } + } + + case 'crowdstrike_init_rtr_session': { + const result = await callCrowdStrike(baseUrl, accessToken, { + method: 'POST', + path: '/real-time-response/entities/sessions/v1', + body: { + device_id: body.deviceId, + origin: body.origin, + queue_offline: body.queueOffline, + }, + }) + if (!result.ok) return fail(result, 'Failed to initialize CrowdStrike RTR session') + + const session = getFirstRecordResource(result.data) + if (!session) return fail(result, 'CrowdStrike did not return an RTR session') + + return { + ok: true, + output: { + sessionId: getString(session.session_id), + deviceId: getString(session.device_id), + platform: getString(session.platform), + pwd: getString(session.pwd), + offlineQueued: getBoolean(session.offline_queued), + existingAidSessions: getNumber(session.existing_aid_sessions), + createdAt: getString(session.created_at), + errors: getEnvelopeErrors(result.data), + }, + } + } + + case 'crowdstrike_execute_rtr_command': { + const result = await callCrowdStrike(baseUrl, accessToken, { + method: 'POST', + path: '/real-time-response/entities/command/v1', + body: { + base_command: body.baseCommand, + command_string: body.commandString, + session_id: body.sessionId, + }, + }) + if (!result.ok) return fail(result, 'Failed to execute CrowdStrike RTR command') + + const command = getFirstRecordResource(result.data) + if (!command) return fail(result, 'CrowdStrike did not return an RTR command result') + + return { + ok: true, + output: { + cloudRequestId: getString(command.cloud_request_id), + sessionId: getString(command.session_id), + queuedCommandOffline: getBoolean(command.queued_command_offline), + errors: getEnvelopeErrors(result.data), + }, + } + } + + case 'crowdstrike_get_rtr_command_status': { + const result = await callCrowdStrike(baseUrl, accessToken, { + method: 'GET', + path: '/real-time-response/entities/command/v1', + query: { + cloud_request_id: body.cloudRequestId, + sequence_id: body.sequenceId ?? 0, + }, + }) + if (!result.ok) return fail(result, 'Failed to fetch CrowdStrike RTR command status') + + const status = getFirstRecordResource(result.data) + if (!status) return fail(result, 'CrowdStrike did not return an RTR command status') + + return { + ok: true, + output: { + complete: getBoolean(status.complete), + stdout: getString(status.stdout), + stderr: getString(status.stderr), + baseCommand: getString(status.base_command), + sessionId: getString(status.session_id), + taskId: getString(status.task_id), + sequenceId: getNumber(status.sequence_id), + errors: getEnvelopeErrors(result.data), + }, + } + } + + case 'crowdstrike_delete_rtr_session': { + const result = await callCrowdStrike(baseUrl, accessToken, { + method: 'DELETE', + path: '/real-time-response/entities/sessions/v1', + query: { session_id: body.sessionId }, + }) + if (!result.ok) return fail(result, 'Failed to delete CrowdStrike RTR session') + + const deleteErrors = getEnvelopeErrors(result.data) + if (deleteErrors.length > 0) { + return fail(result, 'Failed to delete CrowdStrike RTR session') + } + + return { + ok: true, + output: { + sessionId: body.sessionId, + deleted: true, + errors: deleteErrors, + }, + } + } + + case 'crowdstrike_query_cases': { + const result = await callCrowdStrike(baseUrl, accessToken, { + method: 'GET', + path: '/cases/queries/cases/v1', + query: { + filter: body.filter, + limit: body.limit, + offset: body.offset, + q: body.q, + sort: body.sort, + }, + }) + if (!result.ok) return fail(result, 'Failed to query CrowdStrike cases') + + const caseIds = getStringResources(result.data) + if (failedWithoutResources(result, caseIds.length)) { + return fail(result, 'Failed to query CrowdStrike cases') + } + + return { + ok: true, + output: { caseIds, count: caseIds.length, pagination: getPagination(result.data) }, + } + } + + case 'crowdstrike_get_case_details': { + const result = await callCrowdStrike(baseUrl, accessToken, { + method: 'POST', + path: '/cases/entities/cases/v2', + body: { ids: body.caseIds }, + }) + if (!result.ok) return fail(result, 'Failed to fetch CrowdStrike case details') + + const cases = getRecordResources(result.data).map(normalizeCase) + if (failedWithoutResources(result, cases.length)) { + return fail(result, 'Failed to fetch CrowdStrike case details') + } + + return { + ok: true, + output: { cases, count: cases.length, errors: getEnvelopeErrors(result.data) }, + } + } + } +} diff --git a/apps/sim/app/api/tools/crowdstrike/query/route.test.ts b/apps/sim/app/api/tools/crowdstrike/query/route.test.ts index 39aa92dd783..634ff43f649 100644 --- a/apps/sim/app/api/tools/crowdstrike/query/route.test.ts +++ b/apps/sim/app/api/tools/crowdstrike/query/route.test.ts @@ -113,6 +113,7 @@ describe('CrowdStrike query route', () => { }) expect(data.output).toEqual({ count: 1, + errors: [], pagination: { limit: 1, offset: 0, @@ -153,6 +154,7 @@ describe('CrowdStrike query route', () => { }) expect(data.output).toEqual({ count: 1, + errors: [], pagination: null, sensors: [normalizedSensor], }) @@ -266,6 +268,7 @@ describe('CrowdStrike query route', () => { }, ], count: 1, + errors: [], }) }) }) diff --git a/apps/sim/app/api/tools/crowdstrike/query/route.ts b/apps/sim/app/api/tools/crowdstrike/query/route.ts index 218695f8601..ed502f38521 100644 --- a/apps/sim/app/api/tools/crowdstrike/query/route.ts +++ b/apps/sim/app/api/tools/crowdstrike/query/route.ts @@ -1,187 +1,38 @@ import { createLogger } from '@sim/logger' import { toError } from '@sim/utils/errors' -import { generateId } from '@sim/utils/id' -import { isRecordLike } from '@sim/utils/object' import { type NextRequest, NextResponse } from 'next/server' import { crowdstrikeQueryContract } from '@/lib/api/contracts/tools/crowdstrike' import { getValidationErrorMessage, parseRequest } from '@/lib/api/server' import { checkInternalAuth } from '@/lib/auth/hybrid' import { withRouteHandler } from '@/lib/core/utils/with-route-handler' +import { + type CrowdStrikeCallResult, + callCrowdStrike, + getAccessToken, + getCloudBaseUrl, + getEnvelopeErrors, + getFalconErrorMessage, + getNumber, + getPagination, + getRecordArray, + getRecordResources, + getString, + getStringArray, + getStringResources, + type JsonRecord, +} from '@/app/api/tools/crowdstrike/query/falcon' +import { + executeCrowdStrikeOperation, + failedWithoutResources, + failureStatus, +} from '@/app/api/tools/crowdstrike/query/operations' import type { - CrowdStrikeAggregateQuery, - CrowdStrikeBaseParams, - CrowdStrikeCloud, CrowdStrikeQuerySensorsParams, CrowdStrikeSensorAggregateBucket, CrowdStrikeSensorAggregateResult, } from '@/tools/crowdstrike/types' -const logger = createLogger('CrowdStrikeIdentityProtectionAPI') - -type JsonRecord = Record - -function getCloudBaseUrl(cloud: CrowdStrikeCloud): string { - const cloudMap: Record = { - 'eu-1': 'https://api.eu-1.crowdstrike.com', - 'us-1': 'https://api.crowdstrike.com', - 'us-2': 'https://api.us-2.crowdstrike.com', - 'us-gov-1': 'https://api.laggar.gcw.crowdstrike.com', - 'us-gov-2': 'https://api.us-gov-2.crowdstrike.mil', - } - - return cloudMap[cloud] -} - -function getString(value: unknown): string | null { - return typeof value === 'string' ? value : null -} - -function getNumber(value: unknown): number | null { - return typeof value === 'number' ? value : null -} - -function getStringArray(value: unknown): string[] { - if (!Array.isArray(value)) { - return [] - } - - return value.filter((entry): entry is string => typeof entry === 'string') -} - -function getRecordArray(value: unknown): JsonRecord[] { - if (!Array.isArray(value)) { - return [] - } - - return value.filter(isRecordLike) -} - -function getResourcesArray(data: unknown): unknown[] { - const root = getResponseRoot(data) - if (!isRecordLike(root) || !Array.isArray(root.resources)) { - return [] - } - - return root.resources -} - -function getRecordResources(data: unknown): JsonRecord[] { - return getResourcesArray(data).filter(isRecordLike) -} - -function getStringResources(data: unknown): string[] { - return getStringArray(getResourcesArray(data)) -} - -function getResponseRoot(data: unknown): unknown { - if (!isRecordLike(data)) { - return null - } - - if (isRecordLike(data.body)) { - return data.body - } - - return data -} - -function getPagination(data: unknown) { - const root = getResponseRoot(data) - if (!isRecordLike(root) || !isRecordLike(root.meta) || !isRecordLike(root.meta.pagination)) { - return null - } - - return { - limit: getNumber(root.meta.pagination.limit), - offset: getNumber(root.meta.pagination.offset), - total: getNumber(root.meta.pagination.total), - } -} - -function getErrorMessage(data: unknown, fallback: string): string { - if (!isRecordLike(data)) { - return fallback - } - - const errors = Array.isArray(data.errors) ? data.errors : [] - const firstError = errors[0] - if (isRecordLike(firstError)) { - const firstMessage = getString(firstError.message) ?? getString(firstError.code) - if (firstMessage) { - return firstMessage - } - } - - return ( - getString(data.message) ?? - getString(data.error_description) ?? - getString(data.error) ?? - fallback - ) -} - -function buildQueryUrl(baseUrl: string, params: CrowdStrikeQuerySensorsParams): string { - const url = new URL(baseUrl) - url.pathname = '/identity-protection/queries/devices/v1' - - if (params.filter) { - url.searchParams.set('filter', params.filter) - } - - if (params.limit != null) { - url.searchParams.set('limit', params.limit.toString()) - } - - if (params.offset != null) { - url.searchParams.set('offset', params.offset.toString()) - } - - if (params.sort) { - url.searchParams.set('sort', params.sort) - } - - return url.toString() -} - -function buildSensorDetailsUrl(baseUrl: string): string { - const url = new URL(baseUrl) - url.pathname = '/identity-protection/entities/devices/GET/v1' - return url.toString() -} - -function buildSensorAggregatesUrl(baseUrl: string): string { - const url = new URL(baseUrl) - url.pathname = '/identity-protection/aggregates/devices/GET/v1' - return url.toString() -} - -async function getAccessToken(params: CrowdStrikeBaseParams): Promise { - const baseUrl = getCloudBaseUrl(params.cloud) - const response = await fetch(`${baseUrl}/oauth2/token`, { - method: 'POST', - headers: { - Accept: 'application/json', - 'Content-Type': 'application/x-www-form-urlencoded', - }, - body: new URLSearchParams({ - client_id: params.clientId, - client_secret: params.clientSecret, - grant_type: 'client_credentials', - }).toString(), - cache: 'no-store', - }) - - const data: unknown = await response.json().catch(() => null) - if (!response.ok) { - throw new Error(getErrorMessage(data, 'Failed to authenticate with CrowdStrike')) - } - - if (!isRecordLike(data) || typeof data.access_token !== 'string') { - throw new Error('CrowdStrike authentication did not return an access token') - } - - return data.access_token -} +const logger = createLogger('CrowdStrikeAPI') function normalizeSensor(resource: JsonRecord) { return { @@ -212,11 +63,32 @@ function normalizeSensorsOutput(data: unknown, paginationData?: unknown) { return { count: sensors.length, + errors: getEnvelopeErrors(data), pagination: paginationData == null ? null : getPagination(paginationData), sensors, } } +/** + * CrowdStrike answers 200 while the envelope carries only errors. Mirrors the + * shared operation executor so the Identity Protection branches cannot report a + * resource-less error envelope as a success. + */ +function envelopeFailureResponse( + result: CrowdStrikeCallResult, + resourceCount: number, + fallback: string +) { + if (!failedWithoutResources(result, resourceCount)) { + return null + } + + return NextResponse.json( + { success: false, error: getFalconErrorMessage(result.data, fallback) }, + { status: failureStatus(result) } + ) +} + function normalizeAggregationResult(resource: JsonRecord): CrowdStrikeSensorAggregateResult { return { buckets: getRecordArray(resource.buckets).map(normalizeAggregationBucket), @@ -231,7 +103,7 @@ function normalizeAggregationBucket(resource: JsonRecord): CrowdStrikeSensorAggr count: getNumber(resource.count), from: getNumber(resource.from), keyAsString: getString(resource.key_as_string), - label: isRecordLike(resource.label) ? resource.label : null, + label: resource.label ?? null, stringFrom: getString(resource.string_from), stringTo: getString(resource.string_to), subAggregates: getRecordArray(resource.sub_aggregates).map(normalizeAggregationResult), @@ -247,29 +119,25 @@ function normalizeAggregatesOutput(data: unknown) { return { aggregates, count: aggregates.length, + errors: getEnvelopeErrors(data), } } -async function postCrowdStrikeJson( - url: string, - accessToken: string, - body: JsonRecord | CrowdStrikeAggregateQuery -) { - return fetch(url, { - method: 'POST', - headers: { - Accept: 'application/json', - Authorization: `Bearer ${accessToken}`, - 'Content-Type': 'application/json', - }, - body: JSON.stringify(body), - cache: 'no-store', - }) +function sensorQuery(params: CrowdStrikeQuerySensorsParams) { + return { + filter: params.filter, + limit: params.limit, + offset: params.offset, + sort: params.sort, + } } +/** + * Special route: this proxies workflow tool calls to CrowdStrike Falcon with the + * caller's own API credentials, so it authenticates through `checkInternalAuth` + * rather than an application use case and uses raw `withRouteHandler`. + */ export const POST = withRouteHandler(async (request: NextRequest) => { - const requestId = generateId().slice(0, 8) - const authResult = await checkInternalAuth(request, { requireWorkflowId: false }) if (!authResult.success) { return NextResponse.json( @@ -300,111 +168,153 @@ export const POST = withRouteHandler(async (request: NextRequest) => { const baseUrl = getCloudBaseUrl(params.cloud) const accessToken = await getAccessToken(params) - logger.info(`[${requestId}] CrowdStrike request`, { + logger.info('CrowdStrike request', { cloud: params.cloud, operation: params.operation, }) if (params.operation === 'crowdstrike_query_sensors') { - const queryResponse = await fetch(buildQueryUrl(baseUrl, params), { + const queryResponse = await callCrowdStrike(baseUrl, accessToken, { method: 'GET', - headers: { - Accept: 'application/json', - Authorization: `Bearer ${accessToken}`, - }, - cache: 'no-store', + path: '/identity-protection/queries/devices/v1', + query: sensorQuery(params), }) - const queryData: unknown = await queryResponse.json().catch(() => null) if (!queryResponse.ok) { return NextResponse.json( { success: false, - error: getErrorMessage(queryData, 'CrowdStrike request failed'), + error: getFalconErrorMessage(queryResponse.data, 'CrowdStrike request failed'), }, { status: queryResponse.status } ) } - const ids = getStringResources(queryData) + const ids = getStringResources(queryResponse.data) + const queryFailure = envelopeFailureResponse( + queryResponse, + ids.length, + 'Failed to query CrowdStrike sensors' + ) + if (queryFailure) return queryFailure + if (ids.length === 0) { return NextResponse.json({ success: true, - output: normalizeSensorsOutput({ resources: [] }, queryData), + output: normalizeSensorsOutput({ resources: [] }, queryResponse.data), }) } - const detailResponse = await postCrowdStrikeJson( - buildSensorDetailsUrl(baseUrl), - accessToken, - { ids } - ) + const detailResponse = await callCrowdStrike(baseUrl, accessToken, { + method: 'POST', + path: '/identity-protection/entities/devices/GET/v1', + body: { ids }, + }) - const detailData: unknown = await detailResponse.json().catch(() => null) if (!detailResponse.ok) { return NextResponse.json( { success: false, - error: getErrorMessage(detailData, 'Failed to fetch CrowdStrike sensor details'), + error: getFalconErrorMessage( + detailResponse.data, + 'Failed to fetch CrowdStrike sensor details' + ), }, { status: detailResponse.status } ) } + const detailFailure = envelopeFailureResponse( + detailResponse, + getRecordResources(detailResponse.data).length, + 'Failed to fetch CrowdStrike sensor details' + ) + if (detailFailure) return detailFailure + return NextResponse.json({ success: true, - output: normalizeSensorsOutput(detailData, queryData), + output: normalizeSensorsOutput(detailResponse.data, queryResponse.data), }) } if (params.operation === 'crowdstrike_get_sensor_details') { - const detailResponse = await postCrowdStrikeJson( - buildSensorDetailsUrl(baseUrl), - accessToken, - { ids: params.ids } - ) + const detailResponse = await callCrowdStrike(baseUrl, accessToken, { + method: 'POST', + path: '/identity-protection/entities/devices/GET/v1', + body: { ids: params.ids }, + }) - const detailData: unknown = await detailResponse.json().catch(() => null) if (!detailResponse.ok) { return NextResponse.json( { success: false, - error: getErrorMessage(detailData, 'Failed to fetch CrowdStrike sensor details'), + error: getFalconErrorMessage( + detailResponse.data, + 'Failed to fetch CrowdStrike sensor details' + ), }, { status: detailResponse.status } ) } + const detailsFailure = envelopeFailureResponse( + detailResponse, + getRecordResources(detailResponse.data).length, + 'Failed to fetch CrowdStrike sensor details' + ) + if (detailsFailure) return detailsFailure + return NextResponse.json({ success: true, - output: normalizeSensorsOutput(detailData), + output: normalizeSensorsOutput(detailResponse.data), }) } - const aggregateResponse = await postCrowdStrikeJson( - buildSensorAggregatesUrl(baseUrl), - accessToken, - params.aggregateQuery - ) + if (params.operation === 'crowdstrike_get_sensor_aggregates') { + const aggregateResponse = await callCrowdStrike(baseUrl, accessToken, { + method: 'POST', + path: '/identity-protection/aggregates/devices/GET/v1', + body: params.aggregateQuery, + }) + + if (!aggregateResponse.ok) { + return NextResponse.json( + { + success: false, + error: getFalconErrorMessage( + aggregateResponse.data, + 'Failed to fetch CrowdStrike sensor aggregates' + ), + }, + { status: aggregateResponse.status } + ) + } + + const aggregateFailure = envelopeFailureResponse( + aggregateResponse, + getRecordResources(aggregateResponse.data).length, + 'Failed to fetch CrowdStrike sensor aggregates' + ) + if (aggregateFailure) return aggregateFailure - const aggregateData: unknown = await aggregateResponse.json().catch(() => null) - if (!aggregateResponse.ok) { + return NextResponse.json({ + success: true, + output: normalizeAggregatesOutput(aggregateResponse.data), + }) + } + + const result = await executeCrowdStrikeOperation(params, baseUrl, accessToken) + if (!result.ok) { return NextResponse.json( - { - success: false, - error: getErrorMessage(aggregateData, 'Failed to fetch CrowdStrike sensor aggregates'), - }, - { status: aggregateResponse.status } + { success: false, error: result.error }, + { status: result.status || 502 } ) } - return NextResponse.json({ - success: true, - output: normalizeAggregatesOutput(aggregateData), - }) + return NextResponse.json({ success: true, output: result.output }) } catch (error) { const message = toError(error).message - logger.error(`[${requestId}] CrowdStrike request failed`, { error: message }) + logger.error('CrowdStrike request failed', { error: message }) return NextResponse.json({ success: false, error: message }, { status: 500 }) } }) diff --git a/apps/sim/blocks/blocks/crowdstrike.test.ts b/apps/sim/blocks/blocks/crowdstrike.test.ts new file mode 100644 index 00000000000..e8cbfb9b3bc --- /dev/null +++ b/apps/sim/blocks/blocks/crowdstrike.test.ts @@ -0,0 +1,226 @@ +/** + * @vitest-environment node + */ +import fs from 'node:fs' +import path from 'node:path' +import { describe, expect, it } from 'vitest' +import { CrowdStrikeBlock } from '@/blocks/blocks/crowdstrike' + +/** + * `buildToolDescriptionMap` in `scripts/generate-docs.ts` searches only the 600 + * characters that follow a tool's `id:` for its `name:` and `description:`. A + * description whose closing quote falls outside that window does not fail the + * build — it silently publishes as an empty string in `integrations.json` and in + * the generated MDX. + */ +const DOCS_GENERATOR_ID_WINDOW = 600 + +/** Leave headroom so a small wording edit cannot silently cross the window. */ +const DESCRIPTION_SPAN_BUDGET = DOCS_GENERATOR_ID_WINDOW - 40 + +const mapParams = CrowdStrikeBlock.tools.config?.params +if (!mapParams) { + throw new Error('CrowdStrike block must define tools.config.params') +} + +const credentials = { + clientId: 'client-id', + clientSecret: 'client-secret', + cloud: 'us-1', +} + +/** + * The executor merges the mapped params over the raw block inputs + * (`{ ...inputs, ...transformedParams }`), so a key the mapper omits keeps its raw + * subBlock value. Every assertion here runs against the merged result, because a + * mapper-only assertion passes even when the raw value survives onto the wire. + */ +function merge(inputs: Record) { + return { ...inputs, ...mapParams(inputs) } +} + +describe('CrowdStrike block params', () => { + it('drops untouched optional subBlocks instead of forwarding their stored null', () => { + const merged = merge({ + ...credentials, + operation: 'crowdstrike_query_alerts', + filter: null, + q: null, + limit: null, + offset: null, + sort: null, + includeHidden: null, + }) + + expect(merged.filter).toBeUndefined() + expect(merged.q).toBeUndefined() + expect(merged.limit).toBeUndefined() + expect(merged.offset).toBeUndefined() + expect(merged.sort).toBeUndefined() + expect(merged.includeHidden).toBeUndefined() + }) + + it('drops a blank alert update field rather than sending an empty action value', () => { + const merged = merge({ + ...credentials, + operation: 'crowdstrike_update_alerts', + compositeIds: '["cid:aid:alert"]', + updateStatus: 'closed', + assignToUuid: null, + appendComment: '', + addTag: null, + }) + + expect(merged.updateStatus).toBe('closed') + expect(merged.assignToUuid).toBeUndefined() + expect(merged.appendComment).toBeUndefined() + expect(merged.addTag).toBeUndefined() + }) + + it('clears an advanced value left over from another operation', () => { + const merged = merge({ + ...credentials, + operation: 'crowdstrike_init_rtr_session', + deviceId: 'aid-1', + includeHidden: 'true', + q: 'stale free-text search', + after: 'stale-cursor', + updateStatus: 'closed', + }) + + expect(merged.deviceId).toBe('aid-1') + expect(merged.includeHidden).toBeUndefined() + expect(merged.q).toBeUndefined() + expect(merged.after).toBeUndefined() + expect(merged.updateStatus).toBeUndefined() + }) + + it('sends the free-text search only to the operations that accept it', () => { + expect( + merge({ ...credentials, operation: 'crowdstrike_query_alerts', q: 'ransomware' }).q + ).toBe('ransomware') + expect( + merge({ ...credentials, operation: 'crowdstrike_query_host_groups', q: 'ransomware' }).q + ).toBeUndefined() + }) + + it('sends the after cursor only to the cursor-paginated collections', () => { + expect( + merge({ ...credentials, operation: 'crowdstrike_query_indicators', after: 'cursor-1' }).after + ).toBe('cursor-1') + expect( + merge({ ...credentials, operation: 'crowdstrike_query_alerts', after: 'cursor-1' }).after + ).toBeUndefined() + }) + + it('never sends an offset to Spotlight, which paginates by cursor only', () => { + const merged = merge({ + ...credentials, + operation: 'crowdstrike_query_vulnerabilities', + filter: "status:'open'", + offset: '100', + }) + + expect(merged.filter).toBe("status:'open'") + expect(merged.offset).toBeUndefined() + }) + + it('keeps the alert filter out of a destructive indicator delete', () => { + const merged = merge({ + ...credentials, + operation: 'crowdstrike_delete_indicators', + indicatorIds: '["ioc-1"]', + filter: "status:'new'", + deleteFilter: null, + }) + + expect(merged.indicatorIds).toEqual(['ioc-1']) + expect(merged.filter).toBeUndefined() + }) + + it('forwards the dedicated delete filter', () => { + const merged = merge({ + ...credentials, + operation: 'crowdstrike_delete_indicators', + deleteFilter: "type:'sha256'", + }) + + expect(merged.filter).toBe("type:'sha256'") + }) + + it('rejects an IOC limit above the documented maximum of 500', () => { + expect(() => + merge({ ...credentials, operation: 'crowdstrike_query_indicators', limit: '2000' }) + ).toThrow(/500/) + }) + + it('offers only the documented read-tier RTR base command families', () => { + const baseCommand = CrowdStrikeBlock.subBlocks.find((subBlock) => subBlock.id === 'baseCommand') + const ids = (baseCommand?.options as { id: string }[] | undefined)?.map((option) => option.id) + + expect(ids).toEqual([ + 'cat', + 'cd', + 'clear', + 'csrutil', + 'env', + 'eventlog', + 'filehash', + 'getsid', + 'help', + 'history', + 'ipconfig', + 'ls', + 'mount', + 'netstat', + 'ps', + 'reg', + ]) + }) + + it('offers no write-tier RTR base command under the read-scoped tool', () => { + const baseCommand = CrowdStrikeBlock.subBlocks.find((subBlock) => subBlock.id === 'baseCommand') + const ids = (baseCommand?.options as { id: string }[] | undefined)?.map((option) => option.id) + + for (const writeTier of ['eventlog backup', 'eventlog export', 'put', 'get', 'runscript']) { + expect(ids).not.toContain(writeTier) + } + }) + + it('exposes every CrowdStrike commercial and GovCloud region', () => { + const cloud = CrowdStrikeBlock.subBlocks.find((subBlock) => subBlock.id === 'cloud') + const ids = (cloud?.options as { id: string }[] | undefined)?.map((option) => option.id) + + expect(ids).toEqual(['us-1', 'us-2', 'us-3', 'eu-1', 'us-gov-1', 'us-gov-2']) + }) + + it('does not preselect the network-isolating host action', () => { + const hostAction = CrowdStrikeBlock.subBlocks.find( + (subBlock) => subBlock.id === 'hostActionName' + ) + const ids = (hostAction?.options as { id: string }[] | undefined)?.map((option) => option.id) + + expect(hostAction?.value).toBeUndefined() + expect(ids).toContain('detection_suppress') + expect(ids).toContain('detection_unsuppress') + }) + + it('keeps every tool description inside the docs generator id-search window', () => { + const toolsDir = path.join(__dirname, '../../tools/crowdstrike') + const offenders: string[] = [] + + for (const file of fs.readdirSync(toolsDir)) { + if (file === 'index.ts' || file === 'types.ts') continue + const source = fs.readFileSync(path.join(toolsDir, file), 'utf-8') + const idIndex = source.search(/\bid\s*:\s*'crowdstrike_/) + const descriptionEnd = source.indexOf("',", source.indexOf('description:')) + if (idIndex < 0 || descriptionEnd < 0) continue + const span = descriptionEnd + 2 - idIndex + if (span > DESCRIPTION_SPAN_BUDGET) { + offenders.push(`${file} (${span} chars)`) + } + } + + expect(offenders).toEqual([]) + }) +}) diff --git a/apps/sim/blocks/blocks/crowdstrike.ts b/apps/sim/blocks/blocks/crowdstrike.ts index 80bdbc559fa..5759198aa2b 100644 --- a/apps/sim/blocks/blocks/crowdstrike.ts +++ b/apps/sim/blocks/blocks/crowdstrike.ts @@ -1,15 +1,99 @@ import { CrowdStrikeIcon } from '@/components/icons' import type { BlockConfig, BlockMeta } from '@/blocks/types' import { AuthMode, IntegrationType } from '@/blocks/types' -import { parseOptionalJsonInput, parseOptionalNumberInput } from '@/blocks/utils' +import { + parseOptionalBooleanInput, + parseOptionalJsonInput, + parseOptionalNumberInput, +} from '@/blocks/utils' import type { CrowdStrikeResponse } from '@/tools/crowdstrike/types' +/** Documented maximum `limit` for each CrowdStrike query collection. */ +const QUERY_LIMITS: Record = { + crowdstrike_query_sensors: { min: 1, max: 200 }, + crowdstrike_query_alerts: { min: 1, max: 10000 }, + crowdstrike_query_host_groups: { min: 1, max: 5000 }, + crowdstrike_query_indicators: { min: 1, max: 500 }, + crowdstrike_query_vulnerabilities: { min: 1, max: 400 }, + crowdstrike_query_cases: { min: 1, max: 10000 }, +} + +/** Spotlight paginates by cursor only, so it accepts no `offset`. */ +const OFFSET_QUERY_OPERATIONS = new Set([ + 'crowdstrike_query_sensors', + 'crowdstrike_query_alerts', + 'crowdstrike_query_host_groups', + 'crowdstrike_query_indicators', + 'crowdstrike_query_cases', +]) + +/** Only the IOC and Spotlight query endpoints accept an `after` cursor. */ +const CURSOR_QUERY_OPERATIONS = new Set([ + 'crowdstrike_query_indicators', + 'crowdstrike_query_vulnerabilities', +]) + +/** Only Alerts and Case Management accept the free-text `q` parameter. */ +const FREE_TEXT_QUERY_OPERATIONS = new Set(['crowdstrike_query_alerts', 'crowdstrike_query_cases']) + +/** + * Every optional request key the block can produce, pre-cleared to `undefined`. + * The executor merges the mapped params over the raw block inputs, so a key left + * out of the mapped result silently keeps its raw subBlock value. + */ +const CLEARED_OPTIONAL_PARAMS: Record = Object.freeze({ + actionName: undefined, + actionParameters: undefined, + addTag: undefined, + after: undefined, + aggregateQuery: undefined, + appendComment: undefined, + assignToName: undefined, + assignToUserId: undefined, + assignToUuid: undefined, + baseCommand: undefined, + caseIds: undefined, + cloudRequestId: undefined, + commandString: undefined, + comment: undefined, + compositeIds: undefined, + deleteFilter: undefined, + deviceId: undefined, + deviceIds: undefined, + filter: undefined, + hostActionName: undefined, + hostGroupActionName: undefined, + hostGroupId: undefined, + hostGroupIds: undefined, + ids: undefined, + ignoreWarnings: undefined, + includeHidden: undefined, + indicatorIds: undefined, + indicators: undefined, + limit: undefined, + offset: undefined, + origin: undefined, + q: undefined, + queueOffline: undefined, + removeTag: undefined, + removeTagsByPrefix: undefined, + retrodetects: undefined, + sequenceId: undefined, + sessionId: undefined, + showInUi: undefined, + sort: undefined, + unassign: undefined, + updateStatus: undefined, + vulnerabilityIds: undefined, +}) + export const CrowdStrikeBlock: BlockConfig = { type: 'crowdstrike', name: 'CrowdStrike', - description: 'Query CrowdStrike Identity Protection sensors and documented aggregates', + description: + 'Investigate and respond to CrowdStrike Falcon alerts, hosts, IOCs, and vulnerabilities', longDescription: - 'Integrate CrowdStrike Identity Protection into workflows to search sensors, fetch documented sensor details by device ID, and run documented sensor aggregate queries.', + 'Integrate CrowdStrike Falcon into workflows to triage alerts, contain hosts, manage host groups and custom indicators of compromise, review Spotlight vulnerabilities, run read-only Real Time Response commands, read Case Management cases, and query Identity Protection sensors.', docsLink: 'https://docs.sim.ai/integrations/crowdstrike', category: 'tools', integrationType: IntegrationType.Security, @@ -33,6 +117,95 @@ export const CrowdStrikeBlock: BlockConfig = { crowdstrike_get_sensor_aggregates: [ { text: 'Aggregate sensors with', field: 'aggregateQuery', core: true }, ], + crowdstrike_query_alerts: [ + 'Search Falcon alerts', + { text: ', where', field: 'filter' }, + { text: ', matching', field: 'q' }, + { text: ', sorted by', field: 'sort' }, + { text: ', up to', field: 'limit', after: 'results' }, + ], + crowdstrike_get_alert_details: [ + { text: 'Fetch alert details for', field: 'compositeIds', core: true }, + ], + crowdstrike_update_alerts: [ + { text: 'Update alerts', field: 'compositeIds', core: true }, + { text: ', setting status to', field: 'updateStatus' }, + { text: ', assigning to', field: 'assignToUuid' }, + { text: ', commenting', field: 'appendComment' }, + ], + crowdstrike_perform_host_action: [ + { text: 'Run', field: 'hostActionName', core: true }, + { text: 'on hosts', field: 'deviceIds', core: true }, + ], + crowdstrike_query_host_groups: [ + 'Search host groups', + { text: ', where', field: 'filter' }, + { text: ', sorted by', field: 'sort' }, + { text: ', up to', field: 'limit', after: 'results' }, + ], + crowdstrike_get_host_group_details: [ + { text: 'Fetch host group details for', field: 'hostGroupIds', core: true }, + ], + crowdstrike_perform_host_group_action: [ + { text: 'Run', field: 'hostGroupActionName', core: true }, + { text: 'on group', field: 'hostGroupId', core: true }, + { text: 'for hosts', field: 'deviceIds' }, + ], + crowdstrike_query_indicators: [ + 'Search custom indicators', + { text: ', where', field: 'filter' }, + { text: ', sorted by', field: 'sort' }, + { text: ', up to', field: 'limit', after: 'results' }, + ], + crowdstrike_get_indicator_details: [ + { text: 'Fetch indicator details for', field: 'indicatorIds', core: true }, + ], + crowdstrike_create_indicators: [ + { text: 'Create indicators', field: 'indicators', core: true }, + { text: ', noting', field: 'comment' }, + ], + crowdstrike_update_indicators: [ + { text: 'Update indicators', field: 'indicators', core: true }, + { text: ', noting', field: 'comment' }, + ], + crowdstrike_delete_indicators: [ + 'Delete custom indicators', + { text: 'with IDs', field: 'indicatorIds' }, + { text: ', matching', field: 'deleteFilter' }, + { text: ', noting', field: 'comment' }, + ], + crowdstrike_query_vulnerabilities: [ + { text: 'Search Spotlight vulnerabilities where', field: 'filter', core: true }, + { text: ', sorted by', field: 'sort' }, + { text: ', up to', field: 'limit', after: 'results' }, + ], + crowdstrike_get_vulnerability_details: [ + { text: 'Fetch vulnerability details for', field: 'vulnerabilityIds', core: true }, + ], + crowdstrike_init_rtr_session: [ + { text: 'Open a Real Time Response session on', field: 'deviceId', core: true }, + ], + crowdstrike_execute_rtr_command: [ + { text: 'Run', field: 'commandString', core: true }, + { text: 'in session', field: 'sessionId', core: true }, + ], + crowdstrike_get_rtr_command_status: [ + { text: 'Check command', field: 'cloudRequestId', core: true }, + { text: ', chunk', field: 'sequenceId' }, + ], + crowdstrike_delete_rtr_session: [ + { text: 'Close Real Time Response session', field: 'sessionId', core: true }, + ], + crowdstrike_query_cases: [ + 'Search cases', + { text: ', where', field: 'filter' }, + { text: ', matching', field: 'q' }, + { text: ', sorted by', field: 'sort' }, + { text: ', up to', field: 'limit', after: 'results' }, + ], + crowdstrike_get_case_details: [ + { text: 'Fetch case details for', field: 'caseIds', core: true }, + ], }, }, }, @@ -43,11 +216,31 @@ export const CrowdStrikeBlock: BlockConfig = { title: 'Operation', type: 'dropdown', options: [ + { label: 'Query Alerts', id: 'crowdstrike_query_alerts' }, + { label: 'Get Alert Details', id: 'crowdstrike_get_alert_details' }, + { label: 'Update Alerts', id: 'crowdstrike_update_alerts' }, + { label: 'Perform Host Action', id: 'crowdstrike_perform_host_action' }, + { label: 'Query Host Groups', id: 'crowdstrike_query_host_groups' }, + { label: 'Get Host Group Details', id: 'crowdstrike_get_host_group_details' }, + { label: 'Perform Host Group Action', id: 'crowdstrike_perform_host_group_action' }, + { label: 'Query Indicators', id: 'crowdstrike_query_indicators' }, + { label: 'Get Indicator Details', id: 'crowdstrike_get_indicator_details' }, + { label: 'Create Indicators', id: 'crowdstrike_create_indicators' }, + { label: 'Update Indicators', id: 'crowdstrike_update_indicators' }, + { label: 'Delete Indicators', id: 'crowdstrike_delete_indicators' }, + { label: 'Query Vulnerabilities', id: 'crowdstrike_query_vulnerabilities' }, + { label: 'Get Vulnerability Details', id: 'crowdstrike_get_vulnerability_details' }, + { label: 'Init RTR Session', id: 'crowdstrike_init_rtr_session' }, + { label: 'Execute RTR Command', id: 'crowdstrike_execute_rtr_command' }, + { label: 'Get RTR Command Status', id: 'crowdstrike_get_rtr_command_status' }, + { label: 'Delete RTR Session', id: 'crowdstrike_delete_rtr_session' }, + { label: 'Query Cases', id: 'crowdstrike_query_cases' }, + { label: 'Get Case Details', id: 'crowdstrike_get_case_details' }, { label: 'Query Sensors', id: 'crowdstrike_query_sensors' }, { label: 'Get Sensor Details', id: 'crowdstrike_get_sensor_details' }, { label: 'Get Sensor Aggregates', id: 'crowdstrike_get_sensor_aggregates' }, ], - value: () => 'crowdstrike_query_sensors', + value: () => 'crowdstrike_query_alerts', required: true, }, { @@ -72,6 +265,7 @@ export const CrowdStrikeBlock: BlockConfig = { options: [ { label: 'US-1', id: 'us-1' }, { label: 'US-2', id: 'us-2' }, + { label: 'US-3', id: 'us-3' }, { label: 'EU-1', id: 'eu-1' }, { label: 'US-GOV-1', id: 'us-gov-1' }, { label: 'US-GOV-2', id: 'us-gov-2' }, @@ -83,22 +277,54 @@ export const CrowdStrikeBlock: BlockConfig = { id: 'filter', title: 'Filter', type: 'short-input', - placeholder: 'hostname:"server-01" or status:"protected"', - condition: { field: 'operation', value: 'crowdstrike_query_sensors' }, + placeholder: 'status:"new"+severity:>70', + condition: { + field: 'operation', + value: [ + 'crowdstrike_query_sensors', + 'crowdstrike_query_alerts', + 'crowdstrike_query_host_groups', + 'crowdstrike_query_indicators', + 'crowdstrike_query_vulnerabilities', + 'crowdstrike_query_cases', + ], + }, + required: { field: 'operation', value: 'crowdstrike_query_vulnerabilities' }, wandConfig: { enabled: true, prompt: - 'Generate a CrowdStrike Identity Protection Falcon Query Language filter string for sensor search. Use exact field names, operators, and values only. Return ONLY the filter string - no explanations, no extra text.', + 'Generate a CrowdStrike Falcon Query Language (FQL) filter string for the selected CrowdStrike collection. Use exact field names, operators, and values only. Return ONLY the filter string - no explanations, no extra text.', placeholder: - 'Describe the sensors you want to search, for example "sensors with hostnames starting with web" or "sensors with protected status"...', + 'Describe what you want to match, for example "new alerts with severity above 70" or "open vulnerabilities with a CISA KEV CVE"...', }, }, + { + id: 'q', + title: 'Search', + type: 'short-input', + placeholder: 'Free-text metadata search', + condition: { + field: 'operation', + value: ['crowdstrike_query_alerts', 'crowdstrike_query_cases'], + }, + mode: 'advanced', + }, { id: 'limit', title: 'Limit', type: 'short-input', placeholder: '100', - condition: { field: 'operation', value: 'crowdstrike_query_sensors' }, + condition: { + field: 'operation', + value: [ + 'crowdstrike_query_sensors', + 'crowdstrike_query_alerts', + 'crowdstrike_query_host_groups', + 'crowdstrike_query_indicators', + 'crowdstrike_query_vulnerabilities', + 'crowdstrike_query_cases', + ], + }, mode: 'advanced', }, { @@ -106,17 +332,413 @@ export const CrowdStrikeBlock: BlockConfig = { title: 'Offset', type: 'short-input', placeholder: '0', - condition: { field: 'operation', value: 'crowdstrike_query_sensors' }, + condition: { + field: 'operation', + value: [ + 'crowdstrike_query_sensors', + 'crowdstrike_query_alerts', + 'crowdstrike_query_host_groups', + 'crowdstrike_query_indicators', + 'crowdstrike_query_cases', + ], + }, + mode: 'advanced', + }, + { + id: 'after', + title: 'After Cursor', + type: 'short-input', + placeholder: 'Cursor from the previous page', + condition: { + field: 'operation', + value: ['crowdstrike_query_indicators', 'crowdstrike_query_vulnerabilities'], + }, mode: 'advanced', }, { id: 'sort', title: 'Sort', type: 'short-input', - placeholder: 'status.asc', - condition: { field: 'operation', value: 'crowdstrike_query_sensors' }, + placeholder: 'created_timestamp|desc', + condition: { + field: 'operation', + value: [ + 'crowdstrike_query_sensors', + 'crowdstrike_query_alerts', + 'crowdstrike_query_host_groups', + 'crowdstrike_query_indicators', + 'crowdstrike_query_vulnerabilities', + 'crowdstrike_query_cases', + ], + }, + mode: 'advanced', + }, + { + id: 'includeHidden', + title: 'Include Hidden Alerts', + type: 'switch', + condition: { + field: 'operation', + value: [ + 'crowdstrike_query_alerts', + 'crowdstrike_get_alert_details', + 'crowdstrike_update_alerts', + ], + }, + mode: 'advanced', + }, + { + id: 'compositeIds', + title: 'Composite Alert IDs', + type: 'code', + language: 'json', + placeholder: '["cid:aid:alert-id"]', + condition: { + field: 'operation', + value: ['crowdstrike_get_alert_details', 'crowdstrike_update_alerts'], + }, + required: { + field: 'operation', + value: ['crowdstrike_get_alert_details', 'crowdstrike_update_alerts'], + }, + }, + { + id: 'updateStatus', + title: 'Status', + type: 'dropdown', + options: [ + { label: 'New', id: 'new' }, + { label: 'In Progress', id: 'in_progress' }, + { label: 'Reopened', id: 'reopened' }, + { label: 'Closed', id: 'closed' }, + ], + condition: { field: 'operation', value: 'crowdstrike_update_alerts' }, + }, + { + id: 'assignToUuid', + title: 'Assign To UUID', + type: 'short-input', + placeholder: '00000000-0000-0000-0000-000000000000', + condition: { field: 'operation', value: 'crowdstrike_update_alerts' }, + }, + { + id: 'assignToUserId', + title: 'Assign To User ID', + type: 'short-input', + placeholder: 'analyst@example.com', + condition: { field: 'operation', value: 'crowdstrike_update_alerts' }, mode: 'advanced', }, + { + id: 'assignToName', + title: 'Assign To Name', + type: 'short-input', + placeholder: 'Jane Doe', + condition: { field: 'operation', value: 'crowdstrike_update_alerts' }, + mode: 'advanced', + }, + { + id: 'unassign', + title: 'Unassign', + type: 'switch', + condition: { field: 'operation', value: 'crowdstrike_update_alerts' }, + mode: 'advanced', + }, + { + id: 'appendComment', + title: 'Comment', + type: 'long-input', + placeholder: 'Triage note to append to the alert', + condition: { field: 'operation', value: 'crowdstrike_update_alerts' }, + }, + { + id: 'addTag', + title: 'Add Tag', + type: 'short-input', + placeholder: 'triaged', + condition: { field: 'operation', value: 'crowdstrike_update_alerts' }, + mode: 'advanced', + }, + { + id: 'removeTag', + title: 'Remove Tag', + type: 'short-input', + placeholder: 'needs-review', + condition: { field: 'operation', value: 'crowdstrike_update_alerts' }, + mode: 'advanced', + }, + { + id: 'removeTagsByPrefix', + title: 'Remove Tags By Prefix', + type: 'short-input', + placeholder: 'auto-', + condition: { field: 'operation', value: 'crowdstrike_update_alerts' }, + mode: 'advanced', + }, + { + id: 'showInUi', + title: 'Show In Falcon Console', + type: 'switch', + condition: { field: 'operation', value: 'crowdstrike_update_alerts' }, + mode: 'advanced', + }, + { + id: 'actionParameters', + title: 'Additional Action Parameters', + type: 'code', + language: 'json', + placeholder: '[{ "name": "action_name", "value": "action_value" }]', + condition: { field: 'operation', value: 'crowdstrike_update_alerts' }, + mode: 'advanced', + }, + { + id: 'hostActionName', + title: 'Host Action', + type: 'dropdown', + options: [ + { label: 'Contain (network isolate)', id: 'contain' }, + { label: 'Lift Containment', id: 'lift_containment' }, + { label: 'Hide Host', id: 'hide_host' }, + { label: 'Unhide Host', id: 'unhide_host' }, + { label: 'Suppress Detections', id: 'detection_suppress' }, + { label: 'Unsuppress Detections', id: 'detection_unsuppress' }, + ], + condition: { field: 'operation', value: 'crowdstrike_perform_host_action' }, + required: { field: 'operation', value: 'crowdstrike_perform_host_action' }, + }, + { + id: 'deviceIds', + title: 'Host Agent IDs', + type: 'code', + language: 'json', + placeholder: '["aid-1", "aid-2"]', + condition: { + field: 'operation', + value: ['crowdstrike_perform_host_action', 'crowdstrike_perform_host_group_action'], + }, + required: { + field: 'operation', + value: ['crowdstrike_perform_host_action', 'crowdstrike_perform_host_group_action'], + }, + }, + { + id: 'hostGroupIds', + title: 'Host Group IDs', + type: 'code', + language: 'json', + placeholder: '["host-group-id"]', + condition: { field: 'operation', value: 'crowdstrike_get_host_group_details' }, + required: { field: 'operation', value: 'crowdstrike_get_host_group_details' }, + }, + { + id: 'hostGroupActionName', + title: 'Host Group Action', + type: 'dropdown', + options: [ + { label: 'Add Hosts', id: 'add-hosts' }, + { label: 'Remove Hosts', id: 'remove-hosts' }, + ], + value: () => 'add-hosts', + condition: { field: 'operation', value: 'crowdstrike_perform_host_group_action' }, + required: { field: 'operation', value: 'crowdstrike_perform_host_group_action' }, + }, + { + id: 'hostGroupId', + title: 'Host Group ID', + type: 'short-input', + placeholder: 'Static host group ID', + condition: { field: 'operation', value: 'crowdstrike_perform_host_group_action' }, + required: { field: 'operation', value: 'crowdstrike_perform_host_group_action' }, + }, + { + id: 'indicatorIds', + title: 'Indicator IDs', + type: 'code', + language: 'json', + placeholder: '["ioc-id-1"]', + condition: { + field: 'operation', + value: ['crowdstrike_get_indicator_details', 'crowdstrike_delete_indicators'], + }, + required: { field: 'operation', value: 'crowdstrike_get_indicator_details' }, + }, + { + id: 'deleteFilter', + title: 'Delete Filter', + type: 'short-input', + placeholder: "type:'sha256'+created_on:<'2026-01-01'", + condition: { field: 'operation', value: 'crowdstrike_delete_indicators' }, + wandConfig: { + enabled: true, + prompt: + 'Generate a CrowdStrike IOC Management Falcon Query Language (FQL) filter string that selects the custom indicators to delete. Use exact IOC field names, operators, and values only. Return ONLY the filter string - no explanations, no extra text.', + placeholder: + 'Describe which indicators to delete, for example "every sha256 indicator created before 2026"...', + }, + }, + { + id: 'indicators', + title: 'Indicators', + type: 'code', + language: 'json', + placeholder: + '[\n {\n "type": "sha256",\n "value": "",\n "action": "prevent",\n "severity": "high",\n "platforms": ["windows"],\n "applied_globally": true\n }\n]', + condition: { + field: 'operation', + value: ['crowdstrike_create_indicators', 'crowdstrike_update_indicators'], + }, + required: { + field: 'operation', + value: ['crowdstrike_create_indicators', 'crowdstrike_update_indicators'], + }, + wandConfig: { + enabled: true, + prompt: + 'Generate a JSON array of CrowdStrike IOC Management indicator objects. Documented fields are type, value, action, severity, platforms (array), applied_globally (boolean), host_groups (array), description, source, tags (array), expiration (ISO 8601), mobile_action, and metadata ({ filename }). Updates must include id and cannot change type or value. Return ONLY valid JSON.', + placeholder: + 'Describe the indicators you want, for example "block this SHA256 on Windows hosts globally"...', + generationType: 'json-object', + }, + }, + { + id: 'comment', + title: 'Audit Comment', + type: 'short-input', + placeholder: 'Why this change was made', + condition: { + field: 'operation', + value: [ + 'crowdstrike_create_indicators', + 'crowdstrike_update_indicators', + 'crowdstrike_delete_indicators', + ], + }, + }, + { + id: 'retrodetects', + title: 'Generate Retroactive Detections', + type: 'switch', + condition: { + field: 'operation', + value: ['crowdstrike_create_indicators', 'crowdstrike_update_indicators'], + }, + mode: 'advanced', + }, + { + id: 'ignoreWarnings', + title: 'Ignore Warnings', + type: 'switch', + condition: { + field: 'operation', + value: ['crowdstrike_create_indicators', 'crowdstrike_update_indicators'], + }, + mode: 'advanced', + }, + { + id: 'vulnerabilityIds', + title: 'Vulnerability IDs', + type: 'code', + language: 'json', + placeholder: '["vulnerability-id"]', + condition: { field: 'operation', value: 'crowdstrike_get_vulnerability_details' }, + required: { field: 'operation', value: 'crowdstrike_get_vulnerability_details' }, + }, + { + id: 'deviceId', + title: 'Host Agent ID', + type: 'short-input', + placeholder: 'Agent ID (AID) to connect to', + condition: { field: 'operation', value: 'crowdstrike_init_rtr_session' }, + required: { field: 'operation', value: 'crowdstrike_init_rtr_session' }, + }, + { + id: 'queueOffline', + title: 'Queue If Host Offline', + type: 'switch', + condition: { field: 'operation', value: 'crowdstrike_init_rtr_session' }, + mode: 'advanced', + }, + { + id: 'origin', + title: 'Session Origin', + type: 'short-input', + placeholder: 'Origin label recorded by CrowdStrike', + condition: { field: 'operation', value: 'crowdstrike_init_rtr_session' }, + mode: 'advanced', + }, + { + id: 'sessionId', + title: 'RTR Session ID', + type: 'short-input', + placeholder: 'Session ID from Init RTR Session', + condition: { + field: 'operation', + value: ['crowdstrike_execute_rtr_command', 'crowdstrike_delete_rtr_session'], + }, + required: { + field: 'operation', + value: ['crowdstrike_execute_rtr_command', 'crowdstrike_delete_rtr_session'], + }, + }, + { + id: 'baseCommand', + title: 'Base Command', + type: 'dropdown', + options: [ + { label: 'cat', id: 'cat' }, + { label: 'cd', id: 'cd' }, + { label: 'clear', id: 'clear' }, + { label: 'csrutil (macOS)', id: 'csrutil' }, + { label: 'env', id: 'env' }, + { label: 'eventlog (Windows)', id: 'eventlog' }, + { label: 'filehash', id: 'filehash' }, + { label: 'getsid (Windows, macOS)', id: 'getsid' }, + { label: 'help', id: 'help' }, + { label: 'history', id: 'history' }, + { label: 'ipconfig', id: 'ipconfig' }, + { label: 'ls', id: 'ls' }, + { label: 'mount', id: 'mount' }, + { label: 'netstat', id: 'netstat' }, + { label: 'ps', id: 'ps' }, + { label: 'reg (Windows)', id: 'reg' }, + ], + value: () => 'ls', + condition: { field: 'operation', value: 'crowdstrike_execute_rtr_command' }, + required: { field: 'operation', value: 'crowdstrike_execute_rtr_command' }, + }, + { + id: 'commandString', + title: 'Command', + type: 'short-input', + placeholder: 'ls C:\\Windows\\Temp', + condition: { field: 'operation', value: 'crowdstrike_execute_rtr_command' }, + required: { field: 'operation', value: 'crowdstrike_execute_rtr_command' }, + }, + { + id: 'cloudRequestId', + title: 'Cloud Request ID', + type: 'short-input', + placeholder: 'Cloud request ID from Execute RTR Command', + condition: { field: 'operation', value: 'crowdstrike_get_rtr_command_status' }, + required: { field: 'operation', value: 'crowdstrike_get_rtr_command_status' }, + }, + { + id: 'sequenceId', + title: 'Sequence ID', + type: 'short-input', + placeholder: '0', + condition: { field: 'operation', value: 'crowdstrike_get_rtr_command_status' }, + mode: 'advanced', + }, + { + id: 'caseIds', + title: 'Case IDs', + type: 'code', + language: 'json', + placeholder: '["case-id"]', + condition: { field: 'operation', value: 'crowdstrike_get_case_details' }, + required: { field: 'operation', value: 'crowdstrike_get_case_details' }, + }, { id: 'ids', title: 'Sensor IDs', @@ -148,46 +770,172 @@ export const CrowdStrikeBlock: BlockConfig = { tools: { access: [ + 'crowdstrike_create_indicators', + 'crowdstrike_delete_indicators', + 'crowdstrike_delete_rtr_session', + 'crowdstrike_execute_rtr_command', + 'crowdstrike_get_alert_details', + 'crowdstrike_get_case_details', + 'crowdstrike_get_host_group_details', + 'crowdstrike_get_indicator_details', + 'crowdstrike_get_rtr_command_status', 'crowdstrike_get_sensor_aggregates', 'crowdstrike_get_sensor_details', + 'crowdstrike_get_vulnerability_details', + 'crowdstrike_init_rtr_session', + 'crowdstrike_perform_host_action', + 'crowdstrike_perform_host_group_action', + 'crowdstrike_query_alerts', + 'crowdstrike_query_cases', + 'crowdstrike_query_host_groups', + 'crowdstrike_query_indicators', 'crowdstrike_query_sensors', + 'crowdstrike_query_vulnerabilities', + 'crowdstrike_update_alerts', + 'crowdstrike_update_indicators', ], config: { tool: (params) => - typeof params.operation === 'string' ? params.operation : 'crowdstrike_query_sensors', + typeof params.operation === 'string' ? params.operation : 'crowdstrike_query_alerts', params: (params) => { + const operation = typeof params.operation === 'string' ? params.operation : '' + + /** + * The executor merges this result over the raw block inputs, so a key this + * mapper simply omits keeps the raw subBlock value — and an untouched + * subBlock is stored as `null`, which the route contract rejects. Seeding + * every optional key as `undefined` makes omission authoritative: a blank + * field is dropped, and a value left over from another operation cannot + * ride along on the request. + */ const mapped: Record = { + ...CLEARED_OPTIONAL_PARAMS, clientId: params.clientId, clientSecret: params.clientSecret, cloud: params.cloud, } - if (params.operation === 'crowdstrike_query_sensors') { - if (params.filter) mapped.filter = params.filter + const setString = (key: string, value: unknown) => { + mapped[key] = typeof value === 'string' && value.trim().length > 0 ? value : undefined + } + + const setNumber = ( + key: string, + value: unknown, + label: string, + bounds: { min?: number; max?: number } + ) => { + mapped[key] = parseOptionalNumberInput(value, label, { integer: true, ...bounds }) + } - const limit = parseOptionalNumberInput(params.limit, 'limit', { - integer: true, - max: 200, - min: 1, - }) - const offset = parseOptionalNumberInput(params.offset, 'offset', { - integer: true, - min: 0, - }) + const setBoolean = (key: string, value: unknown) => { + mapped[key] = parseOptionalBooleanInput(value) + } + + const setJson = (key: string, value: unknown, label: string) => { + mapped[key] = parseOptionalJsonInput(value, label) + } + + const queryLimit = QUERY_LIMITS[operation] + if (queryLimit) { + setString('filter', params.filter) + setString('sort', params.sort) + setNumber('limit', params.limit, 'limit', queryLimit) + } + + if (OFFSET_QUERY_OPERATIONS.has(operation)) { + setNumber('offset', params.offset, 'offset', { min: 0 }) + } - if (limit != null) mapped.limit = limit - if (offset != null) mapped.offset = offset - if (params.sort) mapped.sort = params.sort + if (CURSOR_QUERY_OPERATIONS.has(operation)) { + setString('after', params.after) } - if (params.operation === 'crowdstrike_get_sensor_details') { - const ids = parseOptionalJsonInput(params.ids, 'sensor IDs') - if (ids !== undefined) mapped.ids = ids + if (FREE_TEXT_QUERY_OPERATIONS.has(operation)) { + setString('q', params.q) } - if (params.operation === 'crowdstrike_get_sensor_aggregates') { - const aggregateQuery = parseOptionalJsonInput(params.aggregateQuery, 'aggregate query') - if (aggregateQuery !== undefined) mapped.aggregateQuery = aggregateQuery + switch (operation) { + case 'crowdstrike_get_sensor_details': + setJson('ids', params.ids, 'sensor IDs') + break + case 'crowdstrike_get_sensor_aggregates': + setJson('aggregateQuery', params.aggregateQuery, 'aggregate query') + break + case 'crowdstrike_query_alerts': + setBoolean('includeHidden', params.includeHidden) + break + case 'crowdstrike_get_alert_details': + setJson('compositeIds', params.compositeIds, 'composite alert IDs') + setBoolean('includeHidden', params.includeHidden) + break + case 'crowdstrike_update_alerts': + setJson('compositeIds', params.compositeIds, 'composite alert IDs') + setString('updateStatus', params.updateStatus) + setString('assignToUuid', params.assignToUuid) + setString('assignToUserId', params.assignToUserId) + setString('assignToName', params.assignToName) + setString('appendComment', params.appendComment) + setString('addTag', params.addTag) + setString('removeTag', params.removeTag) + setString('removeTagsByPrefix', params.removeTagsByPrefix) + setBoolean('unassign', params.unassign) + setBoolean('showInUi', params.showInUi) + setBoolean('includeHidden', params.includeHidden) + setJson('actionParameters', params.actionParameters, 'action parameters') + break + case 'crowdstrike_perform_host_action': + setString('actionName', params.hostActionName) + setJson('deviceIds', params.deviceIds, 'host agent IDs') + break + case 'crowdstrike_get_host_group_details': + setJson('hostGroupIds', params.hostGroupIds, 'host group IDs') + break + case 'crowdstrike_perform_host_group_action': + setString('actionName', params.hostGroupActionName) + setString('hostGroupId', params.hostGroupId) + setJson('deviceIds', params.deviceIds, 'host agent IDs') + break + case 'crowdstrike_get_indicator_details': + setJson('indicatorIds', params.indicatorIds, 'indicator IDs') + break + case 'crowdstrike_create_indicators': + case 'crowdstrike_update_indicators': + setJson('indicators', params.indicators, 'indicators') + setString('comment', params.comment) + setBoolean('retrodetects', params.retrodetects) + setBoolean('ignoreWarnings', params.ignoreWarnings) + break + case 'crowdstrike_delete_indicators': + setJson('indicatorIds', params.indicatorIds, 'indicator IDs') + setString('filter', params.deleteFilter) + setString('comment', params.comment) + break + case 'crowdstrike_get_vulnerability_details': + setJson('vulnerabilityIds', params.vulnerabilityIds, 'vulnerability IDs') + break + case 'crowdstrike_init_rtr_session': + setString('deviceId', params.deviceId) + setString('origin', params.origin) + setBoolean('queueOffline', params.queueOffline) + break + case 'crowdstrike_execute_rtr_command': + setString('sessionId', params.sessionId) + setString('baseCommand', params.baseCommand) + setString('commandString', params.commandString) + break + case 'crowdstrike_get_rtr_command_status': + setString('cloudRequestId', params.cloudRequestId) + setNumber('sequenceId', params.sequenceId, 'sequence ID', { min: 0 }) + break + case 'crowdstrike_delete_rtr_session': + setString('sessionId', params.sessionId) + break + case 'crowdstrike_get_case_details': + setJson('caseIds', params.caseIds, 'case IDs') + break + default: + break } return mapped @@ -201,6 +949,11 @@ export const CrowdStrikeBlock: BlockConfig = { clientSecret: { type: 'string', description: 'CrowdStrike Falcon API client secret' }, cloud: { type: 'string', description: 'CrowdStrike Falcon cloud region' }, filter: { type: 'string', description: 'Falcon Query Language filter' }, + deleteFilter: { + type: 'string', + description: 'Falcon Query Language filter selecting the indicators to delete', + }, + q: { type: 'string', description: 'Free-text metadata search' }, ids: { type: 'json', description: 'JSON array of CrowdStrike sensor device IDs' }, aggregateQuery: { type: 'json', @@ -208,7 +961,47 @@ export const CrowdStrikeBlock: BlockConfig = { }, limit: { type: 'number', description: 'Maximum number of records to return' }, offset: { type: 'number', description: 'Pagination offset' }, + after: { type: 'string', description: 'Cursor for the next page of results' }, sort: { type: 'string', description: 'Sort expression' }, + includeHidden: { type: 'boolean', description: 'Include previously hidden alerts' }, + compositeIds: { type: 'json', description: 'JSON array of composite alert IDs' }, + updateStatus: { type: 'string', description: 'New alert status' }, + assignToUuid: { type: 'string', description: 'Falcon user UUID to assign alerts to' }, + assignToUserId: { type: 'string', description: 'Falcon user ID to assign alerts to' }, + assignToName: { type: 'string', description: 'Falcon username to assign alerts to' }, + unassign: { type: 'boolean', description: 'Clear the alert assignment' }, + appendComment: { type: 'string', description: 'Comment to append to the alert' }, + addTag: { type: 'string', description: 'Tag to add to the alert' }, + removeTag: { type: 'string', description: 'Tag to remove from the alert' }, + removeTagsByPrefix: { + type: 'string', + description: 'Remove every alert tag starting with this prefix', + }, + showInUi: { type: 'boolean', description: 'Whether the alert shows in the Falcon console' }, + actionParameters: { + type: 'json', + description: 'Additional alert action parameters as { name, value } objects', + }, + hostActionName: { type: 'string', description: 'Host action to perform' }, + deviceIds: { type: 'json', description: 'JSON array of host agent IDs' }, + hostGroupIds: { type: 'json', description: 'JSON array of host group IDs' }, + hostGroupActionName: { type: 'string', description: 'Host group action to perform' }, + hostGroupId: { type: 'string', description: 'Host group ID to modify' }, + indicatorIds: { type: 'json', description: 'JSON array of indicator IDs' }, + indicators: { type: 'json', description: 'JSON array of indicator objects' }, + comment: { type: 'string', description: 'Audit comment for indicator changes' }, + retrodetects: { type: 'boolean', description: 'Generate retroactive detections' }, + ignoreWarnings: { type: 'boolean', description: 'Apply indicator changes despite warnings' }, + vulnerabilityIds: { type: 'json', description: 'JSON array of Spotlight vulnerability IDs' }, + deviceId: { type: 'string', description: 'Host agent ID for the RTR session' }, + queueOffline: { type: 'boolean', description: 'Queue the RTR session for an offline host' }, + origin: { type: 'string', description: 'RTR session origin label' }, + sessionId: { type: 'string', description: 'RTR session ID' }, + baseCommand: { type: 'string', description: 'Read-only RTR base command' }, + commandString: { type: 'string', description: 'Full RTR command line to run' }, + cloudRequestId: { type: 'string', description: 'RTR cloud request ID' }, + sequenceId: { type: 'number', description: 'RTR output chunk sequence' }, + caseIds: { type: 'json', description: 'JSON array of Case Management case IDs' }, }, outputs: { @@ -222,18 +1015,135 @@ export const CrowdStrikeBlock: BlockConfig = { description: 'CrowdStrike aggregate result groups (name, buckets, docCountErrorUpperBound, sumOtherDocCount)', }, + alertIds: { type: 'json', description: 'Composite alert IDs matching an alert query' }, + alerts: { + type: 'json', + description: + 'CrowdStrike alert records (compositeId, id, cid, name, description, type, product, platform, severity, severityName, status, assignedToName, tactic, technique, deviceId, hostname, tags, timestamps)', + }, + updatedIds: { type: 'json', description: 'Composite alert IDs an update was submitted for' }, + affected: { + type: 'json', + description: 'Entities affected by a host action (id, path)', + }, + hostGroupIds: { type: 'json', description: 'Host group IDs matching a host group query' }, + hostGroups: { + type: 'json', + description: + 'CrowdStrike host group records (id, name, description, groupType, assignmentRule, createdBy, createdTimestamp, modifiedBy, modifiedTimestamp)', + }, + indicatorIds: { type: 'json', description: 'Indicator IDs matching an indicator query' }, + indicators: { + type: 'json', + description: + 'CrowdStrike indicator records (id, type, value, action, severity, platforms, hostGroups, appliedGlobally, tags, expiration, metadata, timestamps)', + }, + deletedIds: { type: 'json', description: 'Indicator IDs CrowdStrike deleted' }, + vulnerabilityIds: { + type: 'json', + description: 'Spotlight vulnerability IDs matching a vulnerability query', + }, + vulnerabilities: { + type: 'json', + description: + 'Spotlight vulnerability records (id, aid, status, cve, app, hostInfo, remediations, suppressionInfo, timestamps)', + }, + sessionId: { type: 'string', description: 'RTR session ID' }, + deviceId: { type: 'string', description: 'Host ID (AID) the RTR session was opened against' }, + platform: { type: 'string', description: 'Platform of the host in the RTR session' }, + pwd: { type: 'string', description: 'Working directory the RTR session started in' }, + offlineQueued: { + type: 'boolean', + description: 'Whether the RTR session was queued for an offline host', + }, + existingAidSessions: { + type: 'number', + description: 'Number of RTR sessions already open against the host', + }, + createdAt: { type: 'string', description: 'When the RTR session was created' }, + cloudRequestId: { type: 'string', description: 'RTR cloud request ID to poll for output' }, + queuedCommandOffline: { + type: 'boolean', + description: 'Whether the RTR command was queued because the host is offline', + }, + baseCommand: { type: 'string', description: 'Base RTR command the status refers to' }, + taskId: { type: 'string', description: 'RTR task ID for the executed command' }, + sequenceId: { type: 'number', description: 'Sequence number of the RTR command output chunk' }, + complete: { type: 'boolean', description: 'Whether an RTR command has finished' }, + stdout: { type: 'string', description: 'Standard output from an RTR command' }, + stderr: { type: 'string', description: 'Standard error from an RTR command' }, + deleted: { type: 'boolean', description: 'Whether the RTR session was closed' }, + caseIds: { type: 'json', description: 'Case IDs matching a case query' }, + cases: { + type: 'json', + description: + 'CrowdStrike Case Management records (id, name, description, status, severity, severityLevel, referenceId, assignedTo, tags, timestamps)', + }, pagination: { type: 'json', - description: 'Pagination metadata (limit, offset, total) for query responses', + description: 'Pagination metadata (limit, offset, total, after) for query responses', + }, + errors: { + type: 'json', + description: + 'Per-item errors CrowdStrike returned alongside a partially successful response (code, id, message)', }, count: { type: 'number', description: 'Number of records returned by the selected operation' }, }, } export const CrowdStrikeBlockMeta = { - tags: ['identity', 'monitoring'], + tags: ['identity', 'monitoring', 'incident-management', 'automation'], url: 'https://www.crowdstrike.com', templates: [ + { + icon: CrowdStrikeIcon, + title: 'CrowdStrike alert triage', + prompt: + 'Create a workflow that queries new high-severity CrowdStrike alerts, pulls their details, summarizes the tactic, technique, and affected host for each, posts the triage summary to Slack, and marks the reviewed alerts in progress.', + modules: ['scheduled', 'agent', 'workflows'], + category: 'operations', + tags: ['security', 'monitoring'], + alsoIntegrations: ['slack'], + }, + { + icon: CrowdStrikeIcon, + title: 'CrowdStrike host containment', + prompt: + 'Create a workflow that takes a host ID, contains the host in CrowdStrike, opens a Real Time Response session to capture running processes and network connections, and posts the collected evidence to Slack for the on-call responder.', + modules: ['agent', 'workflows'], + category: 'operations', + tags: ['security', 'incident-response'], + alsoIntegrations: ['slack'], + }, + { + icon: CrowdStrikeIcon, + title: 'CrowdStrike IOC sync', + prompt: + 'Create a workflow that reads indicators of compromise from a table, creates them as custom CrowdStrike indicators with a blocking action and an expiration, and records the returned indicator IDs back to the table.', + modules: ['agent', 'tables', 'workflows'], + category: 'operations', + tags: ['security', 'automation'], + }, + { + icon: CrowdStrikeIcon, + title: 'CrowdStrike vulnerability report', + prompt: + 'Create a scheduled workflow that queries CrowdStrike Spotlight for open critical vulnerabilities, pulls the CVE and remediation details, groups them by host, and writes a prioritized remediation report for the platform team.', + modules: ['scheduled', 'agent', 'files', 'workflows'], + category: 'operations', + tags: ['security', 'reporting'], + }, + { + icon: CrowdStrikeIcon, + title: 'CrowdStrike case digest', + prompt: + 'Create a scheduled workflow that queries open CrowdStrike Case Management cases, pulls each case status, severity, and assignee, and posts a daily standup digest to Slack.', + modules: ['scheduled', 'agent', 'workflows'], + category: 'operations', + tags: ['security', 'reporting'], + alsoIntegrations: ['slack'], + }, { icon: CrowdStrikeIcon, title: 'CrowdStrike sensor coverage gaps', @@ -302,6 +1212,34 @@ export const CrowdStrikeBlockMeta = { }, ], skills: [ + { + name: 'triage-falcon-alerts', + description: + 'Query CrowdStrike alerts, pull their details, and summarize severity, tactic, and affected host for SOC triage.', + content: + '# Triage CrowdStrike Alerts\n\nWork a queue of Falcon alerts down to a reviewed state.\n\n## Steps\n1. Query alerts with an FQL filter for the status and severity you care about.\n2. Pull alert details for the returned composite IDs.\n3. Summarize each alert by severity, tactic, technique, and affected host.\n4. Update the reviewed alerts with a new status and an audit comment.\n\n## Output\nA triage summary per alert plus the list of alert IDs whose status was updated.', + }, + { + name: 'contain-compromised-host', + description: + 'Contain a CrowdStrike host and collect live evidence through a Real Time Response session.', + content: + '# Contain a Compromised Host\n\nIsolate a host and gather evidence before responders arrive.\n\n## Steps\n1. Run the contain action against the target host ID.\n2. Open a Real Time Response session on that host.\n3. Run read-tier commands (ps, netstat, ls, filehash) and poll each cloud request ID for output.\n4. Close the session when collection is done.\n\n## Output\nConfirmation the host was contained, plus the captured command output for the incident record.', + }, + { + name: 'manage-custom-indicators', + description: + 'Create, update, search, and delete custom CrowdStrike indicators of compromise.', + content: + '# Manage Custom CrowdStrike Indicators\n\nKeep the custom IOC list current.\n\n## Steps\n1. Query existing indicators with an FQL filter to see what is already covered.\n2. Create new indicators with the intended action, platforms, and expiration.\n3. Update severity, action, or expiration on indicators that need changing.\n4. Delete indicators that are stale, scoping deletes by explicit IDs rather than a broad filter.\n\n## Output\nThe indicator IDs created, updated, or deleted, plus any per-item errors CrowdStrike returned.', + }, + { + name: 'prioritize-spotlight-vulnerabilities', + description: + 'Query CrowdStrike Spotlight vulnerabilities and rank them by severity, exploit status, and affected host.', + content: + '# Prioritize Spotlight Vulnerabilities\n\nTurn the Spotlight backlog into a ranked remediation list.\n\n## Steps\n1. Query vulnerabilities with an FQL filter (Spotlight requires one) for open findings.\n2. Pull details for the returned IDs to get CVE data, host info, and remediations.\n3. Rank by CVE severity and exploit status, then group by host or application.\n\n## Output\nA prioritized remediation list naming each CVE, its affected hosts, and the recommended fix.', + }, { name: 'audit-identity-sensors', description: diff --git a/apps/sim/lib/api/contracts/tools/crowdstrike.ts b/apps/sim/lib/api/contracts/tools/crowdstrike.ts index 4fedf74fcc3..2094bedd327 100644 --- a/apps/sim/lib/api/contracts/tools/crowdstrike.ts +++ b/apps/sim/lib/api/contracts/tools/crowdstrike.ts @@ -5,11 +5,23 @@ import type { ContractJsonResponse, } from '@/lib/api/contracts/types' import { defineRouteContract } from '@/lib/api/contracts/types' -import type { CrowdStrikeAggregateQuery } from '@/tools/crowdstrike/types' +import type { + CrowdStrikeAggregateQuery, + CrowdStrikeSensorAggregateBucket, + CrowdStrikeSensorAggregateResult, +} from '@/tools/crowdstrike/types' const crowdstrikeNullableStringSchema = z.string().nullable() const crowdstrikeNullableNumberSchema = z.number().nullable() +const crowdstrikeErrorsSchema = z.array( + z.object({ + code: crowdstrikeNullableNumberSchema, + id: crowdstrikeNullableStringSchema, + message: crowdstrikeNullableStringSchema, + }) +) + const crowdstrikePaginationSchema = z .object({ limit: crowdstrikeNullableNumberSchema, @@ -40,30 +52,41 @@ const crowdstrikeSensorSchema = z.object({ tiEnabled: crowdstrikeNullableStringSchema, }) -const crowdstrikeAggregateBucketSchema = z.object({ - count: crowdstrikeNullableNumberSchema, - from: crowdstrikeNullableNumberSchema, - keyAsString: crowdstrikeNullableStringSchema, - label: z.unknown().nullable(), - stringFrom: crowdstrikeNullableStringSchema, - stringTo: crowdstrikeNullableStringSchema, - subAggregates: z.array(z.unknown()), - to: crowdstrikeNullableNumberSchema, - value: crowdstrikeNullableNumberSchema, - valueAsString: crowdstrikeNullableStringSchema, -}) +/** + * Buckets nest recursively through `subAggregates`, so the two schemas reference + * each other through `z.lazy`. `label` is `interface{}` in CrowdStrike's own spec — + * a terms aggregation returns a scalar and a range aggregation an object — so the + * route forwards it unchanged. + */ +const crowdstrikeAggregateBucketSchema: z.ZodType = z.lazy(() => + z.object({ + count: crowdstrikeNullableNumberSchema, + from: crowdstrikeNullableNumberSchema, + keyAsString: crowdstrikeNullableStringSchema, + label: z.unknown(), + stringFrom: crowdstrikeNullableStringSchema, + stringTo: crowdstrikeNullableStringSchema, + subAggregates: z.array(crowdstrikeAggregateResultSchema), + to: crowdstrikeNullableNumberSchema, + value: crowdstrikeNullableNumberSchema, + valueAsString: crowdstrikeNullableStringSchema, + }) +) -const crowdstrikeAggregateResultSchema = z.object({ - buckets: z.array(crowdstrikeAggregateBucketSchema), - docCountErrorUpperBound: crowdstrikeNullableNumberSchema, - name: crowdstrikeNullableStringSchema, - sumOtherDocCount: crowdstrikeNullableNumberSchema, -}) +const crowdstrikeAggregateResultSchema: z.ZodType = z.lazy(() => + z.object({ + buckets: z.array(crowdstrikeAggregateBucketSchema), + docCountErrorUpperBound: crowdstrikeNullableNumberSchema, + name: crowdstrikeNullableStringSchema, + sumOtherDocCount: crowdstrikeNullableNumberSchema, + }) +) const crowdstrikeSensorsResponseSchema = z.object({ success: z.literal(true), output: z.object({ count: z.number(), + errors: crowdstrikeErrorsSchema, pagination: crowdstrikePaginationSchema, sensors: z.array(crowdstrikeSensorSchema), }), @@ -74,10 +97,11 @@ const crowdstrikeAggregatesResponseSchema = z.object({ output: z.object({ aggregates: z.array(crowdstrikeAggregateResultSchema), count: z.number(), + errors: crowdstrikeErrorsSchema, }), }) -const CROWDSTRIKE_CLOUDS = ['us-1', 'us-2', 'eu-1', 'us-gov-1', 'us-gov-2'] as const +const CROWDSTRIKE_CLOUDS = ['us-1', 'us-2', 'us-3', 'eu-1', 'us-gov-1', 'us-gov-2'] as const const baseRequestSchema = z.object({ clientId: z.string().min(1, 'Client ID is required'), @@ -95,38 +119,67 @@ const extendedBoundsSchema = z.object({ min: z.string(), }) +/** CrowdStrike's `MsaRangeSpec` serializes its bounds capitalized, unlike every sibling spec. */ const rangeSpecSchema = z.object({ - from: z.number(), - to: z.number(), + From: z.number(), + To: z.number(), }) +/** `MsaAPIFiltersSpec` — an FQL-per-bucket map plus the catch-all bucket controls. */ +const filtersSpecSchema = z.object({ + filters: z.record(z.string(), z.string()), + other_bucket: z.boolean().optional(), + other_bucket_key: z.string().optional(), +}) + +/** + * `MsaAggregateQueryRequest` marks nearly every property `Required: true`, which + * cannot be literally true of an aggregation body, so the fields stay optional + * here. Demanding at least a `field` or a `type` is strictly weaker than the + * published spec, so it cannot reject an aggregation CrowdStrike would accept, + * and it turns "aggregate query says nothing" into a message the caller can act + * on instead of an opaque 400. + */ const aggregateQuerySchema: z.ZodType = z.lazy(() => - z.object({ - date_ranges: z.array(dateRangeSchema).optional(), - exclude: z.string().optional(), - extended_bounds: extendedBoundsSchema.optional(), - field: z.string().optional(), - filter: z.string().optional(), - from: z.number().int().nonnegative().optional(), - include: z.string().optional(), - interval: z.string().optional(), - max_doc_count: z.number().int().nonnegative().optional(), - min_doc_count: z.number().int().nonnegative().optional(), - missing: z.string().optional(), - name: z.string().optional(), - q: z.string().optional(), - ranges: z.array(rangeSpecSchema).optional(), - size: z.number().int().nonnegative().optional(), - sort: z.string().optional(), - sub_aggregates: z.array(aggregateQuerySchema).optional(), - time_zone: z.string().optional(), - type: z.string().optional(), - }) + z + .object({ + date_ranges: z.array(dateRangeSchema).optional(), + exclude: z.string().optional(), + extended_bounds: extendedBoundsSchema.optional(), + field: z.string().optional(), + filter: z.string().optional(), + filters_spec: filtersSpecSchema.optional(), + from: z.number().int().nonnegative().optional(), + include: z.string().optional(), + interval: z.string().optional(), + max_doc_count: z.number().int().nonnegative().optional(), + min_doc_count: z.number().int().nonnegative().optional(), + missing: z.string().optional(), + name: z.string().optional(), + percents: z.array(z.number()).optional(), + q: z.string().optional(), + ranges: z.array(rangeSpecSchema).optional(), + size: z.number().int().nonnegative().optional(), + sort: z.string().optional(), + sub_aggregates: z.array(aggregateQuerySchema).optional(), + time_zone: z.string().optional(), + type: z.string().optional(), + }) + .refine((value) => Boolean(value.field ?? value.type), { + message: 'aggregateQuery must set at least a field or a type', + }) ) +/** + * Falcon treats an empty query param as an empty FQL expression rather than an + * absent one, so a blank string must be rejected instead of forwarded. + */ +const nonBlankQuerySchema = (label: string) => + z.string().trim().min(1, `${label} must not be empty`).optional() + const querySensorsSchema = baseRequestSchema.extend({ operation: z.literal('crowdstrike_query_sensors'), - filter: z.string().optional(), + filter: nonBlankQuerySchema('Filter'), limit: z .number() .int() @@ -134,7 +187,7 @@ const querySensorsSchema = baseRequestSchema.extend({ .max(200, 'Limit must be at most 200') .optional(), offset: z.number().int().nonnegative('Offset must be 0 or greater').optional(), - sort: z.string().optional(), + sort: nonBlankQuerySchema('Sort'), }) const getSensorDetailsSchema = baseRequestSchema.extend({ @@ -142,7 +195,7 @@ const getSensorDetailsSchema = baseRequestSchema.extend({ ids: z .array(z.string().trim().min(1, 'Sensor IDs must not be empty')) .min(1, 'At least one sensor ID is required') - .max(5000, 'CrowdStrike supports up to 5000 sensor IDs per request'), + .max(5000, 'CrowdStrike accepts at most 5000 sensor IDs per request'), }) const getSensorAggregatesSchema = baseRequestSchema.extend({ @@ -150,10 +203,812 @@ const getSensorAggregatesSchema = baseRequestSchema.extend({ aggregateQuery: aggregateQuerySchema, }) +/** + * Falcon agent IDs are 32-character hex AIDs. Constraining them keeps a crafted + * value out of the FQL `device_id` filter the host-group action builds, and bounds + * the length of that generated filter. + */ +const agentIdsSchema = (max: number, limitReason: string) => + z + .array( + z + .string() + .trim() + .regex(/^[0-9a-fA-F]{32}$/, 'Host agent IDs must be 32 hexadecimal characters') + ) + .min(1, 'At least one host agent ID is required') + .max(max, `${limitReason} (limit ${max})`) + +/** + * `documented` distinguishes a cap CrowdStrike publishes from one Sim imposes so + * a single request cannot balloon without bound. Only the published caps may + * claim CrowdStrike as their source. + */ +const idsSchema = (max: number, label: string, documented = false) => + z + .array(z.string().trim().min(1, `${label} must not be empty`)) + .min(1, `At least one ${label} is required`) + .max( + max, + documented + ? `CrowdStrike accepts at most ${max} ${label} values per request` + : `Sim caps this request at ${max} ${label} values; CrowdStrike publishes no limit for this endpoint` + ) + +const crowdstrikeCursorPaginationSchema = z + .object({ + after: crowdstrikeNullableStringSchema, + limit: crowdstrikeNullableNumberSchema, + offset: crowdstrikeNullableNumberSchema, + total: crowdstrikeNullableNumberSchema, + }) + .nullable() + +const crowdstrikeSpotlightPaginationSchema = z + .object({ + after: crowdstrikeNullableStringSchema, + limit: crowdstrikeNullableNumberSchema, + total: crowdstrikeNullableNumberSchema, + }) + .nullable() + +const crowdstrikeAlertSchema = z.object({ + compositeId: crowdstrikeNullableStringSchema, + id: crowdstrikeNullableStringSchema, + cid: crowdstrikeNullableStringSchema, + aggregateId: crowdstrikeNullableStringSchema, + agentId: crowdstrikeNullableStringSchema, + deviceId: crowdstrikeNullableStringSchema, + hostname: crowdstrikeNullableStringSchema, + name: crowdstrikeNullableStringSchema, + displayName: crowdstrikeNullableStringSchema, + description: crowdstrikeNullableStringSchema, + type: crowdstrikeNullableStringSchema, + product: crowdstrikeNullableStringSchema, + platform: crowdstrikeNullableStringSchema, + severity: crowdstrikeNullableNumberSchema, + severityName: crowdstrikeNullableStringSchema, + confidence: crowdstrikeNullableNumberSchema, + status: crowdstrikeNullableStringSchema, + assignedToName: crowdstrikeNullableStringSchema, + assignedToUid: crowdstrikeNullableStringSchema, + assignedToUuid: crowdstrikeNullableStringSchema, + tactic: crowdstrikeNullableStringSchema, + tacticId: crowdstrikeNullableStringSchema, + technique: crowdstrikeNullableStringSchema, + techniqueId: crowdstrikeNullableStringSchema, + scenario: crowdstrikeNullableStringSchema, + objective: crowdstrikeNullableStringSchema, + resolution: crowdstrikeNullableStringSchema, + showInUi: z.boolean().nullable(), + tags: z.array(z.string()), + filename: crowdstrikeNullableStringSchema, + filepath: crowdstrikeNullableStringSchema, + cmdline: crowdstrikeNullableStringSchema, + sha256: crowdstrikeNullableStringSchema, + sha1: crowdstrikeNullableStringSchema, + md5: crowdstrikeNullableStringSchema, + userName: crowdstrikeNullableStringSchema, + userId: crowdstrikeNullableStringSchema, + patternId: crowdstrikeNullableNumberSchema, + falconHostLink: crowdstrikeNullableStringSchema, + controlGraphId: crowdstrikeNullableStringSchema, + external: z.boolean().nullable(), + emailSent: z.boolean().nullable(), + isAggregated: z.boolean().nullable(), + isFalconPlatformIoa: z.boolean().nullable(), + dataDomains: z.array(z.string()), + iocValues: z.array(z.string()), + linkedCaseIds: z.array(z.string()), + linkedBehavioralDetections: z.array(z.string()), + timestamp: crowdstrikeNullableStringSchema, + createdTimestamp: crowdstrikeNullableStringSchema, + updatedTimestamp: crowdstrikeNullableStringSchema, + crawledTimestamp: crowdstrikeNullableStringSchema, + contextTimestamp: crowdstrikeNullableStringSchema, +}) + +const crowdstrikeHostGroupSchema = z.object({ + id: crowdstrikeNullableStringSchema, + name: crowdstrikeNullableStringSchema, + description: crowdstrikeNullableStringSchema, + groupType: crowdstrikeNullableStringSchema, + assignmentRule: crowdstrikeNullableStringSchema, + createdBy: crowdstrikeNullableStringSchema, + createdTimestamp: crowdstrikeNullableStringSchema, + modifiedBy: crowdstrikeNullableStringSchema, + modifiedTimestamp: crowdstrikeNullableStringSchema, +}) + +const crowdstrikeIndicatorSchema = z.object({ + id: crowdstrikeNullableStringSchema, + type: crowdstrikeNullableStringSchema, + value: crowdstrikeNullableStringSchema, + action: crowdstrikeNullableStringSchema, + mobileAction: crowdstrikeNullableStringSchema, + severity: crowdstrikeNullableStringSchema, + description: crowdstrikeNullableStringSchema, + source: crowdstrikeNullableStringSchema, + appliedGlobally: z.boolean().nullable(), + platforms: z.array(z.string()), + hostGroups: z.array(z.string()), + tags: z.array(z.string()), + expiration: crowdstrikeNullableStringSchema, + expired: z.boolean().nullable(), + deleted: z.boolean().nullable(), + fromParent: z.boolean().nullable(), + parentCidName: crowdstrikeNullableStringSchema, + createdBy: crowdstrikeNullableStringSchema, + createdOn: crowdstrikeNullableStringSchema, + modifiedBy: crowdstrikeNullableStringSchema, + modifiedOn: crowdstrikeNullableStringSchema, + metadata: z + .object({ + avHits: crowdstrikeNullableNumberSchema, + companyName: crowdstrikeNullableStringSchema, + fileDescription: crowdstrikeNullableStringSchema, + fileVersion: crowdstrikeNullableStringSchema, + filename: crowdstrikeNullableStringSchema, + originalFilename: crowdstrikeNullableStringSchema, + productName: crowdstrikeNullableStringSchema, + productVersion: crowdstrikeNullableStringSchema, + signed: z.boolean().nullable(), + }) + .nullable(), +}) + +const crowdstrikeVulnerabilitySchema = z.object({ + id: crowdstrikeNullableStringSchema, + aid: crowdstrikeNullableStringSchema, + cid: crowdstrikeNullableStringSchema, + status: crowdstrikeNullableStringSchema, + confidence: crowdstrikeNullableStringSchema, + vulnerabilityId: crowdstrikeNullableStringSchema, + createdTimestamp: crowdstrikeNullableStringSchema, + updatedTimestamp: crowdstrikeNullableStringSchema, + closedTimestamp: crowdstrikeNullableStringSchema, + cve: z + .object({ + id: crowdstrikeNullableStringSchema, + baseScore: crowdstrikeNullableNumberSchema, + severity: crowdstrikeNullableStringSchema, + exprtRating: crowdstrikeNullableStringSchema, + exploitStatus: crowdstrikeNullableNumberSchema, + exploitabilityScore: crowdstrikeNullableNumberSchema, + impactScore: crowdstrikeNullableNumberSchema, + remediationLevel: crowdstrikeNullableStringSchema, + description: crowdstrikeNullableStringSchema, + publishedDate: crowdstrikeNullableStringSchema, + vector: crowdstrikeNullableStringSchema, + types: z.array(z.string()), + isCisaKev: z.boolean().nullable(), + cisaDueDate: crowdstrikeNullableStringSchema, + }) + .nullable(), + app: z + .object({ + productNameNormalized: crowdstrikeNullableStringSchema, + productNameVersion: crowdstrikeNullableStringSchema, + vendorNormalized: crowdstrikeNullableStringSchema, + }) + .nullable(), + hostInfo: z + .object({ + hostname: crowdstrikeNullableStringSchema, + localIp: crowdstrikeNullableStringSchema, + machineDomain: crowdstrikeNullableStringSchema, + osVersion: crowdstrikeNullableStringSchema, + platform: crowdstrikeNullableStringSchema, + productTypeDesc: crowdstrikeNullableStringSchema, + assetCriticality: crowdstrikeNullableStringSchema, + internetExposure: crowdstrikeNullableStringSchema, + tags: z.array(z.string()), + groups: z.array(z.string()), + }) + .nullable(), + remediationIds: z.array(z.string()), + remediations: z.array( + z.object({ + id: crowdstrikeNullableStringSchema, + title: crowdstrikeNullableStringSchema, + action: crowdstrikeNullableStringSchema, + type: crowdstrikeNullableStringSchema, + link: crowdstrikeNullableStringSchema, + reference: crowdstrikeNullableStringSchema, + vendorUrl: crowdstrikeNullableStringSchema, + }) + ), + suppressionInfo: z + .object({ + isSuppressed: z.boolean().nullable(), + reason: crowdstrikeNullableStringSchema, + }) + .nullable(), +}) + +const crowdstrikeFalconUserSchema = z + .object({ + uuid: crowdstrikeNullableStringSchema, + email: crowdstrikeNullableStringSchema, + fullName: crowdstrikeNullableStringSchema, + }) + .nullable() + +const crowdstrikeCaseSchema = z.object({ + id: crowdstrikeNullableStringSchema, + cid: crowdstrikeNullableStringSchema, + name: crowdstrikeNullableStringSchema, + description: crowdstrikeNullableStringSchema, + descriptionFormat: crowdstrikeNullableStringSchema, + status: crowdstrikeNullableStringSchema, + severity: crowdstrikeNullableNumberSchema, + severityLevel: crowdstrikeNullableStringSchema, + referenceId: crowdstrikeNullableStringSchema, + version: crowdstrikeNullableNumberSchema, + tags: z.array(z.string()), + assignedTo: crowdstrikeFalconUserSchema, + createdBy: crowdstrikeFalconUserSchema, + lastUpdatedBy: crowdstrikeFalconUserSchema, + createdTimestamp: crowdstrikeNullableStringSchema, + updatedTimestamp: crowdstrikeNullableStringSchema, + startTimestamp: crowdstrikeNullableStringSchema, + endTimestamp: crowdstrikeNullableStringSchema, + templateId: crowdstrikeNullableStringSchema, + templateName: crowdstrikeNullableStringSchema, + slaId: crowdstrikeNullableStringSchema, + slaName: crowdstrikeNullableStringSchema, + isReadOnly: z.boolean().nullable(), +}) + +const successOutput = (output: T) => + z.object({ success: z.literal(true), output }) + +const crowdstrikeAlertIdsResponseSchema = successOutput( + z.object({ + alertIds: z.array(z.string()), + count: z.number(), + pagination: crowdstrikePaginationSchema, + }) +) + +const crowdstrikeHostGroupIdsResponseSchema = successOutput( + z.object({ + hostGroupIds: z.array(z.string()), + count: z.number(), + pagination: crowdstrikePaginationSchema, + }) +) + +const crowdstrikeCaseIdsResponseSchema = successOutput( + z.object({ + caseIds: z.array(z.string()), + count: z.number(), + pagination: crowdstrikePaginationSchema, + }) +) + +const crowdstrikeIndicatorIdsResponseSchema = successOutput( + z.object({ + indicatorIds: z.array(z.string()), + count: z.number(), + pagination: crowdstrikeCursorPaginationSchema, + }) +) + +const crowdstrikeVulnerabilityIdsResponseSchema = successOutput( + z.object({ + vulnerabilityIds: z.array(z.string()), + count: z.number(), + pagination: crowdstrikeSpotlightPaginationSchema, + }) +) + +const crowdstrikeAlertsResponseSchema = successOutput( + z.object({ + alerts: z.array(crowdstrikeAlertSchema), + count: z.number(), + errors: crowdstrikeErrorsSchema, + }) +) + +const crowdstrikeUpdatedAlertsResponseSchema = successOutput( + z.object({ + updatedIds: z.array(z.string()), + count: z.number(), + errors: crowdstrikeErrorsSchema, + }) +) + +const crowdstrikeAffectedEntitiesResponseSchema = successOutput( + z.object({ + affected: z.array( + z.object({ + id: crowdstrikeNullableStringSchema, + path: crowdstrikeNullableStringSchema, + }) + ), + count: z.number(), + errors: crowdstrikeErrorsSchema, + }) +) + +const crowdstrikeHostGroupsResponseSchema = successOutput( + z.object({ + hostGroups: z.array(crowdstrikeHostGroupSchema), + count: z.number(), + errors: crowdstrikeErrorsSchema, + }) +) + +const crowdstrikeIndicatorsResponseSchema = successOutput( + z.object({ + indicators: z.array(crowdstrikeIndicatorSchema), + count: z.number(), + errors: crowdstrikeErrorsSchema, + }) +) + +const crowdstrikeDeletedIndicatorsResponseSchema = successOutput( + z.object({ + deletedIds: z.array(z.string()), + count: z.number(), + errors: crowdstrikeErrorsSchema, + }) +) + +const crowdstrikeVulnerabilitiesResponseSchema = successOutput( + z.object({ + vulnerabilities: z.array(crowdstrikeVulnerabilitySchema), + count: z.number(), + errors: crowdstrikeErrorsSchema, + }) +) + +const crowdstrikeRtrSessionResponseSchema = successOutput( + z.object({ + sessionId: crowdstrikeNullableStringSchema, + deviceId: crowdstrikeNullableStringSchema, + platform: crowdstrikeNullableStringSchema, + pwd: crowdstrikeNullableStringSchema, + offlineQueued: z.boolean().nullable(), + existingAidSessions: crowdstrikeNullableNumberSchema, + createdAt: crowdstrikeNullableStringSchema, + errors: crowdstrikeErrorsSchema, + }) +) + +const crowdstrikeRtrCommandResponseSchema = successOutput( + z.object({ + cloudRequestId: crowdstrikeNullableStringSchema, + sessionId: crowdstrikeNullableStringSchema, + queuedCommandOffline: z.boolean().nullable(), + errors: crowdstrikeErrorsSchema, + }) +) + +const crowdstrikeRtrCommandStatusResponseSchema = successOutput( + z.object({ + complete: z.boolean().nullable(), + stdout: crowdstrikeNullableStringSchema, + stderr: crowdstrikeNullableStringSchema, + baseCommand: crowdstrikeNullableStringSchema, + sessionId: crowdstrikeNullableStringSchema, + taskId: crowdstrikeNullableStringSchema, + sequenceId: crowdstrikeNullableNumberSchema, + errors: crowdstrikeErrorsSchema, + }) +) + +const crowdstrikeRtrDeleteSessionResponseSchema = successOutput( + z.object({ + sessionId: z.string(), + deleted: z.boolean(), + errors: crowdstrikeErrorsSchema, + }) +) + +const crowdstrikeCasesResponseSchema = successOutput( + z.object({ + cases: z.array(crowdstrikeCaseSchema), + count: z.number(), + errors: crowdstrikeErrorsSchema, + }) +) + +const queryAlertsSchema = baseRequestSchema.extend({ + operation: z.literal('crowdstrike_query_alerts'), + filter: nonBlankQuerySchema('Filter'), + q: nonBlankQuerySchema('Query'), + limit: z + .number() + .int() + .min(1, 'Limit must be at least 1') + .max(10000, 'Limit must be at most 10000') + .optional(), + offset: z.number().int().nonnegative('Offset must be 0 or greater').optional(), + sort: nonBlankQuerySchema('Sort'), + includeHidden: z.boolean().optional(), +}) + +const getAlertDetailsSchema = baseRequestSchema.extend({ + operation: z.literal('crowdstrike_get_alert_details'), + compositeIds: idsSchema(1000, 'composite alert ID'), + includeHidden: z.boolean().optional(), +}) + +const ALERT_STATUSES = ['new', 'in_progress', 'reopened', 'closed'] as const + +const updateAlertsSchema = baseRequestSchema + .extend({ + operation: z.literal('crowdstrike_update_alerts'), + compositeIds: idsSchema(1000, 'composite alert ID'), + updateStatus: z + .enum(ALERT_STATUSES, { + message: 'updateStatus must be new, in_progress, reopened, or closed', + }) + .optional(), + assignToUuid: z.string().trim().min(1, 'assignToUuid cannot be empty').optional(), + assignToUserId: z.string().trim().min(1, 'assignToUserId cannot be empty').optional(), + assignToName: z.string().trim().min(1, 'assignToName cannot be empty').optional(), + unassign: z.boolean().optional(), + appendComment: z.string().trim().min(1, 'appendComment cannot be empty').optional(), + addTag: z.string().trim().min(1, 'addTag cannot be empty').optional(), + removeTag: z.string().trim().min(1, 'removeTag cannot be empty').optional(), + removeTagsByPrefix: z.string().trim().min(1, 'removeTagsByPrefix cannot be empty').optional(), + showInUi: z.boolean().optional(), + actionParameters: z + .array( + z.object({ + name: z.string().trim().min(1, 'Action parameter name cannot be empty'), + value: z.string(), + }) + ) + .max(50, 'At most 50 action parameters are supported') + .optional(), + includeHidden: z.boolean().optional(), + }) + .superRefine((value, ctx) => { + const assignsSomeone = + value.assignToUuid !== undefined || + value.assignToUserId !== undefined || + value.assignToName !== undefined + if (value.unassign === true && assignsSomeone) { + ctx.addIssue({ + code: 'custom', + path: ['unassign'], + message: + 'unassign cannot be combined with assignToUuid, assignToUserId, or assignToName; CrowdStrike does not define which wins', + }) + } + + const hasAction = + value.updateStatus !== undefined || + value.assignToUuid !== undefined || + value.assignToUserId !== undefined || + value.assignToName !== undefined || + value.unassign === true || + value.appendComment !== undefined || + value.addTag !== undefined || + value.removeTag !== undefined || + value.removeTagsByPrefix !== undefined || + value.showInUi !== undefined || + (value.actionParameters?.length ?? 0) > 0 + + if (!hasAction) { + ctx.addIssue({ + code: 'custom', + path: ['actionParameters'], + message: + 'Supply at least one alert update: updateStatus, assignToUuid, assignToUserId, assignToName, unassign, appendComment, addTag, removeTag, removeTagsByPrefix, showInUi, or actionParameters', + }) + } + }) + +const HOST_ACTIONS = [ + 'contain', + 'lift_containment', + 'hide_host', + 'unhide_host', + 'detection_suppress', + 'detection_unsuppress', +] as const + +const performHostActionSchema = baseRequestSchema.extend({ + operation: z.literal('crowdstrike_perform_host_action'), + actionName: z.enum(HOST_ACTIONS, { + message: `actionName must be one of ${HOST_ACTIONS.join(', ')}`, + }), + deviceIds: agentIdsSchema(100, 'CrowdStrike accepts at most 100 host agent IDs per host action'), +}) + +const queryHostGroupsSchema = baseRequestSchema.extend({ + operation: z.literal('crowdstrike_query_host_groups'), + filter: nonBlankQuerySchema('Filter'), + limit: z + .number() + .int() + .min(1, 'Limit must be at least 1') + .max(5000, 'Limit must be at most 5000') + .optional(), + offset: z.number().int().nonnegative('Offset must be 0 or greater').optional(), + sort: nonBlankQuerySchema('Sort'), +}) + +const getHostGroupDetailsSchema = baseRequestSchema.extend({ + operation: z.literal('crowdstrike_get_host_group_details'), + hostGroupIds: idsSchema(500, 'host group ID'), +}) + +const HOST_GROUP_ACTIONS = ['add-hosts', 'remove-hosts'] as const + +/** + * `RTR-ExecuteCommand` is the Read-scoped tier of the three RTR command endpoints, + * and it accepts only these base commands. Subcommands ride in `command_string` + * (`eventlog view ...`, `reg query ...`), never in `base_command`; the write-tier + * variants such as `eventlog backup` belong to `/entities/active-responder-command/v1` + * and would fail here on scope. + */ +export const RTR_READ_ONLY_BASE_COMMANDS = [ + 'cat', + 'cd', + 'clear', + 'csrutil', + 'env', + 'eventlog', + 'filehash', + 'getsid', + 'help', + 'history', + 'ipconfig', + 'ls', + 'mount', + 'netstat', + 'ps', + 'reg', +] as const + +const performHostGroupActionSchema = baseRequestSchema.extend({ + operation: z.literal('crowdstrike_perform_host_group_action'), + actionName: z.enum(HOST_GROUP_ACTIONS, { + message: 'actionName must be add-hosts or remove-hosts', + }), + hostGroupId: z.string().trim().min(1, 'hostGroupId is required'), + deviceIds: agentIdsSchema( + 500, + 'CrowdStrike documents no host cap for this endpoint, so Sim bounds the generated device_id FQL filter' + ), +}) + +const queryIndicatorsSchema = baseRequestSchema + .extend({ + operation: z.literal('crowdstrike_query_indicators'), + filter: nonBlankQuerySchema('Filter'), + limit: z + .number() + .int() + .min(1, 'Limit must be at least 1') + .max(500, 'Limit must be at most 500') + .optional(), + offset: z.number().int().nonnegative('Offset must be 0 or greater').optional(), + after: nonBlankQuerySchema('After cursor'), + sort: nonBlankQuerySchema('Sort'), + }) + .superRefine((value, ctx) => { + if (value.offset !== undefined && value.after !== undefined) { + ctx.addIssue({ + code: 'custom', + path: ['after'], + message: 'after cannot be combined with offset; pick one pagination mode', + }) + } + }) + +const getIndicatorDetailsSchema = baseRequestSchema.extend({ + operation: z.literal('crowdstrike_get_indicator_details'), + indicatorIds: idsSchema(1000, 'indicator ID'), +}) + +/** + * `PATCH /iocs/entities/indicators/v1` treats a supplied empty string as a real + * value and clears the stored field, so the fields a blank would clobber are + * constrained here. Unknown keys pass through so newly documented IOC fields keep + * working without a contract change. + * + * This guards blanks only. CrowdStrike separately documents that *omitting* a + * field on PATCH also overwrites it with a blank value, and no schema can detect + * an absent key — that hazard is carried in the `crowdstrike_update_indicators` + * tool and parameter descriptions instead. + */ +const indicatorPayloadSchema = z + .object({ + id: nonBlankQuerySchema('Indicator id'), + type: nonBlankQuerySchema('Indicator type'), + value: nonBlankQuerySchema('Indicator value'), + action: nonBlankQuerySchema('Indicator action'), + mobile_action: nonBlankQuerySchema('Indicator mobile_action'), + severity: nonBlankQuerySchema('Indicator severity'), + description: nonBlankQuerySchema('Indicator description'), + source: nonBlankQuerySchema('Indicator source'), + expiration: nonBlankQuerySchema('Indicator expiration'), + applied_globally: z.boolean().optional(), + platforms: z.array(z.string().trim().min(1, 'Platform must not be empty')).optional(), + host_groups: z.array(z.string().trim().min(1, 'Host group ID must not be empty')).optional(), + tags: z.array(z.string().trim().min(1, 'Tag must not be empty')).optional(), + metadata: z.record(z.string(), z.unknown()).optional(), + }) + .catchall(z.unknown()) + +/** + * `api.IndicatorCreateReqV1` carries no `id` — the ID is assigned by CrowdStrike — + * and identifies the indicator by `type` plus `value`. `applied_globally` is the + * one property the spec marks `Required: true`, and it decides whether the + * indicator applies to the whole fleet, so it must be stated rather than defaulted. + */ +const createIndicatorPayloadSchema = indicatorPayloadSchema.extend({ + type: z.string().trim().min(1, 'Indicator type is required to create an indicator'), + value: z.string().trim().min(1, 'Indicator value is required to create an indicator'), + applied_globally: z.boolean({ + message: 'applied_globally is required; set it to false to scope the indicator to host_groups', + }), +}) + +/** + * `api.IndicatorUpdateReqV1` identifies the record by `id` and exposes no `type` + * or `value` — those are immutable — so an update missing an `id` cannot name a + * record and must be rejected before it reaches Falcon. + */ +const updateIndicatorPayloadSchema = indicatorPayloadSchema + .extend({ + id: z.string().trim().min(1, 'Each indicator to update requires an id'), + }) + .superRefine((value, ctx) => { + for (const immutable of ['type', 'value'] as const) { + if (value[immutable] !== undefined) { + ctx.addIssue({ + code: 'custom', + path: [immutable], + message: `${immutable} cannot be changed on an existing indicator; delete and recreate it instead`, + }) + } + } + }) + +const createIndicatorsSchema = baseRequestSchema.extend({ + operation: z.literal('crowdstrike_create_indicators'), + indicators: z + .array(createIndicatorPayloadSchema) + .min(1, 'At least one indicator is required') + .max(200, 'CrowdStrike accepts at most 200 indicators per request'), + comment: nonBlankQuerySchema('Comment'), + retrodetects: z.boolean().optional(), + ignoreWarnings: z.boolean().optional(), +}) + +const updateIndicatorsSchema = baseRequestSchema.extend({ + operation: z.literal('crowdstrike_update_indicators'), + indicators: z + .array(updateIndicatorPayloadSchema) + .min(1, 'At least one indicator is required') + .max(200, 'CrowdStrike accepts at most 200 indicators per request'), + comment: nonBlankQuerySchema('Comment'), + retrodetects: z.boolean().optional(), + ignoreWarnings: z.boolean().optional(), +}) + +const deleteIndicatorsSchema = baseRequestSchema + .extend({ + operation: z.literal('crowdstrike_delete_indicators'), + indicatorIds: idsSchema(1000, 'indicator ID').optional(), + filter: z.string().trim().min(1, 'filter cannot be empty').optional(), + comment: nonBlankQuerySchema('Comment'), + }) + .superRefine((value, ctx) => { + if (!value.filter && !value.indicatorIds?.length) { + ctx.addIssue({ + code: 'custom', + path: ['indicatorIds'], + message: 'Supply indicatorIds or a filter selecting the indicators to delete', + }) + } + + if (value.filter && value.indicatorIds?.length) { + ctx.addIssue({ + code: 'custom', + path: ['filter'], + message: + 'Supply indicatorIds or a filter, not both; CrowdStrike ignores the ID list whenever a filter is present', + }) + } + }) + +const queryVulnerabilitiesSchema = baseRequestSchema.extend({ + operation: z.literal('crowdstrike_query_vulnerabilities'), + filter: z.string().trim().min(1, 'Spotlight requires a filter expression'), + limit: z + .number() + .int() + .min(1, 'Limit must be at least 1') + .max(400, 'Limit must be at most 400') + .optional(), + after: nonBlankQuerySchema('After cursor'), + sort: nonBlankQuerySchema('Sort'), +}) + +const getVulnerabilityDetailsSchema = baseRequestSchema.extend({ + operation: z.literal('crowdstrike_get_vulnerability_details'), + vulnerabilityIds: idsSchema(400, 'vulnerability ID', true), +}) + +const initRtrSessionSchema = baseRequestSchema.extend({ + operation: z.literal('crowdstrike_init_rtr_session'), + deviceId: z.string().trim().min(1, 'deviceId is required'), + queueOffline: z.boolean().optional(), + origin: nonBlankQuerySchema('Origin'), +}) + +const executeRtrCommandSchema = baseRequestSchema.extend({ + operation: z.literal('crowdstrike_execute_rtr_command'), + sessionId: z.string().trim().min(1, 'sessionId is required'), + baseCommand: z.enum(RTR_READ_ONLY_BASE_COMMANDS, { + message: `baseCommand must be one of ${RTR_READ_ONLY_BASE_COMMANDS.join(', ')}`, + }), + commandString: z.string().trim().min(1, 'commandString is required'), +}) + +const getRtrCommandStatusSchema = baseRequestSchema.extend({ + operation: z.literal('crowdstrike_get_rtr_command_status'), + cloudRequestId: z.string().trim().min(1, 'cloudRequestId is required'), + sequenceId: z.number().int().nonnegative('sequenceId must be 0 or greater').optional(), +}) + +const deleteRtrSessionSchema = baseRequestSchema.extend({ + operation: z.literal('crowdstrike_delete_rtr_session'), + sessionId: z.string().trim().min(1, 'sessionId is required'), +}) + +const queryCasesSchema = baseRequestSchema.extend({ + operation: z.literal('crowdstrike_query_cases'), + filter: nonBlankQuerySchema('Filter'), + q: nonBlankQuerySchema('Query'), + limit: z + .number() + .int() + .min(1, 'Limit must be at least 1') + .max(10000, 'Limit must be at most 10000') + .optional(), + offset: z.number().int().nonnegative('Offset must be 0 or greater').optional(), + sort: nonBlankQuerySchema('Sort'), +}) + +const getCaseDetailsSchema = baseRequestSchema.extend({ + operation: z.literal('crowdstrike_get_case_details'), + caseIds: idsSchema(1000, 'case ID'), +}) + export const crowdstrikeQueryBodySchema = z.discriminatedUnion('operation', [ querySensorsSchema, getSensorDetailsSchema, getSensorAggregatesSchema, + queryAlertsSchema, + getAlertDetailsSchema, + updateAlertsSchema, + performHostActionSchema, + queryHostGroupsSchema, + getHostGroupDetailsSchema, + performHostGroupActionSchema, + queryIndicatorsSchema, + getIndicatorDetailsSchema, + createIndicatorsSchema, + updateIndicatorsSchema, + deleteIndicatorsSchema, + queryVulnerabilitiesSchema, + getVulnerabilityDetailsSchema, + initRtrSessionSchema, + executeRtrCommandSchema, + getRtrCommandStatusSchema, + deleteRtrSessionSchema, + queryCasesSchema, + getCaseDetailsSchema, ]) export const crowdstrikeQueryContract = defineRouteContract({ @@ -162,7 +1017,27 @@ export const crowdstrikeQueryContract = defineRouteContract({ body: crowdstrikeQueryBodySchema, response: { mode: 'json', - schema: z.union([crowdstrikeSensorsResponseSchema, crowdstrikeAggregatesResponseSchema]), + schema: z.union([ + crowdstrikeSensorsResponseSchema, + crowdstrikeAggregatesResponseSchema, + crowdstrikeAlertIdsResponseSchema, + crowdstrikeAlertsResponseSchema, + crowdstrikeUpdatedAlertsResponseSchema, + crowdstrikeAffectedEntitiesResponseSchema, + crowdstrikeHostGroupIdsResponseSchema, + crowdstrikeHostGroupsResponseSchema, + crowdstrikeIndicatorIdsResponseSchema, + crowdstrikeIndicatorsResponseSchema, + crowdstrikeDeletedIndicatorsResponseSchema, + crowdstrikeVulnerabilityIdsResponseSchema, + crowdstrikeVulnerabilitiesResponseSchema, + crowdstrikeRtrSessionResponseSchema, + crowdstrikeRtrCommandResponseSchema, + crowdstrikeRtrCommandStatusResponseSchema, + crowdstrikeRtrDeleteSessionResponseSchema, + crowdstrikeCaseIdsResponseSchema, + crowdstrikeCasesResponseSchema, + ]), }, }) diff --git a/apps/sim/lib/integrations/integrations.json b/apps/sim/lib/integrations/integrations.json index dc3834da15f..2c557cbfd74 100644 --- a/apps/sim/lib/integrations/integrations.json +++ b/apps/sim/lib/integrations/integrations.json @@ -4561,32 +4561,112 @@ "type": "crowdstrike", "slug": "crowdstrike", "name": "CrowdStrike", - "description": "Query CrowdStrike Identity Protection sensors and documented aggregates", - "longDescription": "Integrate CrowdStrike Identity Protection into workflows to search sensors, fetch documented sensor details by device ID, and run documented sensor aggregate queries.", + "description": "Investigate and respond to CrowdStrike Falcon alerts, hosts, IOCs, and vulnerabilities", + "longDescription": "Integrate CrowdStrike Falcon into workflows to triage alerts, contain hosts, manage host groups and custom indicators of compromise, review Spotlight vulnerabilities, run read-only Real Time Response commands, read Case Management cases, and query Identity Protection sensors.", "bgColor": "#E01F3D", "iconName": "CrowdStrikeIcon", "docsUrl": "https://docs.sim.ai/integrations/crowdstrike", "operations": [ + { + "name": "Query Alerts", + "description": "Search CrowdStrike Falcon alerts with a Falcon Query Language filter and return their composite IDs. Uses the current Alerts API (GET /alerts/queries/alerts/v2), which supersedes the deprecated Detects API. Requires the \"Alerts: Read\" API scope." + }, + { + "name": "Get Alert Details", + "description": "Get full CrowdStrike Falcon alert records for one or more composite alert IDs (POST /alerts/entities/alerts/v2). Requires the \"Alerts: Read\" API scope." + }, + { + "name": "Update Alerts", + "description": "Update CrowdStrike Falcon alerts by composite ID: change status, assign or unassign an analyst, add or remove tags, append a comment, or toggle visibility (PATCH /alerts/entities/alerts/v3). This modifies live alerts in the Falcon console. Requires the \"Alerts: Write\" API scope." + }, + { + "name": "Perform Host Action", + "description": "Act on CrowdStrike Falcon hosts (POST /devices/entities/devices-actions/v2). Actions: contain, lift_containment, hide_host, unhide_host, detection_suppress, detection_unsuppress. contain network-isolates the host so it can only reach the Falcon cloud; hide_host removes the host record from the console. Both are immediately disruptive. Up to 100 host IDs per call. Requires the \"Hosts: Write\" API scope." + }, + { + "name": "Query Host Groups", + "description": "Search CrowdStrike Falcon host groups with a Falcon Query Language filter and return their IDs (GET /devices/queries/host-groups/v1). Requires the \"Host groups: Read\" API scope." + }, + { + "name": "Get Host Group Details", + "description": "Get CrowdStrike Falcon host group records for one or more group IDs (GET /devices/entities/host-groups/v1). Requires the \"Host groups: Read\" API scope." + }, + { + "name": "Perform Host Group Action", + "description": "Add hosts to or remove hosts from a CrowdStrike Falcon static host group (POST /devices/entities/host-group-actions/v1). Group membership drives policy assignment, so changing it changes which policies apply to those hosts. Requires the \"Host groups: Write\" API scope." + }, + { + "name": "Query Indicators", + "description": "Search custom CrowdStrike Falcon indicators of compromise (IOCs) with a Falcon Query Language filter and return their IDs (GET /iocs/queries/indicators/v1). Requires the \"IOC Management: Read\" API scope." + }, + { + "name": "Get Indicator Details", + "description": "Get custom CrowdStrike Falcon indicator of compromise (IOC) records for one or more IOC IDs (GET /iocs/entities/indicators/v1). Requires the \"IOC Management: Read\" API scope." + }, + { + "name": "Create Indicators", + "description": "Create custom CrowdStrike Falcon indicators of compromise (POST /iocs/entities/indicators/v1). Each indicator can allow, detect, or block activity across the fleet, so a wrong value can suppress detections or break legitimate software. Requires the \"IOC Management: Write\" API scope." + }, + { + "name": "Update Indicators", + "description": "Update custom CrowdStrike Falcon indicators of compromise by ID (PATCH /iocs/entities/indicators/v1). DESTRUCTIVE: CrowdStrike blanks out any field you omit, so read each indicator with crowdstrike_get_indicator_details first and resend its full field set with your edits applied. Changing action or scope changes prevention behavior fleet-wide. type and value are immutable. Requires the \"IOC Management: Write\" API scope." + }, + { + "name": "Delete Indicators", + "description": "Permanently delete custom CrowdStrike Falcon indicators of compromise (DELETE /iocs/entities/indicators/v1). Cannot be undone; deleting a blocking indicator removes that protection from every host, and a broad filter can delete far more than intended. Supply an ID list or a filter, never both -- CrowdStrike lets a filter silently override the IDs, so this tool rejects that instead. Requires the \"IOC Management: Write\" API scope." + }, + { + "name": "Query Vulnerabilities", + "description": "Search CrowdStrike Falcon Spotlight vulnerabilities with a required Falcon Query Language filter and return their IDs (GET /spotlight/queries/vulnerabilities/v1). Requires the spotlight-vulnerabilities:read API scope, shown as \"Vulnerabilities: Read\" in the Falcon API client UI." + }, + { + "name": "Get Vulnerability Details", + "description": "Get CrowdStrike Falcon Spotlight vulnerability records for one or more vulnerability IDs, including CVE, affected host, application, and remediation details (GET /spotlight/entities/vulnerabilities/v2). Requires the spotlight-vulnerabilities:read API scope, shown as \"Vulnerabilities: Read\" in the Falcon API client UI." + }, + { + "name": "Init RTR Session", + "description": "Open a CrowdStrike Falcon Real Time Response session against a host so read-only commands can be run on it (POST /real-time-response/entities/sessions/v1). This connects a live remote shell to the endpoint. Requires the \"Real time response: Read\" API scope." + }, + { + "name": "Execute RTR Command", + "description": "Run a read-only Real Time Response command in an open CrowdStrike Falcon session (POST /real-time-response/entities/command/v1). baseCommand names the family only (cat, cd, clear, csrutil, env, eventlog, filehash, getsid, help, history, ipconfig, ls, mount, netstat, ps, reg); subcommands go in commandString. Host-modifying commands need the Active Responder or Admin endpoints. Requires the \"Real time response: Read\" API scope." + }, + { + "name": "Get RTR Command Status", + "description": "Get the status and output of a Real Time Response command by cloud request ID (GET /real-time-response/entities/command/v1). Long output is chunked across sequences, so increment the sequence ID to read the next chunk. Requires the \"Real time response: Read\" API scope." + }, + { + "name": "Delete RTR Session", + "description": "Close an open CrowdStrike Falcon Real Time Response session (DELETE /real-time-response/entities/sessions/v1). Requires the \"Real time response: Read\" API scope." + }, + { + "name": "Query Cases", + "description": "Search CrowdStrike Falcon Case Management cases with a Falcon Query Language filter and return their IDs (GET /cases/queries/cases/v1). Case Management supersedes the CrowdScore Incidents API, which CrowdStrike has removed from its published API spec. Requires the \"Cases: Read\" API scope." + }, + { + "name": "Get Case Details", + "description": "Get CrowdStrike Falcon Case Management case records for one or more case IDs (POST /cases/entities/cases/v2). Requires the \"Cases: Read\" API scope." + }, { "name": "Query Sensors", - "description": "Search CrowdStrike identity protection sensors by hostname, IP, or related fields" + "description": "Search CrowdStrike Identity Protection sensors -- the domain controllers Falcon Identity Protection monitors, not Falcon endpoint sensors -- and return their device IDs (GET /identity-protection/queries/devices/v1). Sort uses the dot form, for example status.desc. Requires the \"Identity Protection Entities: Read\" API scope, a separate entitlement from Hosts and Alerts." }, { "name": "Get Sensor Details", - "description": "Get documented CrowdStrike Identity Protection sensor details for one or more device IDs" + "description": "Get CrowdStrike Identity Protection sensor details for one or more device IDs (POST /identity-protection/entities/devices/GET/v1). These are the domain controllers Falcon Identity Protection monitors, not Falcon endpoint sensors. Requires the \"Identity Protection Entities: Read\" API scope." }, { "name": "Get Sensor Aggregates", - "description": "Get documented CrowdStrike Identity Protection sensor aggregates from a JSON aggregate query body" + "description": "Aggregate CrowdStrike Identity Protection sensors from a JSON aggregate query body (POST /identity-protection/aggregates/devices/GET/v1). These are the domain controllers Falcon Identity Protection monitors, not Falcon endpoint sensors. Requires the \"Identity Protection Entities: Read\" API scope." } ], - "operationCount": 3, + "operationCount": 23, "triggers": [], "triggerCount": 0, "authType": "api-key", "category": "tools", "integrationType": "security", - "tags": ["identity", "monitoring"] + "tags": ["identity", "monitoring", "incident-management", "automation"] }, { "type": "cursor_v2", diff --git a/apps/sim/tools/crowdstrike/create_indicators.ts b/apps/sim/tools/crowdstrike/create_indicators.ts new file mode 100644 index 00000000000..74d4a58e9f6 --- /dev/null +++ b/apps/sim/tools/crowdstrike/create_indicators.ts @@ -0,0 +1,226 @@ +import type { + CrowdStrikeCreateIndicatorsParams, + CrowdStrikeCreateIndicatorsResponse, +} from '@/tools/crowdstrike/types' +import type { ToolConfig } from '@/tools/types' + +export const crowdstrikeCreateIndicatorsTool: ToolConfig< + CrowdStrikeCreateIndicatorsParams, + CrowdStrikeCreateIndicatorsResponse +> = { + id: 'crowdstrike_create_indicators', + name: 'CrowdStrike Create Indicators', + description: + 'Create custom CrowdStrike Falcon indicators of compromise (POST /iocs/entities/indicators/v1). Each indicator can allow, detect, or block activity across the fleet, so a wrong value can suppress detections or break legitimate software. Requires the "IOC Management: Write" API scope.', + version: '1.0.0', + + params: { + clientId: { + type: 'string', + required: true, + visibility: 'user-only', + description: 'CrowdStrike Falcon API client ID', + }, + clientSecret: { + type: 'string', + required: true, + visibility: 'user-only', + description: 'CrowdStrike Falcon API client secret', + }, + cloud: { + type: 'string', + required: true, + visibility: 'user-only', + description: 'CrowdStrike Falcon cloud region', + }, + indicators: { + type: 'json', + required: true, + visibility: 'user-or-llm', + description: + 'JSON array of indicators to create. Each entry requires type, value, and applied_globally (boolean). type is one of sha256, md5, domain, ipv4, ipv6; action is one of no_action, allow, prevent_no_ui, prevent, detect; severity is one of informational, low, medium, high, critical; platforms entries are windows, mac, or linux. Other documented fields: host_groups (array), description, source, tags (array), expiration (ISO 8601), mobile_action, metadata ({ filename }). Either applied_globally must be true or host_groups must be supplied. Tenants can extend these value sets, so treat them as the documented defaults rather than a closed list.', + }, + comment: { + type: 'string', + required: false, + visibility: 'user-or-llm', + description: 'Audit comment explaining why these indicators were created', + }, + retrodetects: { + type: 'boolean', + required: false, + visibility: 'user-or-llm', + description: 'Whether to generate retroactive detections for the new indicators', + }, + ignoreWarnings: { + type: 'boolean', + required: false, + visibility: 'user-or-llm', + description: 'Whether to create the indicators even when CrowdStrike returns warnings', + }, + }, + + request: { + url: '/api/tools/crowdstrike/query', + method: 'POST', + headers: () => ({ + 'Content-Type': 'application/json', + }), + body: (params) => ({ + cloud: params.cloud, + clientId: params.clientId, + clientSecret: params.clientSecret, + comment: params.comment, + ignoreWarnings: params.ignoreWarnings, + indicators: params.indicators, + operation: 'crowdstrike_create_indicators', + retrodetects: params.retrodetects, + }), + }, + + transformResponse: async (response) => { + const data = await response.json() + + if (!response.ok || data.success === false) { + throw new Error(data.error || 'Failed to create CrowdStrike indicators') + } + + return { + success: true, + output: data.output, + } + }, + + outputs: { + indicators: { + type: 'array', + description: 'Created CrowdStrike indicator records', + items: { + type: 'object', + properties: { + id: { type: 'string', description: 'Indicator identifier', optional: true }, + type: { type: 'string', description: 'Indicator type', optional: true }, + value: { type: 'string', description: 'Indicator value', optional: true }, + action: { + type: 'string', + description: 'Action taken when the indicator matches', + optional: true, + }, + mobileAction: { + type: 'string', + description: 'Action taken on mobile platforms when the indicator matches', + optional: true, + }, + severity: { type: 'string', description: 'Indicator severity', optional: true }, + description: { type: 'string', description: 'Indicator description', optional: true }, + source: { type: 'string', description: 'Indicator source', optional: true }, + appliedGlobally: { + type: 'boolean', + description: 'Whether the indicator applies to all hosts', + optional: true, + }, + platforms: { + type: 'array', + description: 'Platforms the indicator applies to', + optional: true, + items: { type: 'string' }, + }, + hostGroups: { + type: 'array', + description: 'Host group IDs the indicator is scoped to', + optional: true, + items: { type: 'string' }, + }, + tags: { + type: 'array', + description: 'Tags applied to the indicator', + optional: true, + items: { type: 'string' }, + }, + expiration: { + type: 'string', + description: 'Indicator expiration timestamp', + optional: true, + }, + expired: { + type: 'boolean', + description: 'Whether the indicator has expired', + optional: true, + }, + deleted: { + type: 'boolean', + description: 'Whether the indicator is deleted', + optional: true, + }, + fromParent: { + type: 'boolean', + description: 'Whether the indicator was inherited from a parent CID', + optional: true, + }, + parentCidName: { type: 'string', description: 'Parent CID name', optional: true }, + createdBy: { + type: 'string', + description: 'User who created the indicator', + optional: true, + }, + createdOn: { + type: 'string', + description: 'Indicator creation timestamp', + optional: true, + }, + modifiedBy: { + type: 'string', + description: 'User who last modified the indicator', + optional: true, + }, + modifiedOn: { + type: 'string', + description: 'Indicator modification timestamp', + optional: true, + }, + metadata: { + type: 'json', + description: 'File metadata CrowdStrike resolved for the indicator', + optional: true, + properties: { + avHits: { type: 'number', description: 'Antivirus hit count', optional: true }, + companyName: { type: 'string', description: 'Company name', optional: true }, + fileDescription: { type: 'string', description: 'File description', optional: true }, + fileVersion: { type: 'string', description: 'File version', optional: true }, + filename: { type: 'string', description: 'File name', optional: true }, + originalFilename: { + type: 'string', + description: 'Original file name', + optional: true, + }, + productName: { type: 'string', description: 'Product name', optional: true }, + productVersion: { type: 'string', description: 'Product version', optional: true }, + signed: { + type: 'boolean', + description: 'Whether the file is signed', + optional: true, + }, + }, + }, + }, + }, + }, + count: { + type: 'number', + description: 'Number of indicators created', + }, + errors: { + type: 'array', + description: 'Errors CrowdStrike returned alongside a partially successful response', + optional: true, + items: { + type: 'object', + properties: { + code: { type: 'number', description: 'CrowdStrike error code', optional: true }, + id: { type: 'string', description: 'Identifier the error applies to', optional: true }, + message: { type: 'string', description: 'Error message', optional: true }, + }, + }, + }, + }, +} diff --git a/apps/sim/tools/crowdstrike/delete_indicators.ts b/apps/sim/tools/crowdstrike/delete_indicators.ts new file mode 100644 index 00000000000..c7773f75151 --- /dev/null +++ b/apps/sim/tools/crowdstrike/delete_indicators.ts @@ -0,0 +1,111 @@ +import type { + CrowdStrikeDeleteIndicatorsParams, + CrowdStrikeDeleteIndicatorsResponse, +} from '@/tools/crowdstrike/types' +import type { ToolConfig } from '@/tools/types' + +export const crowdstrikeDeleteIndicatorsTool: ToolConfig< + CrowdStrikeDeleteIndicatorsParams, + CrowdStrikeDeleteIndicatorsResponse +> = { + id: 'crowdstrike_delete_indicators', + name: 'CrowdStrike Delete Indicators', + description: + 'Permanently delete custom CrowdStrike Falcon indicators of compromise (DELETE /iocs/entities/indicators/v1). Cannot be undone; deleting a blocking indicator removes that protection from every host, and a broad filter can delete far more than intended. Supply an ID list or a filter, never both -- CrowdStrike lets a filter silently override the IDs, so this tool rejects that instead. Requires the "IOC Management: Write" API scope.', + version: '1.0.0', + + params: { + clientId: { + type: 'string', + required: true, + visibility: 'user-only', + description: 'CrowdStrike Falcon API client ID', + }, + clientSecret: { + type: 'string', + required: true, + visibility: 'user-only', + description: 'CrowdStrike Falcon API client secret', + }, + cloud: { + type: 'string', + required: true, + visibility: 'user-only', + description: 'CrowdStrike Falcon cloud region', + }, + indicatorIds: { + type: 'json', + required: false, + visibility: 'user-or-llm', + description: 'JSON array of CrowdStrike IOC IDs to delete. Cannot be combined with a filter.', + }, + filter: { + type: 'string', + required: false, + visibility: 'user-or-llm', + description: + 'Falcon Query Language filter selecting indicators to delete in bulk. Cannot be combined with an ID list.', + }, + comment: { + type: 'string', + required: false, + visibility: 'user-or-llm', + description: 'Audit comment explaining why these indicators were deleted', + }, + }, + + request: { + url: '/api/tools/crowdstrike/query', + method: 'POST', + headers: () => ({ + 'Content-Type': 'application/json', + }), + body: (params) => ({ + cloud: params.cloud, + clientId: params.clientId, + clientSecret: params.clientSecret, + comment: params.comment, + filter: params.filter, + indicatorIds: params.indicatorIds, + operation: 'crowdstrike_delete_indicators', + }), + }, + + transformResponse: async (response) => { + const data = await response.json() + + if (!response.ok || data.success === false) { + throw new Error(data.error || 'Failed to delete CrowdStrike indicators') + } + + return { + success: true, + output: data.output, + } + }, + + outputs: { + deletedIds: { + type: 'array', + description: 'IOC IDs CrowdStrike deleted', + items: { type: 'string' }, + }, + count: { + type: 'number', + description: 'Number of indicators deleted', + }, + errors: { + type: 'array', + description: 'Errors CrowdStrike returned alongside a partially successful response', + optional: true, + items: { + type: 'object', + properties: { + code: { type: 'number', description: 'CrowdStrike error code', optional: true }, + id: { type: 'string', description: 'Identifier the error applies to', optional: true }, + message: { type: 'string', description: 'Error message', optional: true }, + }, + }, + }, + }, +} diff --git a/apps/sim/tools/crowdstrike/delete_rtr_session.ts b/apps/sim/tools/crowdstrike/delete_rtr_session.ts new file mode 100644 index 00000000000..23ebdaa9fb9 --- /dev/null +++ b/apps/sim/tools/crowdstrike/delete_rtr_session.ts @@ -0,0 +1,89 @@ +import type { + CrowdStrikeDeleteRtrSessionParams, + CrowdStrikeDeleteRtrSessionResponse, +} from '@/tools/crowdstrike/types' +import type { ToolConfig } from '@/tools/types' + +export const crowdstrikeDeleteRtrSessionTool: ToolConfig< + CrowdStrikeDeleteRtrSessionParams, + CrowdStrikeDeleteRtrSessionResponse +> = { + id: 'crowdstrike_delete_rtr_session', + name: 'CrowdStrike Delete RTR Session', + description: + 'Close an open CrowdStrike Falcon Real Time Response session (DELETE /real-time-response/entities/sessions/v1). Requires the "Real time response: Read" API scope.', + version: '1.0.0', + + params: { + clientId: { + type: 'string', + required: true, + visibility: 'user-only', + description: 'CrowdStrike Falcon API client ID', + }, + clientSecret: { + type: 'string', + required: true, + visibility: 'user-only', + description: 'CrowdStrike Falcon API client secret', + }, + cloud: { + type: 'string', + required: true, + visibility: 'user-only', + description: 'CrowdStrike Falcon cloud region', + }, + sessionId: { + type: 'string', + required: true, + visibility: 'user-or-llm', + description: 'RTR session ID to close', + }, + }, + + request: { + url: '/api/tools/crowdstrike/query', + method: 'POST', + headers: () => ({ + 'Content-Type': 'application/json', + }), + body: (params) => ({ + cloud: params.cloud, + clientId: params.clientId, + clientSecret: params.clientSecret, + operation: 'crowdstrike_delete_rtr_session', + sessionId: params.sessionId, + }), + }, + + transformResponse: async (response) => { + const data = await response.json() + + if (!response.ok || data.success === false) { + throw new Error(data.error || 'Failed to delete CrowdStrike RTR session') + } + + return { + success: true, + output: data.output, + } + }, + + outputs: { + sessionId: { type: 'string', description: 'RTR session ID that was closed' }, + deleted: { type: 'boolean', description: 'Whether CrowdStrike accepted the session deletion' }, + errors: { + type: 'array', + description: 'Errors CrowdStrike returned alongside a partially successful response', + optional: true, + items: { + type: 'object', + properties: { + code: { type: 'number', description: 'CrowdStrike error code', optional: true }, + id: { type: 'string', description: 'Identifier the error applies to', optional: true }, + message: { type: 'string', description: 'Error message', optional: true }, + }, + }, + }, + }, +} diff --git a/apps/sim/tools/crowdstrike/execute_rtr_command.ts b/apps/sim/tools/crowdstrike/execute_rtr_command.ts new file mode 100644 index 00000000000..d50a890a2ac --- /dev/null +++ b/apps/sim/tools/crowdstrike/execute_rtr_command.ts @@ -0,0 +1,114 @@ +import type { + CrowdStrikeExecuteRtrCommandParams, + CrowdStrikeExecuteRtrCommandResponse, +} from '@/tools/crowdstrike/types' +import type { ToolConfig } from '@/tools/types' + +export const crowdstrikeExecuteRtrCommandTool: ToolConfig< + CrowdStrikeExecuteRtrCommandParams, + CrowdStrikeExecuteRtrCommandResponse +> = { + id: 'crowdstrike_execute_rtr_command', + name: 'CrowdStrike Execute RTR Command', + description: + 'Run a read-only Real Time Response command in an open CrowdStrike Falcon session (POST /real-time-response/entities/command/v1). baseCommand names the family only (cat, cd, clear, csrutil, env, eventlog, filehash, getsid, help, history, ipconfig, ls, mount, netstat, ps, reg); subcommands go in commandString. Host-modifying commands need the Active Responder or Admin endpoints. Requires the "Real time response: Read" API scope.', + version: '1.0.0', + + params: { + clientId: { + type: 'string', + required: true, + visibility: 'user-only', + description: 'CrowdStrike Falcon API client ID', + }, + clientSecret: { + type: 'string', + required: true, + visibility: 'user-only', + description: 'CrowdStrike Falcon API client secret', + }, + cloud: { + type: 'string', + required: true, + visibility: 'user-only', + description: 'CrowdStrike Falcon cloud region', + }, + sessionId: { + type: 'string', + required: true, + visibility: 'user-or-llm', + description: 'RTR session ID returned by Init RTR Session', + }, + baseCommand: { + type: 'string', + required: true, + visibility: 'user-or-llm', + description: + 'Read-only RTR base command family, one of: cat, cd, clear, csrutil, env, eventlog, filehash, getsid, help, history, ipconfig, ls, mount, netstat, ps, reg. Subcommands belong in commandString, not here.', + }, + commandString: { + type: 'string', + required: true, + visibility: 'user-or-llm', + description: + 'Full command line to run, such as "ls C:\\Windows" or "reg query HKLM\\Software"', + }, + }, + + request: { + url: '/api/tools/crowdstrike/query', + method: 'POST', + headers: () => ({ + 'Content-Type': 'application/json', + }), + body: (params) => ({ + baseCommand: params.baseCommand, + cloud: params.cloud, + clientId: params.clientId, + clientSecret: params.clientSecret, + commandString: params.commandString, + operation: 'crowdstrike_execute_rtr_command', + sessionId: params.sessionId, + }), + }, + + transformResponse: async (response) => { + const data = await response.json() + + if (!response.ok || data.success === false) { + throw new Error(data.error || 'Failed to execute CrowdStrike RTR command') + } + + return { + success: true, + output: data.output, + } + }, + + outputs: { + cloudRequestId: { + type: 'string', + description: 'Cloud request ID to poll for command output', + optional: true, + }, + sessionId: { type: 'string', description: 'RTR session the command ran in', optional: true }, + queuedCommandOffline: { + type: 'boolean', + description: 'Whether the command was queued for an offline host', + optional: true, + }, + errors: { + type: 'array', + description: 'Errors CrowdStrike returned alongside a partially successful response', + optional: true, + items: { + type: 'object', + properties: { + code: { type: 'number', description: 'CrowdStrike error code', optional: true }, + id: { type: 'string', description: 'Identifier the error applies to', optional: true }, + message: { type: 'string', description: 'Error message', optional: true }, + }, + }, + }, + }, +} diff --git a/apps/sim/tools/crowdstrike/get_alert_details.ts b/apps/sim/tools/crowdstrike/get_alert_details.ts new file mode 100644 index 00000000000..1b7ee1ced28 --- /dev/null +++ b/apps/sim/tools/crowdstrike/get_alert_details.ts @@ -0,0 +1,253 @@ +import type { + CrowdStrikeGetAlertDetailsParams, + CrowdStrikeGetAlertDetailsResponse, +} from '@/tools/crowdstrike/types' +import type { ToolConfig } from '@/tools/types' + +export const crowdstrikeGetAlertDetailsTool: ToolConfig< + CrowdStrikeGetAlertDetailsParams, + CrowdStrikeGetAlertDetailsResponse +> = { + id: 'crowdstrike_get_alert_details', + name: 'CrowdStrike Get Alert Details', + description: + 'Get full CrowdStrike Falcon alert records for one or more composite alert IDs (POST /alerts/entities/alerts/v2). Requires the "Alerts: Read" API scope.', + version: '1.0.0', + + params: { + clientId: { + type: 'string', + required: true, + visibility: 'user-only', + description: 'CrowdStrike Falcon API client ID', + }, + clientSecret: { + type: 'string', + required: true, + visibility: 'user-only', + description: 'CrowdStrike Falcon API client secret', + }, + cloud: { + type: 'string', + required: true, + visibility: 'user-only', + description: 'CrowdStrike Falcon cloud region', + }, + compositeIds: { + type: 'json', + required: true, + visibility: 'user-or-llm', + description: 'JSON array of CrowdStrike composite alert IDs', + }, + includeHidden: { + type: 'boolean', + required: false, + visibility: 'user-or-llm', + description: 'Include previously hidden alerts (CrowdStrike defaults this to true)', + }, + }, + + request: { + url: '/api/tools/crowdstrike/query', + method: 'POST', + headers: () => ({ + 'Content-Type': 'application/json', + }), + body: (params) => ({ + cloud: params.cloud, + clientId: params.clientId, + clientSecret: params.clientSecret, + compositeIds: params.compositeIds, + includeHidden: params.includeHidden, + operation: 'crowdstrike_get_alert_details', + }), + }, + + transformResponse: async (response) => { + const data = await response.json() + + if (!response.ok || data.success === false) { + throw new Error(data.error || 'Failed to fetch CrowdStrike alert details') + } + + return { + success: true, + output: data.output, + } + }, + + outputs: { + alerts: { + type: 'array', + description: 'CrowdStrike alert records', + items: { + type: 'object', + properties: { + compositeId: { type: 'string', description: 'Composite alert ID', optional: true }, + id: { type: 'string', description: 'Alert ID', optional: true }, + cid: { type: 'string', description: 'CrowdStrike customer identifier', optional: true }, + aggregateId: { type: 'string', description: 'Aggregate identifier', optional: true }, + agentId: { type: 'string', description: 'Agent (sensor) identifier', optional: true }, + deviceId: { + type: 'string', + description: 'Device identifier from the alert device', + optional: true, + }, + hostname: { + type: 'string', + description: 'Hostname from the alert device', + optional: true, + }, + name: { type: 'string', description: 'Alert name', optional: true }, + displayName: { type: 'string', description: 'Alert display name', optional: true }, + description: { type: 'string', description: 'Alert description', optional: true }, + type: { type: 'string', description: 'Alert type', optional: true }, + product: { + type: 'string', + description: 'Falcon product that raised the alert', + optional: true, + }, + platform: { + type: 'string', + description: 'Platform the alert was raised on', + optional: true, + }, + severity: { type: 'number', description: 'Numeric severity', optional: true }, + severityName: { type: 'string', description: 'Severity name', optional: true }, + confidence: { type: 'number', description: 'Confidence score', optional: true }, + status: { type: 'string', description: 'Alert status', optional: true }, + assignedToName: { type: 'string', description: 'Assignee display name', optional: true }, + assignedToUid: { type: 'string', description: 'Assignee user ID', optional: true }, + assignedToUuid: { type: 'string', description: 'Assignee user UUID', optional: true }, + tactic: { type: 'string', description: 'MITRE ATT&CK tactic', optional: true }, + tacticId: { type: 'string', description: 'MITRE ATT&CK tactic ID', optional: true }, + technique: { type: 'string', description: 'MITRE ATT&CK technique', optional: true }, + techniqueId: { type: 'string', description: 'MITRE ATT&CK technique ID', optional: true }, + scenario: { type: 'string', description: 'Alert scenario', optional: true }, + objective: { type: 'string', description: 'Adversary objective', optional: true }, + resolution: { type: 'string', description: 'Alert resolution', optional: true }, + showInUi: { + type: 'boolean', + description: 'Whether the alert is shown in Falcon', + optional: true, + }, + tags: { + type: 'array', + description: 'Tags applied to the alert', + optional: true, + items: { type: 'string' }, + }, + filename: { type: 'string', description: 'Triggering file name', optional: true }, + filepath: { type: 'string', description: 'Triggering file path', optional: true }, + cmdline: { type: 'string', description: 'Triggering command line', optional: true }, + sha256: { type: 'string', description: 'SHA256 of the triggering file', optional: true }, + sha1: { type: 'string', description: 'SHA1 of the triggering file', optional: true }, + md5: { type: 'string', description: 'MD5 of the triggering file', optional: true }, + userName: { + type: 'string', + description: 'User name associated with the alert', + optional: true, + }, + userId: { + type: 'string', + description: 'User ID associated with the alert', + optional: true, + }, + patternId: { type: 'number', description: 'Detection pattern ID', optional: true }, + falconHostLink: { + type: 'string', + description: 'Deep link into the Falcon console', + optional: true, + }, + controlGraphId: { + type: 'string', + description: 'Control graph identifier', + optional: true, + }, + external: { + type: 'boolean', + description: 'Whether the alert is external', + optional: true, + }, + emailSent: { + type: 'boolean', + description: 'Whether a notification email was sent', + optional: true, + }, + isAggregated: { + type: 'boolean', + description: 'Whether the alert is aggregated', + optional: true, + }, + isFalconPlatformIoa: { + type: 'boolean', + description: 'Whether the alert is a Falcon platform IOA', + optional: true, + }, + dataDomains: { + type: 'array', + description: 'Data domains the alert belongs to', + optional: true, + items: { type: 'string' }, + }, + iocValues: { + type: 'array', + description: 'Indicator values associated with the alert', + optional: true, + items: { type: 'string' }, + }, + linkedCaseIds: { + type: 'array', + description: 'Case IDs linked to the alert', + optional: true, + items: { type: 'string' }, + }, + linkedBehavioralDetections: { + type: 'array', + description: 'Behavioral detection IDs linked to the alert', + optional: true, + items: { type: 'string' }, + }, + timestamp: { type: 'string', description: 'Alert timestamp', optional: true }, + createdTimestamp: { + type: 'string', + description: 'Alert creation timestamp', + optional: true, + }, + updatedTimestamp: { + type: 'string', + description: 'Alert update timestamp', + optional: true, + }, + crawledTimestamp: { + type: 'string', + description: 'Alert crawl timestamp', + optional: true, + }, + contextTimestamp: { + type: 'string', + description: 'Alert context timestamp', + optional: true, + }, + }, + }, + }, + count: { + type: 'number', + description: 'Number of alerts returned', + }, + errors: { + type: 'array', + description: 'Errors CrowdStrike returned alongside a partially successful response', + optional: true, + items: { + type: 'object', + properties: { + code: { type: 'number', description: 'CrowdStrike error code', optional: true }, + id: { type: 'string', description: 'Identifier the error applies to', optional: true }, + message: { type: 'string', description: 'Error message', optional: true }, + }, + }, + }, + }, +} diff --git a/apps/sim/tools/crowdstrike/get_case_details.ts b/apps/sim/tools/crowdstrike/get_case_details.ts new file mode 100644 index 00000000000..9df58b69e44 --- /dev/null +++ b/apps/sim/tools/crowdstrike/get_case_details.ts @@ -0,0 +1,187 @@ +import type { + CrowdStrikeGetCaseDetailsParams, + CrowdStrikeGetCaseDetailsResponse, +} from '@/tools/crowdstrike/types' +import type { ToolConfig } from '@/tools/types' + +export const crowdstrikeGetCaseDetailsTool: ToolConfig< + CrowdStrikeGetCaseDetailsParams, + CrowdStrikeGetCaseDetailsResponse +> = { + id: 'crowdstrike_get_case_details', + name: 'CrowdStrike Get Case Details', + description: + 'Get CrowdStrike Falcon Case Management case records for one or more case IDs (POST /cases/entities/cases/v2). Requires the "Cases: Read" API scope.', + version: '1.0.0', + + params: { + clientId: { + type: 'string', + required: true, + visibility: 'user-only', + description: 'CrowdStrike Falcon API client ID', + }, + clientSecret: { + type: 'string', + required: true, + visibility: 'user-only', + description: 'CrowdStrike Falcon API client secret', + }, + cloud: { + type: 'string', + required: true, + visibility: 'user-only', + description: 'CrowdStrike Falcon cloud region', + }, + caseIds: { + type: 'json', + required: true, + visibility: 'user-or-llm', + description: 'JSON array of CrowdStrike case IDs', + }, + }, + + request: { + url: '/api/tools/crowdstrike/query', + method: 'POST', + headers: () => ({ + 'Content-Type': 'application/json', + }), + body: (params) => ({ + caseIds: params.caseIds, + cloud: params.cloud, + clientId: params.clientId, + clientSecret: params.clientSecret, + operation: 'crowdstrike_get_case_details', + }), + }, + + transformResponse: async (response) => { + const data = await response.json() + + if (!response.ok || data.success === false) { + throw new Error(data.error || 'Failed to fetch CrowdStrike case details') + } + + return { + success: true, + output: data.output, + } + }, + + outputs: { + cases: { + type: 'array', + description: 'CrowdStrike Case Management case records', + items: { + type: 'object', + properties: { + id: { type: 'string', description: 'Case identifier', optional: true }, + cid: { type: 'string', description: 'CrowdStrike customer identifier', optional: true }, + name: { type: 'string', description: 'Case name', optional: true }, + description: { type: 'string', description: 'Case description', optional: true }, + descriptionFormat: { + type: 'string', + description: 'Format of the case description', + optional: true, + }, + status: { type: 'string', description: 'Case status', optional: true }, + severity: { type: 'number', description: 'Numeric case severity', optional: true }, + severityLevel: { + type: 'string', + description: 'Case severity level name', + optional: true, + }, + referenceId: { + type: 'string', + description: 'Human-readable case reference ID', + optional: true, + }, + version: { + type: 'number', + description: 'Case version for optimistic concurrency', + optional: true, + }, + tags: { + type: 'array', + description: 'Tags applied to the case', + optional: true, + items: { type: 'string' }, + }, + assignedTo: { + type: 'json', + description: 'Falcon user the case is assigned to', + optional: true, + properties: { + uuid: { type: 'string', description: 'Falcon user UUID', optional: true }, + email: { type: 'string', description: 'Falcon user email', optional: true }, + fullName: { type: 'string', description: 'Falcon user full name', optional: true }, + }, + }, + createdBy: { + type: 'json', + description: 'Falcon user who created the case', + optional: true, + properties: { + uuid: { type: 'string', description: 'Falcon user UUID', optional: true }, + email: { type: 'string', description: 'Falcon user email', optional: true }, + fullName: { type: 'string', description: 'Falcon user full name', optional: true }, + }, + }, + lastUpdatedBy: { + type: 'json', + description: 'Falcon user who last updated the case', + optional: true, + properties: { + uuid: { type: 'string', description: 'Falcon user UUID', optional: true }, + email: { type: 'string', description: 'Falcon user email', optional: true }, + fullName: { type: 'string', description: 'Falcon user full name', optional: true }, + }, + }, + createdTimestamp: { + type: 'string', + description: 'Case creation timestamp', + optional: true, + }, + updatedTimestamp: { + type: 'string', + description: 'Case update timestamp', + optional: true, + }, + startTimestamp: { type: 'string', description: 'Case start timestamp', optional: true }, + endTimestamp: { type: 'string', description: 'Case end timestamp', optional: true }, + templateId: { type: 'string', description: 'Case template identifier', optional: true }, + templateName: { type: 'string', description: 'Case template name', optional: true }, + slaId: { + type: 'string', + description: 'SLA identifier applied to the case', + optional: true, + }, + slaName: { type: 'string', description: 'SLA name applied to the case', optional: true }, + isReadOnly: { + type: 'boolean', + description: 'Whether the case is read only', + optional: true, + }, + }, + }, + }, + count: { + type: 'number', + description: 'Number of cases returned', + }, + errors: { + type: 'array', + description: 'Errors CrowdStrike returned alongside a partially successful response', + optional: true, + items: { + type: 'object', + properties: { + code: { type: 'number', description: 'CrowdStrike error code', optional: true }, + id: { type: 'string', description: 'Identifier the error applies to', optional: true }, + message: { type: 'string', description: 'Error message', optional: true }, + }, + }, + }, + }, +} diff --git a/apps/sim/tools/crowdstrike/get_host_group_details.ts b/apps/sim/tools/crowdstrike/get_host_group_details.ts new file mode 100644 index 00000000000..0c411c11311 --- /dev/null +++ b/apps/sim/tools/crowdstrike/get_host_group_details.ts @@ -0,0 +1,129 @@ +import type { + CrowdStrikeGetHostGroupDetailsParams, + CrowdStrikeGetHostGroupDetailsResponse, +} from '@/tools/crowdstrike/types' +import type { ToolConfig } from '@/tools/types' + +export const crowdstrikeGetHostGroupDetailsTool: ToolConfig< + CrowdStrikeGetHostGroupDetailsParams, + CrowdStrikeGetHostGroupDetailsResponse +> = { + id: 'crowdstrike_get_host_group_details', + name: 'CrowdStrike Get Host Group Details', + description: + 'Get CrowdStrike Falcon host group records for one or more group IDs (GET /devices/entities/host-groups/v1). Requires the "Host groups: Read" API scope.', + version: '1.0.0', + + params: { + clientId: { + type: 'string', + required: true, + visibility: 'user-only', + description: 'CrowdStrike Falcon API client ID', + }, + clientSecret: { + type: 'string', + required: true, + visibility: 'user-only', + description: 'CrowdStrike Falcon API client secret', + }, + cloud: { + type: 'string', + required: true, + visibility: 'user-only', + description: 'CrowdStrike Falcon cloud region', + }, + hostGroupIds: { + type: 'json', + required: true, + visibility: 'user-or-llm', + description: 'JSON array of CrowdStrike host group IDs', + }, + }, + + request: { + url: '/api/tools/crowdstrike/query', + method: 'POST', + headers: () => ({ + 'Content-Type': 'application/json', + }), + body: (params) => ({ + cloud: params.cloud, + clientId: params.clientId, + clientSecret: params.clientSecret, + hostGroupIds: params.hostGroupIds, + operation: 'crowdstrike_get_host_group_details', + }), + }, + + transformResponse: async (response) => { + const data = await response.json() + + if (!response.ok || data.success === false) { + throw new Error(data.error || 'Failed to fetch CrowdStrike host group details') + } + + return { + success: true, + output: data.output, + } + }, + + outputs: { + hostGroups: { + type: 'array', + description: 'CrowdStrike host group records', + items: { + type: 'object', + properties: { + id: { type: 'string', description: 'Host group identifier', optional: true }, + name: { type: 'string', description: 'Host group name', optional: true }, + description: { type: 'string', description: 'Host group description', optional: true }, + groupType: { + type: 'string', + description: 'Group type (static, dynamic, staticByID)', + optional: true, + }, + assignmentRule: { + type: 'string', + description: 'FQL assignment rule for dynamic groups', + optional: true, + }, + createdBy: { type: 'string', description: 'User who created the group', optional: true }, + createdTimestamp: { + type: 'string', + description: 'Group creation timestamp', + optional: true, + }, + modifiedBy: { + type: 'string', + description: 'User who last modified the group', + optional: true, + }, + modifiedTimestamp: { + type: 'string', + description: 'Group modification timestamp', + optional: true, + }, + }, + }, + }, + count: { + type: 'number', + description: 'Number of host groups returned', + }, + errors: { + type: 'array', + description: 'Errors CrowdStrike returned alongside a partially successful response', + optional: true, + items: { + type: 'object', + properties: { + code: { type: 'number', description: 'CrowdStrike error code', optional: true }, + id: { type: 'string', description: 'Identifier the error applies to', optional: true }, + message: { type: 'string', description: 'Error message', optional: true }, + }, + }, + }, + }, +} diff --git a/apps/sim/tools/crowdstrike/get_indicator_details.ts b/apps/sim/tools/crowdstrike/get_indicator_details.ts new file mode 100644 index 00000000000..abf864239ce --- /dev/null +++ b/apps/sim/tools/crowdstrike/get_indicator_details.ts @@ -0,0 +1,204 @@ +import type { + CrowdStrikeGetIndicatorDetailsParams, + CrowdStrikeGetIndicatorDetailsResponse, +} from '@/tools/crowdstrike/types' +import type { ToolConfig } from '@/tools/types' + +export const crowdstrikeGetIndicatorDetailsTool: ToolConfig< + CrowdStrikeGetIndicatorDetailsParams, + CrowdStrikeGetIndicatorDetailsResponse +> = { + id: 'crowdstrike_get_indicator_details', + name: 'CrowdStrike Get Indicator Details', + description: + 'Get custom CrowdStrike Falcon indicator of compromise (IOC) records for one or more IOC IDs (GET /iocs/entities/indicators/v1). Requires the "IOC Management: Read" API scope.', + version: '1.0.0', + + params: { + clientId: { + type: 'string', + required: true, + visibility: 'user-only', + description: 'CrowdStrike Falcon API client ID', + }, + clientSecret: { + type: 'string', + required: true, + visibility: 'user-only', + description: 'CrowdStrike Falcon API client secret', + }, + cloud: { + type: 'string', + required: true, + visibility: 'user-only', + description: 'CrowdStrike Falcon cloud region', + }, + indicatorIds: { + type: 'json', + required: true, + visibility: 'user-or-llm', + description: 'JSON array of CrowdStrike IOC IDs', + }, + }, + + request: { + url: '/api/tools/crowdstrike/query', + method: 'POST', + headers: () => ({ + 'Content-Type': 'application/json', + }), + body: (params) => ({ + cloud: params.cloud, + clientId: params.clientId, + clientSecret: params.clientSecret, + indicatorIds: params.indicatorIds, + operation: 'crowdstrike_get_indicator_details', + }), + }, + + transformResponse: async (response) => { + const data = await response.json() + + if (!response.ok || data.success === false) { + throw new Error(data.error || 'Failed to fetch CrowdStrike indicator details') + } + + return { + success: true, + output: data.output, + } + }, + + outputs: { + indicators: { + type: 'array', + description: 'CrowdStrike indicator of compromise records', + items: { + type: 'object', + properties: { + id: { type: 'string', description: 'Indicator identifier', optional: true }, + type: { type: 'string', description: 'Indicator type', optional: true }, + value: { type: 'string', description: 'Indicator value', optional: true }, + action: { + type: 'string', + description: 'Action taken when the indicator matches', + optional: true, + }, + mobileAction: { + type: 'string', + description: 'Action taken on mobile platforms when the indicator matches', + optional: true, + }, + severity: { type: 'string', description: 'Indicator severity', optional: true }, + description: { type: 'string', description: 'Indicator description', optional: true }, + source: { type: 'string', description: 'Indicator source', optional: true }, + appliedGlobally: { + type: 'boolean', + description: 'Whether the indicator applies to all hosts', + optional: true, + }, + platforms: { + type: 'array', + description: 'Platforms the indicator applies to', + optional: true, + items: { type: 'string' }, + }, + hostGroups: { + type: 'array', + description: 'Host group IDs the indicator is scoped to', + optional: true, + items: { type: 'string' }, + }, + tags: { + type: 'array', + description: 'Tags applied to the indicator', + optional: true, + items: { type: 'string' }, + }, + expiration: { + type: 'string', + description: 'Indicator expiration timestamp', + optional: true, + }, + expired: { + type: 'boolean', + description: 'Whether the indicator has expired', + optional: true, + }, + deleted: { + type: 'boolean', + description: 'Whether the indicator is deleted', + optional: true, + }, + fromParent: { + type: 'boolean', + description: 'Whether the indicator was inherited from a parent CID', + optional: true, + }, + parentCidName: { type: 'string', description: 'Parent CID name', optional: true }, + createdBy: { + type: 'string', + description: 'User who created the indicator', + optional: true, + }, + createdOn: { + type: 'string', + description: 'Indicator creation timestamp', + optional: true, + }, + modifiedBy: { + type: 'string', + description: 'User who last modified the indicator', + optional: true, + }, + modifiedOn: { + type: 'string', + description: 'Indicator modification timestamp', + optional: true, + }, + metadata: { + type: 'json', + description: 'File metadata CrowdStrike resolved for the indicator', + optional: true, + properties: { + avHits: { type: 'number', description: 'Antivirus hit count', optional: true }, + companyName: { type: 'string', description: 'Company name', optional: true }, + fileDescription: { type: 'string', description: 'File description', optional: true }, + fileVersion: { type: 'string', description: 'File version', optional: true }, + filename: { type: 'string', description: 'File name', optional: true }, + originalFilename: { + type: 'string', + description: 'Original file name', + optional: true, + }, + productName: { type: 'string', description: 'Product name', optional: true }, + productVersion: { type: 'string', description: 'Product version', optional: true }, + signed: { + type: 'boolean', + description: 'Whether the file is signed', + optional: true, + }, + }, + }, + }, + }, + }, + count: { + type: 'number', + description: 'Number of indicators returned', + }, + errors: { + type: 'array', + description: 'Errors CrowdStrike returned alongside a partially successful response', + optional: true, + items: { + type: 'object', + properties: { + code: { type: 'number', description: 'CrowdStrike error code', optional: true }, + id: { type: 'string', description: 'Identifier the error applies to', optional: true }, + message: { type: 'string', description: 'Error message', optional: true }, + }, + }, + }, + }, +} diff --git a/apps/sim/tools/crowdstrike/get_rtr_command_status.ts b/apps/sim/tools/crowdstrike/get_rtr_command_status.ts new file mode 100644 index 00000000000..439e3a84924 --- /dev/null +++ b/apps/sim/tools/crowdstrike/get_rtr_command_status.ts @@ -0,0 +1,109 @@ +import type { + CrowdStrikeGetRtrCommandStatusParams, + CrowdStrikeGetRtrCommandStatusResponse, +} from '@/tools/crowdstrike/types' +import type { ToolConfig } from '@/tools/types' + +export const crowdstrikeGetRtrCommandStatusTool: ToolConfig< + CrowdStrikeGetRtrCommandStatusParams, + CrowdStrikeGetRtrCommandStatusResponse +> = { + id: 'crowdstrike_get_rtr_command_status', + name: 'CrowdStrike Get RTR Command Status', + description: + 'Get the status and output of a Real Time Response command by cloud request ID (GET /real-time-response/entities/command/v1). Long output is chunked across sequences, so increment the sequence ID to read the next chunk. Requires the "Real time response: Read" API scope.', + version: '1.0.0', + + params: { + clientId: { + type: 'string', + required: true, + visibility: 'user-only', + description: 'CrowdStrike Falcon API client ID', + }, + clientSecret: { + type: 'string', + required: true, + visibility: 'user-only', + description: 'CrowdStrike Falcon API client secret', + }, + cloud: { + type: 'string', + required: true, + visibility: 'user-only', + description: 'CrowdStrike Falcon cloud region', + }, + cloudRequestId: { + type: 'string', + required: true, + visibility: 'user-or-llm', + description: 'Cloud request ID returned by Execute RTR Command', + }, + sequenceId: { + type: 'number', + required: false, + visibility: 'user-or-llm', + description: 'Output chunk to retrieve, starting at 0', + }, + }, + + request: { + url: '/api/tools/crowdstrike/query', + method: 'POST', + headers: () => ({ + 'Content-Type': 'application/json', + }), + body: (params) => ({ + cloud: params.cloud, + clientId: params.clientId, + clientSecret: params.clientSecret, + cloudRequestId: params.cloudRequestId, + operation: 'crowdstrike_get_rtr_command_status', + sequenceId: params.sequenceId, + }), + }, + + transformResponse: async (response) => { + const data = await response.json() + + if (!response.ok || data.success === false) { + throw new Error(data.error || 'Failed to fetch CrowdStrike RTR command status') + } + + return { + success: true, + output: data.output, + } + }, + + outputs: { + complete: { + type: 'boolean', + description: 'Whether the command has finished running', + optional: true, + }, + stdout: { type: 'string', description: 'Standard output from the command', optional: true }, + stderr: { type: 'string', description: 'Standard error from the command', optional: true }, + baseCommand: { type: 'string', description: 'Base command that was run', optional: true }, + sessionId: { type: 'string', description: 'RTR session the command ran in', optional: true }, + taskId: { type: 'string', description: 'Task identifier for the command', optional: true }, + sequenceId: { + type: 'number', + description: 'Output chunk sequence this response covers', + optional: true, + }, + errors: { + type: 'array', + description: 'Errors CrowdStrike returned alongside a partially successful response', + optional: true, + items: { + type: 'object', + properties: { + code: { type: 'number', description: 'CrowdStrike error code', optional: true }, + id: { type: 'string', description: 'Identifier the error applies to', optional: true }, + message: { type: 'string', description: 'Error message', optional: true }, + }, + }, + }, + }, +} diff --git a/apps/sim/tools/crowdstrike/get_sensor_aggregates.ts b/apps/sim/tools/crowdstrike/get_sensor_aggregates.ts index 529bd7a5976..3a3deefa173 100644 --- a/apps/sim/tools/crowdstrike/get_sensor_aggregates.ts +++ b/apps/sim/tools/crowdstrike/get_sensor_aggregates.ts @@ -11,7 +11,7 @@ export const crowdstrikeGetSensorAggregatesTool: ToolConfig< id: 'crowdstrike_get_sensor_aggregates', name: 'CrowdStrike Get Sensor Aggregates', description: - 'Get documented CrowdStrike Identity Protection sensor aggregates from a JSON aggregate query body', + 'Aggregate CrowdStrike Identity Protection sensors from a JSON aggregate query body (POST /identity-protection/aggregates/devices/GET/v1). These are the domain controllers Falcon Identity Protection monitors, not Falcon endpoint sensors. Requires the "Identity Protection Entities: Read" API scope.', version: '1.0.0', params: { @@ -113,9 +113,10 @@ export const crowdstrikeGetSensorAggregatesTool: ToolConfig< optional: true, }, subAggregates: { - type: 'json', + type: 'array', description: 'Nested aggregate results for this bucket', optional: true, + items: { type: 'object' }, }, to: { type: 'number', @@ -157,5 +158,18 @@ export const crowdstrikeGetSensorAggregatesTool: ToolConfig< type: 'number', description: 'Number of aggregate result groups returned', }, + errors: { + type: 'array', + description: 'Errors CrowdStrike returned alongside a partially successful response', + optional: true, + items: { + type: 'object', + properties: { + code: { type: 'number', description: 'CrowdStrike error code', optional: true }, + id: { type: 'string', description: 'Identifier the error applies to', optional: true }, + message: { type: 'string', description: 'Error message', optional: true }, + }, + }, + }, }, } diff --git a/apps/sim/tools/crowdstrike/get_sensor_details.ts b/apps/sim/tools/crowdstrike/get_sensor_details.ts index dcbf44de73a..be162d543b7 100644 --- a/apps/sim/tools/crowdstrike/get_sensor_details.ts +++ b/apps/sim/tools/crowdstrike/get_sensor_details.ts @@ -11,7 +11,7 @@ export const crowdstrikeGetSensorDetailsTool: ToolConfig< id: 'crowdstrike_get_sensor_details', name: 'CrowdStrike Get Sensor Details', description: - 'Get documented CrowdStrike Identity Protection sensor details for one or more device IDs', + 'Get CrowdStrike Identity Protection sensor details for one or more device IDs (POST /identity-protection/entities/devices/GET/v1). These are the domain controllers Falcon Identity Protection monitors, not Falcon endpoint sensors. Requires the "Identity Protection Entities: Read" API scope.', version: '1.0.0', params: { @@ -179,14 +179,17 @@ export const crowdstrikeGetSensorDetailsTool: ToolConfig< type: 'number', description: 'Number of sensors returned', }, - pagination: { - type: 'json', - description: 'Pagination metadata when returned by the underlying API', + errors: { + type: 'array', + description: 'Errors CrowdStrike returned alongside a partially successful response', optional: true, - properties: { - limit: { type: 'number', description: 'Page size used for the query', optional: true }, - offset: { type: 'number', description: 'Offset returned by CrowdStrike', optional: true }, - total: { type: 'number', description: 'Total records available', optional: true }, + items: { + type: 'object', + properties: { + code: { type: 'number', description: 'CrowdStrike error code', optional: true }, + id: { type: 'string', description: 'Identifier the error applies to', optional: true }, + message: { type: 'string', description: 'Error message', optional: true }, + }, }, }, }, diff --git a/apps/sim/tools/crowdstrike/get_vulnerability_details.ts b/apps/sim/tools/crowdstrike/get_vulnerability_details.ts new file mode 100644 index 00000000000..f874b72f314 --- /dev/null +++ b/apps/sim/tools/crowdstrike/get_vulnerability_details.ts @@ -0,0 +1,277 @@ +import type { + CrowdStrikeGetVulnerabilityDetailsParams, + CrowdStrikeGetVulnerabilityDetailsResponse, +} from '@/tools/crowdstrike/types' +import type { ToolConfig } from '@/tools/types' + +export const crowdstrikeGetVulnerabilityDetailsTool: ToolConfig< + CrowdStrikeGetVulnerabilityDetailsParams, + CrowdStrikeGetVulnerabilityDetailsResponse +> = { + id: 'crowdstrike_get_vulnerability_details', + name: 'CrowdStrike Get Vulnerability Details', + description: + 'Get CrowdStrike Falcon Spotlight vulnerability records for one or more vulnerability IDs, including CVE, affected host, application, and remediation details (GET /spotlight/entities/vulnerabilities/v2). Requires the spotlight-vulnerabilities:read API scope, shown as "Vulnerabilities: Read" in the Falcon API client UI.', + version: '1.0.0', + + params: { + clientId: { + type: 'string', + required: true, + visibility: 'user-only', + description: 'CrowdStrike Falcon API client ID', + }, + clientSecret: { + type: 'string', + required: true, + visibility: 'user-only', + description: 'CrowdStrike Falcon API client secret', + }, + cloud: { + type: 'string', + required: true, + visibility: 'user-only', + description: 'CrowdStrike Falcon cloud region', + }, + vulnerabilityIds: { + type: 'json', + required: true, + visibility: 'user-or-llm', + description: 'JSON array of Spotlight vulnerability IDs (maximum 400 per request)', + }, + }, + + request: { + url: '/api/tools/crowdstrike/query', + method: 'POST', + headers: () => ({ + 'Content-Type': 'application/json', + }), + body: (params) => ({ + cloud: params.cloud, + clientId: params.clientId, + clientSecret: params.clientSecret, + operation: 'crowdstrike_get_vulnerability_details', + vulnerabilityIds: params.vulnerabilityIds, + }), + }, + + transformResponse: async (response) => { + const data = await response.json() + + if (!response.ok || data.success === false) { + throw new Error(data.error || 'Failed to fetch CrowdStrike vulnerability details') + } + + return { + success: true, + output: data.output, + } + }, + + outputs: { + vulnerabilities: { + type: 'array', + description: 'CrowdStrike Spotlight vulnerability records', + items: { + type: 'object', + properties: { + id: { type: 'string', description: 'Vulnerability identifier', optional: true }, + aid: { + type: 'string', + description: 'Agent identifier of the affected host', + optional: true, + }, + cid: { type: 'string', description: 'CrowdStrike customer identifier', optional: true }, + status: { + type: 'string', + description: 'Vulnerability status (open, closed, reopen)', + optional: true, + }, + confidence: { type: 'string', description: 'Detection confidence', optional: true }, + vulnerabilityId: { + type: 'string', + description: 'Underlying vulnerability ID', + optional: true, + }, + createdTimestamp: { type: 'string', description: 'Creation timestamp', optional: true }, + updatedTimestamp: { + type: 'string', + description: 'Last update timestamp', + optional: true, + }, + closedTimestamp: { type: 'string', description: 'Closure timestamp', optional: true }, + cve: { + type: 'json', + description: 'CVE details for the vulnerability', + optional: true, + properties: { + id: { type: 'string', description: 'CVE identifier', optional: true }, + baseScore: { type: 'number', description: 'CVSS base score', optional: true }, + severity: { type: 'string', description: 'CVE severity', optional: true }, + exprtRating: { + type: 'string', + description: 'CrowdStrike ExPRT rating', + optional: true, + }, + exploitStatus: { type: 'number', description: 'Exploit status code', optional: true }, + exploitabilityScore: { + type: 'number', + description: 'CVSS exploitability score', + optional: true, + }, + impactScore: { type: 'number', description: 'CVSS impact score', optional: true }, + remediationLevel: { + type: 'string', + description: 'CVSS remediation level', + optional: true, + }, + description: { type: 'string', description: 'CVE description', optional: true }, + publishedDate: { + type: 'string', + description: 'CVE publication date', + optional: true, + }, + vector: { type: 'string', description: 'CVSS vector string', optional: true }, + types: { + type: 'array', + description: 'CVE types', + optional: true, + items: { type: 'string' }, + }, + isCisaKev: { + type: 'boolean', + description: + 'Whether the CVE is in the CISA Known Exploited Vulnerabilities catalog', + optional: true, + }, + cisaDueDate: { + type: 'string', + description: 'CISA remediation due date', + optional: true, + }, + }, + }, + app: { + type: 'json', + description: 'Affected application', + optional: true, + properties: { + productNameNormalized: { + type: 'string', + description: 'Normalized product name', + optional: true, + }, + productNameVersion: { + type: 'string', + description: 'Product name and version', + optional: true, + }, + vendorNormalized: { + type: 'string', + description: 'Normalized vendor name', + optional: true, + }, + }, + }, + hostInfo: { + type: 'json', + description: 'Affected host details', + optional: true, + properties: { + hostname: { type: 'string', description: 'Host name', optional: true }, + localIp: { type: 'string', description: 'Local IP address', optional: true }, + machineDomain: { type: 'string', description: 'Machine domain', optional: true }, + osVersion: { + type: 'string', + description: 'Operating system version', + optional: true, + }, + platform: { type: 'string', description: 'Platform name', optional: true }, + productTypeDesc: { + type: 'string', + description: 'Product type description', + optional: true, + }, + assetCriticality: { + type: 'string', + description: 'Asset criticality', + optional: true, + }, + internetExposure: { + type: 'string', + description: 'Internet exposure', + optional: true, + }, + tags: { + type: 'array', + description: 'Host tags', + optional: true, + items: { type: 'string' }, + }, + groups: { + type: 'array', + description: 'Host group names the host belongs to', + optional: true, + items: { type: 'string' }, + }, + }, + }, + remediationIds: { + type: 'array', + description: 'Remediation IDs for the vulnerability', + optional: true, + items: { type: 'string' }, + }, + remediations: { + type: 'array', + description: 'Remediation entities for the vulnerability', + optional: true, + items: { + type: 'object', + properties: { + id: { type: 'string', description: 'Remediation identifier', optional: true }, + title: { type: 'string', description: 'Remediation title', optional: true }, + action: { type: 'string', description: 'Remediation action', optional: true }, + type: { type: 'string', description: 'Remediation type', optional: true }, + link: { type: 'string', description: 'Remediation link', optional: true }, + reference: { type: 'string', description: 'Remediation reference', optional: true }, + vendorUrl: { type: 'string', description: 'Vendor advisory URL', optional: true }, + }, + }, + }, + suppressionInfo: { + type: 'json', + description: 'Suppression state for the vulnerability', + optional: true, + properties: { + isSuppressed: { + type: 'boolean', + description: 'Whether the finding is suppressed', + optional: true, + }, + reason: { type: 'string', description: 'Suppression reason', optional: true }, + }, + }, + }, + }, + }, + count: { + type: 'number', + description: 'Number of vulnerabilities returned', + }, + errors: { + type: 'array', + description: 'Errors CrowdStrike returned alongside a partially successful response', + optional: true, + items: { + type: 'object', + properties: { + code: { type: 'number', description: 'CrowdStrike error code', optional: true }, + id: { type: 'string', description: 'Identifier the error applies to', optional: true }, + message: { type: 'string', description: 'Error message', optional: true }, + }, + }, + }, + }, +} diff --git a/apps/sim/tools/crowdstrike/index.ts b/apps/sim/tools/crowdstrike/index.ts index e0878239332..d54ffe63c87 100644 --- a/apps/sim/tools/crowdstrike/index.ts +++ b/apps/sim/tools/crowdstrike/index.ts @@ -1,4 +1,24 @@ +export { crowdstrikeCreateIndicatorsTool } from './create_indicators' +export { crowdstrikeDeleteIndicatorsTool } from './delete_indicators' +export { crowdstrikeDeleteRtrSessionTool } from './delete_rtr_session' +export { crowdstrikeExecuteRtrCommandTool } from './execute_rtr_command' +export { crowdstrikeGetAlertDetailsTool } from './get_alert_details' +export { crowdstrikeGetCaseDetailsTool } from './get_case_details' +export { crowdstrikeGetHostGroupDetailsTool } from './get_host_group_details' +export { crowdstrikeGetIndicatorDetailsTool } from './get_indicator_details' +export { crowdstrikeGetRtrCommandStatusTool } from './get_rtr_command_status' export { crowdstrikeGetSensorAggregatesTool } from './get_sensor_aggregates' export { crowdstrikeGetSensorDetailsTool } from './get_sensor_details' +export { crowdstrikeGetVulnerabilityDetailsTool } from './get_vulnerability_details' +export { crowdstrikeInitRtrSessionTool } from './init_rtr_session' +export { crowdstrikePerformHostActionTool } from './perform_host_action' +export { crowdstrikePerformHostGroupActionTool } from './perform_host_group_action' +export { crowdstrikeQueryAlertsTool } from './query_alerts' +export { crowdstrikeQueryCasesTool } from './query_cases' +export { crowdstrikeQueryHostGroupsTool } from './query_host_groups' +export { crowdstrikeQueryIndicatorsTool } from './query_indicators' export { crowdstrikeQuerySensorsTool } from './query_sensors' +export { crowdstrikeQueryVulnerabilitiesTool } from './query_vulnerabilities' export * from './types' +export { crowdstrikeUpdateAlertsTool } from './update_alerts' +export { crowdstrikeUpdateIndicatorsTool } from './update_indicators' diff --git a/apps/sim/tools/crowdstrike/init_rtr_session.ts b/apps/sim/tools/crowdstrike/init_rtr_session.ts new file mode 100644 index 00000000000..4cc7344a3ce --- /dev/null +++ b/apps/sim/tools/crowdstrike/init_rtr_session.ts @@ -0,0 +1,124 @@ +import type { + CrowdStrikeInitRtrSessionParams, + CrowdStrikeInitRtrSessionResponse, +} from '@/tools/crowdstrike/types' +import type { ToolConfig } from '@/tools/types' + +export const crowdstrikeInitRtrSessionTool: ToolConfig< + CrowdStrikeInitRtrSessionParams, + CrowdStrikeInitRtrSessionResponse +> = { + id: 'crowdstrike_init_rtr_session', + name: 'CrowdStrike Init RTR Session', + description: + 'Open a CrowdStrike Falcon Real Time Response session against a host so read-only commands can be run on it (POST /real-time-response/entities/sessions/v1). This connects a live remote shell to the endpoint. Requires the "Real time response: Read" API scope.', + version: '1.0.0', + + params: { + clientId: { + type: 'string', + required: true, + visibility: 'user-only', + description: 'CrowdStrike Falcon API client ID', + }, + clientSecret: { + type: 'string', + required: true, + visibility: 'user-only', + description: 'CrowdStrike Falcon API client secret', + }, + cloud: { + type: 'string', + required: true, + visibility: 'user-only', + description: 'CrowdStrike Falcon cloud region', + }, + deviceId: { + type: 'string', + required: true, + visibility: 'user-or-llm', + description: 'CrowdStrike host agent ID (AID) to open the session against', + }, + queueOffline: { + type: 'boolean', + required: false, + visibility: 'user-or-llm', + description: 'Queue the session so it runs when an offline host comes back online', + }, + origin: { + type: 'string', + required: false, + visibility: 'user-or-llm', + description: 'Optional session origin string recorded by CrowdStrike', + }, + }, + + request: { + url: '/api/tools/crowdstrike/query', + method: 'POST', + headers: () => ({ + 'Content-Type': 'application/json', + }), + body: (params) => ({ + cloud: params.cloud, + clientId: params.clientId, + clientSecret: params.clientSecret, + deviceId: params.deviceId, + operation: 'crowdstrike_init_rtr_session', + origin: params.origin, + queueOffline: params.queueOffline, + }), + }, + + transformResponse: async (response) => { + const data = await response.json() + + if (!response.ok || data.success === false) { + throw new Error(data.error || 'Failed to initialize CrowdStrike RTR session') + } + + return { + success: true, + output: data.output, + } + }, + + outputs: { + sessionId: { + type: 'string', + description: 'RTR session ID to use for subsequent commands', + optional: true, + }, + deviceId: { type: 'string', description: 'Host agent ID for the session', optional: true }, + platform: { type: 'string', description: 'Platform of the connected host', optional: true }, + pwd: { + type: 'string', + description: 'Working directory the session started in', + optional: true, + }, + offlineQueued: { + type: 'boolean', + description: 'Whether the session was queued for an offline host', + optional: true, + }, + existingAidSessions: { + type: 'number', + description: 'Number of sessions already open against this host', + optional: true, + }, + createdAt: { type: 'string', description: 'Session creation timestamp', optional: true }, + errors: { + type: 'array', + description: 'Errors CrowdStrike returned alongside a partially successful response', + optional: true, + items: { + type: 'object', + properties: { + code: { type: 'number', description: 'CrowdStrike error code', optional: true }, + id: { type: 'string', description: 'Identifier the error applies to', optional: true }, + message: { type: 'string', description: 'Error message', optional: true }, + }, + }, + }, + }, +} diff --git a/apps/sim/tools/crowdstrike/perform_host_action.ts b/apps/sim/tools/crowdstrike/perform_host_action.ts new file mode 100644 index 00000000000..95b2f080f03 --- /dev/null +++ b/apps/sim/tools/crowdstrike/perform_host_action.ts @@ -0,0 +1,110 @@ +import type { + CrowdStrikePerformHostActionParams, + CrowdStrikePerformHostActionResponse, +} from '@/tools/crowdstrike/types' +import type { ToolConfig } from '@/tools/types' + +export const crowdstrikePerformHostActionTool: ToolConfig< + CrowdStrikePerformHostActionParams, + CrowdStrikePerformHostActionResponse +> = { + id: 'crowdstrike_perform_host_action', + name: 'CrowdStrike Perform Host Action', + description: + 'Act on CrowdStrike Falcon hosts (POST /devices/entities/devices-actions/v2). Actions: contain, lift_containment, hide_host, unhide_host, detection_suppress, detection_unsuppress. contain network-isolates the host so it can only reach the Falcon cloud; hide_host removes the host record from the console. Both are immediately disruptive. Up to 100 host IDs per call. Requires the "Hosts: Write" API scope.', + version: '1.0.0', + + params: { + clientId: { + type: 'string', + required: true, + visibility: 'user-only', + description: 'CrowdStrike Falcon API client ID', + }, + clientSecret: { + type: 'string', + required: true, + visibility: 'user-only', + description: 'CrowdStrike Falcon API client secret', + }, + cloud: { + type: 'string', + required: true, + visibility: 'user-only', + description: 'CrowdStrike Falcon cloud region', + }, + actionName: { + type: 'string', + required: true, + visibility: 'user-or-llm', + description: + 'Action to take: contain, lift_containment, hide_host, unhide_host, detection_suppress, or detection_unsuppress. "contain" network-isolates the host; "hide_host" removes it from the Falcon console.', + }, + deviceIds: { + type: 'json', + required: true, + visibility: 'user-or-llm', + description: 'JSON array of up to 100 CrowdStrike host agent IDs (AIDs) to act on', + }, + }, + + request: { + url: '/api/tools/crowdstrike/query', + method: 'POST', + headers: () => ({ + 'Content-Type': 'application/json', + }), + body: (params) => ({ + actionName: params.actionName, + cloud: params.cloud, + clientId: params.clientId, + clientSecret: params.clientSecret, + deviceIds: params.deviceIds, + operation: 'crowdstrike_perform_host_action', + }), + }, + + transformResponse: async (response) => { + const data = await response.json() + + if (!response.ok || data.success === false) { + throw new Error(data.error || 'Failed to perform CrowdStrike host action') + } + + return { + success: true, + output: data.output, + } + }, + + outputs: { + affected: { + type: 'array', + description: 'Entities affected by the action', + items: { + type: 'object', + properties: { + id: { type: 'string', description: 'Affected entity identifier', optional: true }, + path: { type: 'string', description: 'API path of the affected entity', optional: true }, + }, + }, + }, + count: { + type: 'number', + description: 'Number of hosts the action was applied to', + }, + errors: { + type: 'array', + description: 'Errors CrowdStrike returned alongside a partially successful response', + optional: true, + items: { + type: 'object', + properties: { + code: { type: 'number', description: 'CrowdStrike error code', optional: true }, + id: { type: 'string', description: 'Identifier the error applies to', optional: true }, + message: { type: 'string', description: 'Error message', optional: true }, + }, + }, + }, + }, +} diff --git a/apps/sim/tools/crowdstrike/perform_host_group_action.ts b/apps/sim/tools/crowdstrike/perform_host_group_action.ts new file mode 100644 index 00000000000..fa39b26c91b --- /dev/null +++ b/apps/sim/tools/crowdstrike/perform_host_group_action.ts @@ -0,0 +1,144 @@ +import type { + CrowdStrikePerformHostGroupActionParams, + CrowdStrikePerformHostGroupActionResponse, +} from '@/tools/crowdstrike/types' +import type { ToolConfig } from '@/tools/types' + +export const crowdstrikePerformHostGroupActionTool: ToolConfig< + CrowdStrikePerformHostGroupActionParams, + CrowdStrikePerformHostGroupActionResponse +> = { + id: 'crowdstrike_perform_host_group_action', + name: 'CrowdStrike Perform Host Group Action', + description: + 'Add hosts to or remove hosts from a CrowdStrike Falcon static host group (POST /devices/entities/host-group-actions/v1). Group membership drives policy assignment, so changing it changes which policies apply to those hosts. Requires the "Host groups: Write" API scope.', + version: '1.0.0', + + params: { + clientId: { + type: 'string', + required: true, + visibility: 'user-only', + description: 'CrowdStrike Falcon API client ID', + }, + clientSecret: { + type: 'string', + required: true, + visibility: 'user-only', + description: 'CrowdStrike Falcon API client secret', + }, + cloud: { + type: 'string', + required: true, + visibility: 'user-only', + description: 'CrowdStrike Falcon cloud region', + }, + actionName: { + type: 'string', + required: true, + visibility: 'user-or-llm', + description: 'Action to take: add-hosts or remove-hosts', + }, + hostGroupId: { + type: 'string', + required: true, + visibility: 'user-or-llm', + description: 'CrowdStrike host group ID to modify (static groups only)', + }, + deviceIds: { + type: 'json', + required: true, + visibility: 'user-or-llm', + description: + 'JSON array of CrowdStrike host agent IDs (AIDs) to add to or remove from the group', + }, + }, + + request: { + url: '/api/tools/crowdstrike/query', + method: 'POST', + headers: () => ({ + 'Content-Type': 'application/json', + }), + body: (params) => ({ + actionName: params.actionName, + cloud: params.cloud, + clientId: params.clientId, + clientSecret: params.clientSecret, + deviceIds: params.deviceIds, + hostGroupId: params.hostGroupId, + operation: 'crowdstrike_perform_host_group_action', + }), + }, + + transformResponse: async (response) => { + const data = await response.json() + + if (!response.ok || data.success === false) { + throw new Error(data.error || 'Failed to perform CrowdStrike host group action') + } + + return { + success: true, + output: data.output, + } + }, + + outputs: { + hostGroups: { + type: 'array', + description: 'Host group records returned after the action', + items: { + type: 'object', + properties: { + id: { type: 'string', description: 'Host group identifier', optional: true }, + name: { type: 'string', description: 'Host group name', optional: true }, + description: { type: 'string', description: 'Host group description', optional: true }, + groupType: { + type: 'string', + description: 'Group type (static, dynamic, staticByID)', + optional: true, + }, + assignmentRule: { + type: 'string', + description: 'FQL assignment rule for dynamic groups', + optional: true, + }, + createdBy: { type: 'string', description: 'User who created the group', optional: true }, + createdTimestamp: { + type: 'string', + description: 'Group creation timestamp', + optional: true, + }, + modifiedBy: { + type: 'string', + description: 'User who last modified the group', + optional: true, + }, + modifiedTimestamp: { + type: 'string', + description: 'Group modification timestamp', + optional: true, + }, + }, + }, + }, + count: { + type: 'number', + description: 'Number of host group records returned', + }, + errors: { + type: 'array', + description: 'Errors CrowdStrike returned alongside a partially successful response', + optional: true, + items: { + type: 'object', + properties: { + code: { type: 'number', description: 'CrowdStrike error code', optional: true }, + id: { type: 'string', description: 'Identifier the error applies to', optional: true }, + message: { type: 'string', description: 'Error message', optional: true }, + }, + }, + }, + }, +} diff --git a/apps/sim/tools/crowdstrike/query_alerts.ts b/apps/sim/tools/crowdstrike/query_alerts.ts new file mode 100644 index 00000000000..a836a8a72fe --- /dev/null +++ b/apps/sim/tools/crowdstrike/query_alerts.ts @@ -0,0 +1,128 @@ +import type { + CrowdStrikeQueryAlertsParams, + CrowdStrikeQueryAlertsResponse, +} from '@/tools/crowdstrike/types' +import type { ToolConfig } from '@/tools/types' + +export const crowdstrikeQueryAlertsTool: ToolConfig< + CrowdStrikeQueryAlertsParams, + CrowdStrikeQueryAlertsResponse +> = { + id: 'crowdstrike_query_alerts', + name: 'CrowdStrike Query Alerts', + description: + 'Search CrowdStrike Falcon alerts with a Falcon Query Language filter and return their composite IDs. Uses the current Alerts API (GET /alerts/queries/alerts/v2), which supersedes the deprecated Detects API. Requires the "Alerts: Read" API scope.', + version: '1.0.0', + + params: { + clientId: { + type: 'string', + required: true, + visibility: 'user-only', + description: 'CrowdStrike Falcon API client ID', + }, + clientSecret: { + type: 'string', + required: true, + visibility: 'user-only', + description: 'CrowdStrike Falcon API client secret', + }, + cloud: { + type: 'string', + required: true, + visibility: 'user-only', + description: 'CrowdStrike Falcon cloud region', + }, + filter: { + type: 'string', + required: false, + visibility: 'user-or-llm', + description: 'Falcon Query Language filter over alert fields', + }, + q: { + type: 'string', + required: false, + visibility: 'user-or-llm', + description: 'Free-text search across all alert metadata', + }, + limit: { + type: 'number', + required: false, + visibility: 'user-or-llm', + description: 'Maximum number of alert IDs to return (max 10000)', + }, + offset: { + type: 'number', + required: false, + visibility: 'user-or-llm', + description: 'Pagination offset for the alert query', + }, + sort: { + type: 'string', + required: false, + visibility: 'user-or-llm', + description: 'Sort expression such as "created_timestamp|desc"', + }, + includeHidden: { + type: 'boolean', + required: false, + visibility: 'user-or-llm', + description: 'Include previously hidden alerts (CrowdStrike defaults this to true)', + }, + }, + + request: { + url: '/api/tools/crowdstrike/query', + method: 'POST', + headers: () => ({ + 'Content-Type': 'application/json', + }), + body: (params) => ({ + cloud: params.cloud, + clientId: params.clientId, + clientSecret: params.clientSecret, + filter: params.filter, + includeHidden: params.includeHidden, + limit: params.limit, + offset: params.offset, + operation: 'crowdstrike_query_alerts', + q: params.q, + sort: params.sort, + }), + }, + + transformResponse: async (response) => { + const data = await response.json() + + if (!response.ok || data.success === false) { + throw new Error(data.error || 'Failed to query CrowdStrike alerts') + } + + return { + success: true, + output: data.output, + } + }, + + outputs: { + alertIds: { + type: 'array', + description: 'Composite alert IDs matching the query, ready for Get Alert Details', + items: { type: 'string' }, + }, + count: { + type: 'number', + description: 'Number of alert IDs returned', + }, + pagination: { + type: 'json', + description: 'Pagination metadata (limit, offset, total)', + optional: true, + properties: { + limit: { type: 'number', description: 'Page size used for the query', optional: true }, + offset: { type: 'number', description: 'Offset returned by CrowdStrike', optional: true }, + total: { type: 'number', description: 'Total records available', optional: true }, + }, + }, + }, +} diff --git a/apps/sim/tools/crowdstrike/query_cases.ts b/apps/sim/tools/crowdstrike/query_cases.ts new file mode 100644 index 00000000000..4cfd9fb57bd --- /dev/null +++ b/apps/sim/tools/crowdstrike/query_cases.ts @@ -0,0 +1,122 @@ +import type { + CrowdStrikeQueryCasesParams, + CrowdStrikeQueryCasesResponse, +} from '@/tools/crowdstrike/types' +import type { ToolConfig } from '@/tools/types' + +export const crowdstrikeQueryCasesTool: ToolConfig< + CrowdStrikeQueryCasesParams, + CrowdStrikeQueryCasesResponse +> = { + id: 'crowdstrike_query_cases', + name: 'CrowdStrike Query Cases', + description: + 'Search CrowdStrike Falcon Case Management cases with a Falcon Query Language filter and return their IDs (GET /cases/queries/cases/v1). Case Management supersedes the CrowdScore Incidents API, which CrowdStrike has removed from its published API spec. Requires the "Cases: Read" API scope.', + version: '1.0.0', + + params: { + clientId: { + type: 'string', + required: true, + visibility: 'user-only', + description: 'CrowdStrike Falcon API client ID', + }, + clientSecret: { + type: 'string', + required: true, + visibility: 'user-only', + description: 'CrowdStrike Falcon API client secret', + }, + cloud: { + type: 'string', + required: true, + visibility: 'user-only', + description: 'CrowdStrike Falcon cloud region', + }, + filter: { + type: 'string', + required: false, + visibility: 'user-or-llm', + description: + 'Falcon Query Language filter. Exact-match fields include cid and id; wildcard fields include assigned_to_name and assigned_to_uuid; range fields include created_timestamp and updated_timestamp.', + }, + q: { + type: 'string', + required: false, + visibility: 'user-or-llm', + description: 'Free-text search across all case metadata', + }, + limit: { + type: 'number', + required: false, + visibility: 'user-or-llm', + description: 'Maximum number of case IDs to return (max 10000, default 100)', + }, + offset: { + type: 'number', + required: false, + visibility: 'user-or-llm', + description: 'Pagination offset for the case query', + }, + sort: { + type: 'string', + required: false, + visibility: 'user-or-llm', + description: 'Sort expression such as "created_timestamp|desc" or "status|asc"', + }, + }, + + request: { + url: '/api/tools/crowdstrike/query', + method: 'POST', + headers: () => ({ + 'Content-Type': 'application/json', + }), + body: (params) => ({ + cloud: params.cloud, + clientId: params.clientId, + clientSecret: params.clientSecret, + filter: params.filter, + limit: params.limit, + offset: params.offset, + operation: 'crowdstrike_query_cases', + q: params.q, + sort: params.sort, + }), + }, + + transformResponse: async (response) => { + const data = await response.json() + + if (!response.ok || data.success === false) { + throw new Error(data.error || 'Failed to query CrowdStrike cases') + } + + return { + success: true, + output: data.output, + } + }, + + outputs: { + caseIds: { + type: 'array', + description: 'Case IDs matching the query', + items: { type: 'string' }, + }, + count: { + type: 'number', + description: 'Number of case IDs returned', + }, + pagination: { + type: 'json', + description: 'Pagination metadata (limit, offset, total)', + optional: true, + properties: { + limit: { type: 'number', description: 'Page size used for the query', optional: true }, + offset: { type: 'number', description: 'Offset returned by CrowdStrike', optional: true }, + total: { type: 'number', description: 'Total records available', optional: true }, + }, + }, + }, +} diff --git a/apps/sim/tools/crowdstrike/query_host_groups.ts b/apps/sim/tools/crowdstrike/query_host_groups.ts new file mode 100644 index 00000000000..4b73dc4d300 --- /dev/null +++ b/apps/sim/tools/crowdstrike/query_host_groups.ts @@ -0,0 +1,114 @@ +import type { + CrowdStrikeQueryHostGroupsParams, + CrowdStrikeQueryHostGroupsResponse, +} from '@/tools/crowdstrike/types' +import type { ToolConfig } from '@/tools/types' + +export const crowdstrikeQueryHostGroupsTool: ToolConfig< + CrowdStrikeQueryHostGroupsParams, + CrowdStrikeQueryHostGroupsResponse +> = { + id: 'crowdstrike_query_host_groups', + name: 'CrowdStrike Query Host Groups', + description: + 'Search CrowdStrike Falcon host groups with a Falcon Query Language filter and return their IDs (GET /devices/queries/host-groups/v1). Requires the "Host groups: Read" API scope.', + version: '1.0.0', + + params: { + clientId: { + type: 'string', + required: true, + visibility: 'user-only', + description: 'CrowdStrike Falcon API client ID', + }, + clientSecret: { + type: 'string', + required: true, + visibility: 'user-only', + description: 'CrowdStrike Falcon API client secret', + }, + cloud: { + type: 'string', + required: true, + visibility: 'user-only', + description: 'CrowdStrike Falcon cloud region', + }, + filter: { + type: 'string', + required: false, + visibility: 'user-or-llm', + description: 'Falcon Query Language filter over host group fields', + }, + limit: { + type: 'number', + required: false, + visibility: 'user-or-llm', + description: 'Maximum number of host group IDs to return (1-5000)', + }, + offset: { + type: 'number', + required: false, + visibility: 'user-or-llm', + description: 'Pagination offset for the host group query', + }, + sort: { + type: 'string', + required: false, + visibility: 'user-or-llm', + description: 'Sort expression such as "name.asc" or "modified_timestamp.desc"', + }, + }, + + request: { + url: '/api/tools/crowdstrike/query', + method: 'POST', + headers: () => ({ + 'Content-Type': 'application/json', + }), + body: (params) => ({ + cloud: params.cloud, + clientId: params.clientId, + clientSecret: params.clientSecret, + filter: params.filter, + limit: params.limit, + offset: params.offset, + operation: 'crowdstrike_query_host_groups', + sort: params.sort, + }), + }, + + transformResponse: async (response) => { + const data = await response.json() + + if (!response.ok || data.success === false) { + throw new Error(data.error || 'Failed to query CrowdStrike host groups') + } + + return { + success: true, + output: data.output, + } + }, + + outputs: { + hostGroupIds: { + type: 'array', + description: 'Host group IDs matching the query', + items: { type: 'string' }, + }, + count: { + type: 'number', + description: 'Number of host group IDs returned', + }, + pagination: { + type: 'json', + description: 'Pagination metadata (limit, offset, total)', + optional: true, + properties: { + limit: { type: 'number', description: 'Page size used for the query', optional: true }, + offset: { type: 'number', description: 'Offset returned by CrowdStrike', optional: true }, + total: { type: 'number', description: 'Total records available', optional: true }, + }, + }, + }, +} diff --git a/apps/sim/tools/crowdstrike/query_indicators.ts b/apps/sim/tools/crowdstrike/query_indicators.ts new file mode 100644 index 00000000000..2e36d7547f1 --- /dev/null +++ b/apps/sim/tools/crowdstrike/query_indicators.ts @@ -0,0 +1,124 @@ +import type { + CrowdStrikeQueryIndicatorsParams, + CrowdStrikeQueryIndicatorsResponse, +} from '@/tools/crowdstrike/types' +import type { ToolConfig } from '@/tools/types' + +export const crowdstrikeQueryIndicatorsTool: ToolConfig< + CrowdStrikeQueryIndicatorsParams, + CrowdStrikeQueryIndicatorsResponse +> = { + id: 'crowdstrike_query_indicators', + name: 'CrowdStrike Query Indicators', + description: + 'Search custom CrowdStrike Falcon indicators of compromise (IOCs) with a Falcon Query Language filter and return their IDs (GET /iocs/queries/indicators/v1). Requires the "IOC Management: Read" API scope.', + version: '1.0.0', + + params: { + clientId: { + type: 'string', + required: true, + visibility: 'user-only', + description: 'CrowdStrike Falcon API client ID', + }, + clientSecret: { + type: 'string', + required: true, + visibility: 'user-only', + description: 'CrowdStrike Falcon API client secret', + }, + cloud: { + type: 'string', + required: true, + visibility: 'user-only', + description: 'CrowdStrike Falcon cloud region', + }, + filter: { + type: 'string', + required: false, + visibility: 'user-or-llm', + description: 'Falcon Query Language filter over IOC fields', + }, + limit: { + type: 'number', + required: false, + visibility: 'user-or-llm', + description: 'Maximum number of IOC IDs to return (1-500, default 100)', + }, + offset: { + type: 'number', + required: false, + visibility: 'user-or-llm', + description: + 'Pagination offset. Mutually exclusive with the after cursor; use after beyond 10,000 IOCs.', + }, + after: { + type: 'string', + required: false, + visibility: 'user-or-llm', + description: 'Pagination cursor from a previous response. Mutually exclusive with offset.', + }, + sort: { + type: 'string', + required: false, + visibility: 'user-or-llm', + description: + 'Sort expression. Supported fields include action, applied_globally, created_by, created_on, expiration, expired, modified_by, modified_on, severity_number, source, type, and value.', + }, + }, + + request: { + url: '/api/tools/crowdstrike/query', + method: 'POST', + headers: () => ({ + 'Content-Type': 'application/json', + }), + body: (params) => ({ + after: params.after, + cloud: params.cloud, + clientId: params.clientId, + clientSecret: params.clientSecret, + filter: params.filter, + limit: params.limit, + offset: params.offset, + operation: 'crowdstrike_query_indicators', + sort: params.sort, + }), + }, + + transformResponse: async (response) => { + const data = await response.json() + + if (!response.ok || data.success === false) { + throw new Error(data.error || 'Failed to query CrowdStrike indicators') + } + + return { + success: true, + output: data.output, + } + }, + + outputs: { + indicatorIds: { + type: 'array', + description: 'IOC IDs matching the query', + items: { type: 'string' }, + }, + count: { + type: 'number', + description: 'Number of IOC IDs returned', + }, + pagination: { + type: 'json', + description: 'Pagination metadata (limit, offset, total, after)', + optional: true, + properties: { + limit: { type: 'number', description: 'Page size used for the query', optional: true }, + offset: { type: 'number', description: 'Offset returned by CrowdStrike', optional: true }, + total: { type: 'number', description: 'Total records available', optional: true }, + after: { type: 'string', description: 'Cursor for the next page', optional: true }, + }, + }, + }, +} diff --git a/apps/sim/tools/crowdstrike/query_sensors.ts b/apps/sim/tools/crowdstrike/query_sensors.ts index d6547815906..1068a34023b 100644 --- a/apps/sim/tools/crowdstrike/query_sensors.ts +++ b/apps/sim/tools/crowdstrike/query_sensors.ts @@ -10,7 +10,8 @@ export const crowdstrikeQuerySensorsTool: ToolConfig< > = { id: 'crowdstrike_query_sensors', name: 'CrowdStrike Query Sensors', - description: 'Search CrowdStrike identity protection sensors by hostname, IP, or related fields', + description: + 'Search CrowdStrike Identity Protection sensors -- the domain controllers Falcon Identity Protection monitors, not Falcon endpoint sensors -- and return their device IDs (GET /identity-protection/queries/devices/v1). Sort uses the dot form, for example status.desc. Requires the "Identity Protection Entities: Read" API scope, a separate entitlement from Hosts and Alerts.', version: '1.0.0', params: { @@ -209,5 +210,18 @@ export const crowdstrikeQuerySensorsTool: ToolConfig< total: { type: 'number', description: 'Total records available', optional: true }, }, }, + errors: { + type: 'array', + description: 'Errors CrowdStrike returned alongside a partially successful response', + optional: true, + items: { + type: 'object', + properties: { + code: { type: 'number', description: 'CrowdStrike error code', optional: true }, + id: { type: 'string', description: 'Identifier the error applies to', optional: true }, + message: { type: 'string', description: 'Error message', optional: true }, + }, + }, + }, }, } diff --git a/apps/sim/tools/crowdstrike/query_vulnerabilities.ts b/apps/sim/tools/crowdstrike/query_vulnerabilities.ts new file mode 100644 index 00000000000..b79c9493e97 --- /dev/null +++ b/apps/sim/tools/crowdstrike/query_vulnerabilities.ts @@ -0,0 +1,115 @@ +import type { + CrowdStrikeQueryVulnerabilitiesParams, + CrowdStrikeQueryVulnerabilitiesResponse, +} from '@/tools/crowdstrike/types' +import type { ToolConfig } from '@/tools/types' + +export const crowdstrikeQueryVulnerabilitiesTool: ToolConfig< + CrowdStrikeQueryVulnerabilitiesParams, + CrowdStrikeQueryVulnerabilitiesResponse +> = { + id: 'crowdstrike_query_vulnerabilities', + name: 'CrowdStrike Query Vulnerabilities', + description: + 'Search CrowdStrike Falcon Spotlight vulnerabilities with a required Falcon Query Language filter and return their IDs (GET /spotlight/queries/vulnerabilities/v1). Requires the spotlight-vulnerabilities:read API scope, shown as "Vulnerabilities: Read" in the Falcon API client UI.', + version: '1.0.0', + + params: { + clientId: { + type: 'string', + required: true, + visibility: 'user-only', + description: 'CrowdStrike Falcon API client ID', + }, + clientSecret: { + type: 'string', + required: true, + visibility: 'user-only', + description: 'CrowdStrike Falcon API client secret', + }, + cloud: { + type: 'string', + required: true, + visibility: 'user-only', + description: 'CrowdStrike Falcon cloud region', + }, + filter: { + type: 'string', + required: true, + visibility: 'user-or-llm', + description: + 'Falcon Query Language filter (required by Spotlight). Filterable fields include status, aid, cid, last_seen_within, cve.id, cve.severity, cve.exprt_rating, cve.is_cisa_kev, cve.base_score, host_info.platform_name, host_info.groups, host_info.tags, host_info.internet_exposure, and suppression_info.is_suppressed.', + }, + limit: { + type: 'number', + required: false, + visibility: 'user-or-llm', + description: 'Maximum number of vulnerability IDs to return (1-400, default 100)', + }, + after: { + type: 'string', + required: false, + visibility: 'user-or-llm', + description: 'Pagination cursor from a previous response. Spotlight does not support offset.', + }, + sort: { + type: 'string', + required: false, + visibility: 'user-or-llm', + description: 'Sort expression such as "updated_timestamp|desc" or "closed_timestamp|asc"', + }, + }, + + request: { + url: '/api/tools/crowdstrike/query', + method: 'POST', + headers: () => ({ + 'Content-Type': 'application/json', + }), + body: (params) => ({ + after: params.after, + cloud: params.cloud, + clientId: params.clientId, + clientSecret: params.clientSecret, + filter: params.filter, + limit: params.limit, + operation: 'crowdstrike_query_vulnerabilities', + sort: params.sort, + }), + }, + + transformResponse: async (response) => { + const data = await response.json() + + if (!response.ok || data.success === false) { + throw new Error(data.error || 'Failed to query CrowdStrike vulnerabilities') + } + + return { + success: true, + output: data.output, + } + }, + + outputs: { + vulnerabilityIds: { + type: 'array', + description: 'Spotlight vulnerability IDs matching the query', + items: { type: 'string' }, + }, + count: { + type: 'number', + description: 'Number of vulnerability IDs returned', + }, + pagination: { + type: 'json', + description: 'Cursor pagination metadata (limit, total, after)', + optional: true, + properties: { + limit: { type: 'number', description: 'Page size used for the query', optional: true }, + total: { type: 'number', description: 'Total records available', optional: true }, + after: { type: 'string', description: 'Cursor for the next page', optional: true }, + }, + }, + }, +} diff --git a/apps/sim/tools/crowdstrike/types.ts b/apps/sim/tools/crowdstrike/types.ts index 6fc3634597d..2879e4e9cff 100644 --- a/apps/sim/tools/crowdstrike/types.ts +++ b/apps/sim/tools/crowdstrike/types.ts @@ -1,6 +1,6 @@ import type { ToolResponse } from '@/tools/types' -export type CrowdStrikeCloud = 'us-1' | 'us-2' | 'eu-1' | 'us-gov-1' | 'us-gov-2' +export type CrowdStrikeCloud = 'us-1' | 'us-2' | 'us-3' | 'eu-1' | 'us-gov-1' | 'us-gov-2' export interface CrowdStrikeBaseParams { clientId: string @@ -29,9 +29,17 @@ interface CrowdStrikeAggregateExtendedBoundsSpec { min: string } +/** CrowdStrike's `MsaRangeSpec` serializes its bounds capitalized, unlike every sibling spec. */ interface CrowdStrikeAggregateRangeSpec { - from: number - to: number + From: number + To: number +} + +/** CrowdStrike's `MsaAPIFiltersSpec`: an FQL-per-bucket map plus the catch-all bucket controls. */ +export interface CrowdStrikeAggregateFiltersSpec { + filters: Record + other_bucket?: boolean + other_bucket_key?: string } export interface CrowdStrikeAggregateQuery { @@ -40,6 +48,7 @@ export interface CrowdStrikeAggregateQuery { extended_bounds?: CrowdStrikeAggregateExtendedBoundsSpec field?: string filter?: string + filters_spec?: CrowdStrikeAggregateFiltersSpec from?: number include?: string interval?: string @@ -47,6 +56,7 @@ export interface CrowdStrikeAggregateQuery { min_doc_count?: number missing?: string name?: string + percents?: number[] q?: string ranges?: CrowdStrikeAggregateRangeSpec[] size?: number @@ -108,7 +118,7 @@ export interface CrowdStrikeSensorAggregateBucket { count: number | null from: number | null keyAsString: string | null - label: Record | null + label: unknown stringFrom: string | null stringTo: string | null subAggregates: CrowdStrikeSensorAggregateResult[] @@ -131,7 +141,539 @@ export interface CrowdStrikeGetSensorAggregatesResponse extends ToolResponse { } } +export interface CrowdStrikeApiError { + code: number | null + id: string | null + message: string | null +} + +interface CrowdStrikeCursorPagination extends CrowdStrikePagination { + after: string | null +} + +interface CrowdStrikeSpotlightPagination { + after: string | null + limit: number | null + total: number | null +} + +export interface CrowdStrikeQueryAlertsParams extends CrowdStrikeBaseParams { + filter?: string + q?: string + limit?: number + offset?: number + sort?: string + includeHidden?: boolean +} + +export interface CrowdStrikeGetAlertDetailsParams extends CrowdStrikeBaseParams { + compositeIds: string[] + includeHidden?: boolean +} + +export interface CrowdStrikeUpdateAlertsParams extends CrowdStrikeBaseParams { + compositeIds: string[] + updateStatus?: string + assignToUuid?: string + assignToUserId?: string + assignToName?: string + unassign?: boolean + appendComment?: string + addTag?: string + removeTag?: string + removeTagsByPrefix?: string + showInUi?: boolean + actionParameters?: CrowdStrikeActionParameter[] + includeHidden?: boolean +} + +export interface CrowdStrikeActionParameter { + name: string + value: string +} + +export interface CrowdStrikeAlert { + compositeId: string | null + id: string | null + cid: string | null + aggregateId: string | null + agentId: string | null + deviceId: string | null + hostname: string | null + name: string | null + displayName: string | null + description: string | null + type: string | null + product: string | null + platform: string | null + severity: number | null + severityName: string | null + confidence: number | null + status: string | null + assignedToName: string | null + assignedToUid: string | null + assignedToUuid: string | null + tactic: string | null + tacticId: string | null + technique: string | null + techniqueId: string | null + scenario: string | null + objective: string | null + resolution: string | null + showInUi: boolean | null + tags: string[] + filename: string | null + filepath: string | null + cmdline: string | null + sha256: string | null + sha1: string | null + md5: string | null + userName: string | null + userId: string | null + patternId: number | null + falconHostLink: string | null + controlGraphId: string | null + external: boolean | null + emailSent: boolean | null + isAggregated: boolean | null + isFalconPlatformIoa: boolean | null + dataDomains: string[] + iocValues: string[] + linkedCaseIds: string[] + linkedBehavioralDetections: string[] + timestamp: string | null + createdTimestamp: string | null + updatedTimestamp: string | null + crawledTimestamp: string | null + contextTimestamp: string | null +} + +export interface CrowdStrikeQueryAlertsResponse extends ToolResponse { + output: { + alertIds: string[] + count: number + pagination: CrowdStrikePagination | null + } +} + +export interface CrowdStrikeGetAlertDetailsResponse extends ToolResponse { + output: { + alerts: CrowdStrikeAlert[] + count: number + errors: CrowdStrikeApiError[] + } +} + +export interface CrowdStrikeUpdateAlertsResponse extends ToolResponse { + output: { + updatedIds: string[] + count: number + errors: CrowdStrikeApiError[] + } +} + +export interface CrowdStrikePerformHostActionParams extends CrowdStrikeBaseParams { + actionName: string + deviceIds: string[] +} + +export interface CrowdStrikeAffectedEntity { + id: string | null + path: string | null +} + +export interface CrowdStrikePerformHostActionResponse extends ToolResponse { + output: { + affected: CrowdStrikeAffectedEntity[] + count: number + errors: CrowdStrikeApiError[] + } +} + +export interface CrowdStrikeQueryHostGroupsParams extends CrowdStrikeBaseParams { + filter?: string + limit?: number + offset?: number + sort?: string +} + +export interface CrowdStrikeGetHostGroupDetailsParams extends CrowdStrikeBaseParams { + hostGroupIds: string[] +} + +export interface CrowdStrikePerformHostGroupActionParams extends CrowdStrikeBaseParams { + actionName: string + hostGroupId: string + deviceIds: string[] +} + +export interface CrowdStrikeHostGroup { + id: string | null + name: string | null + description: string | null + groupType: string | null + assignmentRule: string | null + createdBy: string | null + createdTimestamp: string | null + modifiedBy: string | null + modifiedTimestamp: string | null +} + +export interface CrowdStrikeQueryHostGroupsResponse extends ToolResponse { + output: { + hostGroupIds: string[] + count: number + pagination: CrowdStrikePagination | null + } +} + +export interface CrowdStrikeGetHostGroupDetailsResponse extends ToolResponse { + output: { + hostGroups: CrowdStrikeHostGroup[] + count: number + errors: CrowdStrikeApiError[] + } +} + +export interface CrowdStrikePerformHostGroupActionResponse extends ToolResponse { + output: { + hostGroups: CrowdStrikeHostGroup[] + count: number + errors: CrowdStrikeApiError[] + } +} + +export interface CrowdStrikeQueryIndicatorsParams extends CrowdStrikeBaseParams { + filter?: string + limit?: number + offset?: number + after?: string + sort?: string +} + +export interface CrowdStrikeGetIndicatorDetailsParams extends CrowdStrikeBaseParams { + indicatorIds: string[] +} + +export interface CrowdStrikeCreateIndicatorsParams extends CrowdStrikeBaseParams { + indicators: Record[] + comment?: string + retrodetects?: boolean + ignoreWarnings?: boolean +} + +export interface CrowdStrikeUpdateIndicatorsParams extends CrowdStrikeBaseParams { + indicators: Record[] + comment?: string + retrodetects?: boolean + ignoreWarnings?: boolean +} + +export interface CrowdStrikeDeleteIndicatorsParams extends CrowdStrikeBaseParams { + indicatorIds?: string[] + filter?: string + comment?: string +} + +export interface CrowdStrikeIndicatorMetadata { + avHits: number | null + companyName: string | null + fileDescription: string | null + fileVersion: string | null + filename: string | null + originalFilename: string | null + productName: string | null + productVersion: string | null + signed: boolean | null +} + +export interface CrowdStrikeIndicator { + id: string | null + type: string | null + value: string | null + action: string | null + mobileAction: string | null + severity: string | null + description: string | null + source: string | null + appliedGlobally: boolean | null + platforms: string[] + hostGroups: string[] + tags: string[] + expiration: string | null + expired: boolean | null + deleted: boolean | null + fromParent: boolean | null + parentCidName: string | null + createdBy: string | null + createdOn: string | null + modifiedBy: string | null + modifiedOn: string | null + metadata: CrowdStrikeIndicatorMetadata | null +} + +export interface CrowdStrikeQueryIndicatorsResponse extends ToolResponse { + output: { + indicatorIds: string[] + count: number + pagination: CrowdStrikeCursorPagination | null + } +} + +export interface CrowdStrikeIndicatorListResponse extends ToolResponse { + output: { + indicators: CrowdStrikeIndicator[] + count: number + errors: CrowdStrikeApiError[] + } +} + +export type CrowdStrikeGetIndicatorDetailsResponse = CrowdStrikeIndicatorListResponse +export type CrowdStrikeCreateIndicatorsResponse = CrowdStrikeIndicatorListResponse +export type CrowdStrikeUpdateIndicatorsResponse = CrowdStrikeIndicatorListResponse + +export interface CrowdStrikeDeleteIndicatorsResponse extends ToolResponse { + output: { + deletedIds: string[] + count: number + errors: CrowdStrikeApiError[] + } +} + +export interface CrowdStrikeQueryVulnerabilitiesParams extends CrowdStrikeBaseParams { + filter: string + limit?: number + after?: string + sort?: string +} + +export interface CrowdStrikeGetVulnerabilityDetailsParams extends CrowdStrikeBaseParams { + vulnerabilityIds: string[] +} + +export interface CrowdStrikeVulnerabilityCve { + id: string | null + baseScore: number | null + severity: string | null + exprtRating: string | null + exploitStatus: number | null + exploitabilityScore: number | null + impactScore: number | null + remediationLevel: string | null + description: string | null + publishedDate: string | null + vector: string | null + types: string[] + isCisaKev: boolean | null + cisaDueDate: string | null +} + +export interface CrowdStrikeVulnerabilityApp { + productNameNormalized: string | null + productNameVersion: string | null + vendorNormalized: string | null +} + +export interface CrowdStrikeVulnerabilityHostInfo { + hostname: string | null + localIp: string | null + machineDomain: string | null + osVersion: string | null + platform: string | null + productTypeDesc: string | null + assetCriticality: string | null + internetExposure: string | null + tags: string[] + groups: string[] +} + +export interface CrowdStrikeVulnerabilityRemediation { + id: string | null + title: string | null + action: string | null + type: string | null + link: string | null + reference: string | null + vendorUrl: string | null +} + +export interface CrowdStrikeVulnerability { + id: string | null + aid: string | null + cid: string | null + status: string | null + confidence: string | null + vulnerabilityId: string | null + createdTimestamp: string | null + updatedTimestamp: string | null + closedTimestamp: string | null + cve: CrowdStrikeVulnerabilityCve | null + app: CrowdStrikeVulnerabilityApp | null + hostInfo: CrowdStrikeVulnerabilityHostInfo | null + remediationIds: string[] + remediations: CrowdStrikeVulnerabilityRemediation[] + suppressionInfo: { isSuppressed: boolean | null; reason: string | null } | null +} + +export interface CrowdStrikeQueryVulnerabilitiesResponse extends ToolResponse { + output: { + vulnerabilityIds: string[] + count: number + pagination: CrowdStrikeSpotlightPagination | null + } +} + +export interface CrowdStrikeGetVulnerabilityDetailsResponse extends ToolResponse { + output: { + vulnerabilities: CrowdStrikeVulnerability[] + count: number + errors: CrowdStrikeApiError[] + } +} + +export interface CrowdStrikeInitRtrSessionParams extends CrowdStrikeBaseParams { + deviceId: string + queueOffline?: boolean + origin?: string +} + +export interface CrowdStrikeExecuteRtrCommandParams extends CrowdStrikeBaseParams { + sessionId: string + baseCommand: string + commandString: string +} + +export interface CrowdStrikeGetRtrCommandStatusParams extends CrowdStrikeBaseParams { + cloudRequestId: string + sequenceId?: number +} + +export interface CrowdStrikeDeleteRtrSessionParams extends CrowdStrikeBaseParams { + sessionId: string +} + +export interface CrowdStrikeInitRtrSessionResponse extends ToolResponse { + output: { + sessionId: string | null + deviceId: string | null + platform: string | null + pwd: string | null + offlineQueued: boolean | null + existingAidSessions: number | null + createdAt: string | null + errors: CrowdStrikeApiError[] + } +} + +export interface CrowdStrikeExecuteRtrCommandResponse extends ToolResponse { + output: { + cloudRequestId: string | null + sessionId: string | null + queuedCommandOffline: boolean | null + errors: CrowdStrikeApiError[] + } +} + +export interface CrowdStrikeGetRtrCommandStatusResponse extends ToolResponse { + output: { + complete: boolean | null + stdout: string | null + stderr: string | null + baseCommand: string | null + sessionId: string | null + taskId: string | null + sequenceId: number | null + errors: CrowdStrikeApiError[] + } +} + +export interface CrowdStrikeDeleteRtrSessionResponse extends ToolResponse { + output: { + sessionId: string + deleted: boolean + errors: CrowdStrikeApiError[] + } +} + +export interface CrowdStrikeQueryCasesParams extends CrowdStrikeBaseParams { + filter?: string + q?: string + limit?: number + offset?: number + sort?: string +} + +export interface CrowdStrikeGetCaseDetailsParams extends CrowdStrikeBaseParams { + caseIds: string[] +} + +export interface CrowdStrikeFalconUser { + uuid: string | null + email: string | null + fullName: string | null +} + +export interface CrowdStrikeCase { + id: string | null + cid: string | null + name: string | null + description: string | null + descriptionFormat: string | null + status: string | null + severity: number | null + severityLevel: string | null + referenceId: string | null + version: number | null + tags: string[] + assignedTo: CrowdStrikeFalconUser | null + createdBy: CrowdStrikeFalconUser | null + lastUpdatedBy: CrowdStrikeFalconUser | null + createdTimestamp: string | null + updatedTimestamp: string | null + startTimestamp: string | null + endTimestamp: string | null + templateId: string | null + templateName: string | null + slaId: string | null + slaName: string | null + isReadOnly: boolean | null +} + +export interface CrowdStrikeQueryCasesResponse extends ToolResponse { + output: { + caseIds: string[] + count: number + pagination: CrowdStrikePagination | null + } +} + +export interface CrowdStrikeGetCaseDetailsResponse extends ToolResponse { + output: { + cases: CrowdStrikeCase[] + count: number + errors: CrowdStrikeApiError[] + } +} + export type CrowdStrikeResponse = | CrowdStrikeQuerySensorsResponse | CrowdStrikeGetSensorDetailsResponse | CrowdStrikeGetSensorAggregatesResponse + | CrowdStrikeQueryAlertsResponse + | CrowdStrikeGetAlertDetailsResponse + | CrowdStrikeUpdateAlertsResponse + | CrowdStrikePerformHostActionResponse + | CrowdStrikeQueryHostGroupsResponse + | CrowdStrikeGetHostGroupDetailsResponse + | CrowdStrikePerformHostGroupActionResponse + | CrowdStrikeQueryIndicatorsResponse + | CrowdStrikeIndicatorListResponse + | CrowdStrikeDeleteIndicatorsResponse + | CrowdStrikeQueryVulnerabilitiesResponse + | CrowdStrikeGetVulnerabilityDetailsResponse + | CrowdStrikeInitRtrSessionResponse + | CrowdStrikeExecuteRtrCommandResponse + | CrowdStrikeGetRtrCommandStatusResponse + | CrowdStrikeDeleteRtrSessionResponse + | CrowdStrikeQueryCasesResponse + | CrowdStrikeGetCaseDetailsResponse diff --git a/apps/sim/tools/crowdstrike/update_alerts.ts b/apps/sim/tools/crowdstrike/update_alerts.ts new file mode 100644 index 00000000000..dcc69ee96c4 --- /dev/null +++ b/apps/sim/tools/crowdstrike/update_alerts.ts @@ -0,0 +1,181 @@ +import type { + CrowdStrikeUpdateAlertsParams, + CrowdStrikeUpdateAlertsResponse, +} from '@/tools/crowdstrike/types' +import type { ToolConfig } from '@/tools/types' + +export const crowdstrikeUpdateAlertsTool: ToolConfig< + CrowdStrikeUpdateAlertsParams, + CrowdStrikeUpdateAlertsResponse +> = { + id: 'crowdstrike_update_alerts', + name: 'CrowdStrike Update Alerts', + description: + 'Update CrowdStrike Falcon alerts by composite ID: change status, assign or unassign an analyst, add or remove tags, append a comment, or toggle visibility (PATCH /alerts/entities/alerts/v3). This modifies live alerts in the Falcon console. Requires the "Alerts: Write" API scope.', + version: '1.0.0', + + params: { + clientId: { + type: 'string', + required: true, + visibility: 'user-only', + description: 'CrowdStrike Falcon API client ID', + }, + clientSecret: { + type: 'string', + required: true, + visibility: 'user-only', + description: 'CrowdStrike Falcon API client secret', + }, + cloud: { + type: 'string', + required: true, + visibility: 'user-only', + description: 'CrowdStrike Falcon cloud region', + }, + compositeIds: { + type: 'json', + required: true, + visibility: 'user-or-llm', + description: 'JSON array of CrowdStrike composite alert IDs to update', + }, + updateStatus: { + type: 'string', + required: false, + visibility: 'user-or-llm', + description: 'New alert status: new, in_progress, reopened, or closed', + }, + assignToUuid: { + type: 'string', + required: false, + visibility: 'user-or-llm', + description: 'Assign the alert to this Falcon user UUID', + }, + assignToUserId: { + type: 'string', + required: false, + visibility: 'user-or-llm', + description: 'Assign the alert to this Falcon user ID, such as user@example.com', + }, + assignToName: { + type: 'string', + required: false, + visibility: 'user-or-llm', + description: 'Assign the alert to this Falcon username, such as John Doe', + }, + unassign: { + type: 'boolean', + required: false, + visibility: 'user-or-llm', + description: 'Clear the assigned user UUID, user ID, and username from the alert', + }, + appendComment: { + type: 'string', + required: false, + visibility: 'user-or-llm', + description: 'Comment to append to the alert in the Falcon console', + }, + addTag: { + type: 'string', + required: false, + visibility: 'user-or-llm', + description: 'Tag to add to the alert', + }, + removeTag: { + type: 'string', + required: false, + visibility: 'user-or-llm', + description: 'Tag to remove from the alert', + }, + removeTagsByPrefix: { + type: 'string', + required: false, + visibility: 'user-or-llm', + description: 'Remove every tag on the alert that starts with this prefix', + }, + showInUi: { + type: 'boolean', + required: false, + visibility: 'user-or-llm', + description: 'Whether the alert is displayed in the Falcon console', + }, + actionParameters: { + type: 'json', + required: false, + visibility: 'user-or-llm', + description: + 'Raw JSON array of additional CrowdStrike action parameters, each shaped { "name": string, "value": string }', + }, + includeHidden: { + type: 'boolean', + required: false, + visibility: 'user-or-llm', + description: 'Include previously hidden alerts (CrowdStrike defaults this to true)', + }, + }, + + request: { + url: '/api/tools/crowdstrike/query', + method: 'POST', + headers: () => ({ + 'Content-Type': 'application/json', + }), + body: (params) => ({ + actionParameters: params.actionParameters, + addTag: params.addTag, + appendComment: params.appendComment, + assignToName: params.assignToName, + assignToUserId: params.assignToUserId, + assignToUuid: params.assignToUuid, + cloud: params.cloud, + clientId: params.clientId, + clientSecret: params.clientSecret, + compositeIds: params.compositeIds, + includeHidden: params.includeHidden, + operation: 'crowdstrike_update_alerts', + removeTag: params.removeTag, + removeTagsByPrefix: params.removeTagsByPrefix, + showInUi: params.showInUi, + unassign: params.unassign, + updateStatus: params.updateStatus, + }), + }, + + transformResponse: async (response) => { + const data = await response.json() + + if (!response.ok || data.success === false) { + throw new Error(data.error || 'Failed to update CrowdStrike alerts') + } + + return { + success: true, + output: data.output, + } + }, + + outputs: { + updatedIds: { + type: 'array', + description: 'Composite alert IDs the update was submitted for', + items: { type: 'string' }, + }, + count: { + type: 'number', + description: 'Number of alerts the update was submitted for', + }, + errors: { + type: 'array', + description: 'Errors CrowdStrike returned alongside a partially successful response', + optional: true, + items: { + type: 'object', + properties: { + code: { type: 'number', description: 'CrowdStrike error code', optional: true }, + id: { type: 'string', description: 'Identifier the error applies to', optional: true }, + message: { type: 'string', description: 'Error message', optional: true }, + }, + }, + }, + }, +} diff --git a/apps/sim/tools/crowdstrike/update_indicators.ts b/apps/sim/tools/crowdstrike/update_indicators.ts new file mode 100644 index 00000000000..6c4ce2e2338 --- /dev/null +++ b/apps/sim/tools/crowdstrike/update_indicators.ts @@ -0,0 +1,226 @@ +import type { + CrowdStrikeUpdateIndicatorsParams, + CrowdStrikeUpdateIndicatorsResponse, +} from '@/tools/crowdstrike/types' +import type { ToolConfig } from '@/tools/types' + +export const crowdstrikeUpdateIndicatorsTool: ToolConfig< + CrowdStrikeUpdateIndicatorsParams, + CrowdStrikeUpdateIndicatorsResponse +> = { + id: 'crowdstrike_update_indicators', + name: 'CrowdStrike Update Indicators', + description: + 'Update custom CrowdStrike Falcon indicators of compromise by ID (PATCH /iocs/entities/indicators/v1). DESTRUCTIVE: CrowdStrike blanks out any field you omit, so read each indicator with crowdstrike_get_indicator_details first and resend its full field set with your edits applied. Changing action or scope changes prevention behavior fleet-wide. type and value are immutable. Requires the "IOC Management: Write" API scope.', + version: '1.0.0', + + params: { + clientId: { + type: 'string', + required: true, + visibility: 'user-only', + description: 'CrowdStrike Falcon API client ID', + }, + clientSecret: { + type: 'string', + required: true, + visibility: 'user-only', + description: 'CrowdStrike Falcon API client secret', + }, + cloud: { + type: 'string', + required: true, + visibility: 'user-only', + description: 'CrowdStrike Falcon cloud region', + }, + indicators: { + type: 'json', + required: true, + visibility: 'user-or-llm', + description: + 'JSON array of indicators to update. Each entry requires id, and must also repeat every field it wants to keep: CrowdStrike blanks out any updatable field the entry omits. Updatable fields: action, severity, description, source, tags (array), platforms (array), applied_globally (boolean), host_groups (array), expiration (ISO 8601), mobile_action, metadata ({ filename }). type and value cannot be changed.', + }, + comment: { + type: 'string', + required: false, + visibility: 'user-or-llm', + description: 'Audit comment explaining why these indicators were updated', + }, + retrodetects: { + type: 'boolean', + required: false, + visibility: 'user-or-llm', + description: 'Whether to generate retroactive detections for the updated indicators', + }, + ignoreWarnings: { + type: 'boolean', + required: false, + visibility: 'user-or-llm', + description: 'Whether to apply the updates even when CrowdStrike returns warnings', + }, + }, + + request: { + url: '/api/tools/crowdstrike/query', + method: 'POST', + headers: () => ({ + 'Content-Type': 'application/json', + }), + body: (params) => ({ + cloud: params.cloud, + clientId: params.clientId, + clientSecret: params.clientSecret, + comment: params.comment, + ignoreWarnings: params.ignoreWarnings, + indicators: params.indicators, + operation: 'crowdstrike_update_indicators', + retrodetects: params.retrodetects, + }), + }, + + transformResponse: async (response) => { + const data = await response.json() + + if (!response.ok || data.success === false) { + throw new Error(data.error || 'Failed to update CrowdStrike indicators') + } + + return { + success: true, + output: data.output, + } + }, + + outputs: { + indicators: { + type: 'array', + description: 'Updated CrowdStrike indicator records', + items: { + type: 'object', + properties: { + id: { type: 'string', description: 'Indicator identifier', optional: true }, + type: { type: 'string', description: 'Indicator type', optional: true }, + value: { type: 'string', description: 'Indicator value', optional: true }, + action: { + type: 'string', + description: 'Action taken when the indicator matches', + optional: true, + }, + mobileAction: { + type: 'string', + description: 'Action taken on mobile platforms when the indicator matches', + optional: true, + }, + severity: { type: 'string', description: 'Indicator severity', optional: true }, + description: { type: 'string', description: 'Indicator description', optional: true }, + source: { type: 'string', description: 'Indicator source', optional: true }, + appliedGlobally: { + type: 'boolean', + description: 'Whether the indicator applies to all hosts', + optional: true, + }, + platforms: { + type: 'array', + description: 'Platforms the indicator applies to', + optional: true, + items: { type: 'string' }, + }, + hostGroups: { + type: 'array', + description: 'Host group IDs the indicator is scoped to', + optional: true, + items: { type: 'string' }, + }, + tags: { + type: 'array', + description: 'Tags applied to the indicator', + optional: true, + items: { type: 'string' }, + }, + expiration: { + type: 'string', + description: 'Indicator expiration timestamp', + optional: true, + }, + expired: { + type: 'boolean', + description: 'Whether the indicator has expired', + optional: true, + }, + deleted: { + type: 'boolean', + description: 'Whether the indicator is deleted', + optional: true, + }, + fromParent: { + type: 'boolean', + description: 'Whether the indicator was inherited from a parent CID', + optional: true, + }, + parentCidName: { type: 'string', description: 'Parent CID name', optional: true }, + createdBy: { + type: 'string', + description: 'User who created the indicator', + optional: true, + }, + createdOn: { + type: 'string', + description: 'Indicator creation timestamp', + optional: true, + }, + modifiedBy: { + type: 'string', + description: 'User who last modified the indicator', + optional: true, + }, + modifiedOn: { + type: 'string', + description: 'Indicator modification timestamp', + optional: true, + }, + metadata: { + type: 'json', + description: 'File metadata CrowdStrike resolved for the indicator', + optional: true, + properties: { + avHits: { type: 'number', description: 'Antivirus hit count', optional: true }, + companyName: { type: 'string', description: 'Company name', optional: true }, + fileDescription: { type: 'string', description: 'File description', optional: true }, + fileVersion: { type: 'string', description: 'File version', optional: true }, + filename: { type: 'string', description: 'File name', optional: true }, + originalFilename: { + type: 'string', + description: 'Original file name', + optional: true, + }, + productName: { type: 'string', description: 'Product name', optional: true }, + productVersion: { type: 'string', description: 'Product version', optional: true }, + signed: { + type: 'boolean', + description: 'Whether the file is signed', + optional: true, + }, + }, + }, + }, + }, + }, + count: { + type: 'number', + description: 'Number of indicators updated', + }, + errors: { + type: 'array', + description: 'Errors CrowdStrike returned alongside a partially successful response', + optional: true, + items: { + type: 'object', + properties: { + code: { type: 'number', description: 'CrowdStrike error code', optional: true }, + id: { type: 'string', description: 'Identifier the error applies to', optional: true }, + message: { type: 'string', description: 'Error message', optional: true }, + }, + }, + }, + }, +} diff --git a/apps/sim/tools/generated/tool-ids.ts b/apps/sim/tools/generated/tool-ids.ts index 597eec20d92..5b1376a8131 100644 --- a/apps/sim/tools/generated/tool-ids.ts +++ b/apps/sim/tools/generated/tool-ids.ts @@ -3,7 +3,7 @@ /** Every registered tool id, including versioned variants. */ const toolIds: string[] = JSON.parse( - '["a2a_cancel_task","a2a_get_agent_card","a2a_get_task","a2a_send_message","agentmail_create_draft","agentmail_create_inbox","agentmail_delete_draft","agentmail_delete_inbox","agentmail_delete_thread","agentmail_forward_message","agentmail_get_draft","agentmail_get_inbox","agentmail_get_message","agentmail_get_thread","agentmail_list_drafts","agentmail_list_inboxes","agentmail_list_messages","agentmail_list_threads","agentmail_reply_message","agentmail_send_draft","agentmail_send_message","agentmail_update_draft","agentmail_update_inbox","agentmail_update_message","agentmail_update_thread","agentphone_create_call","agentphone_create_contact","agentphone_create_number","agentphone_delete_contact","agentphone_get_call","agentphone_get_call_transcript","agentphone_get_contact","agentphone_get_conversation","agentphone_get_conversation_messages","agentphone_get_number_messages","agentphone_get_usage","agentphone_get_usage_daily","agentphone_get_usage_monthly","agentphone_list_calls","agentphone_list_contacts","agentphone_list_conversations","agentphone_list_numbers","agentphone_react_to_message","agentphone_release_number","agentphone_send_message","agentphone_update_contact","agentphone_update_conversation","agiloft_async_status","agiloft_attach_file","agiloft_attachment_info","agiloft_create_record","agiloft_delete_record","agiloft_get_choice_line_id","agiloft_list_tables","agiloft_lock_record","agiloft_nlp_search","agiloft_read_record","agiloft_remove_attachment","agiloft_retrieve_attachment","agiloft_run_action_button","agiloft_saved_search","agiloft_search_records","agiloft_select_records","agiloft_update_record","agiloft_upsert_record","ahrefs_anchors","ahrefs_backlinks","ahrefs_backlinks_stats","ahrefs_batch_analysis","ahrefs_broken_backlinks","ahrefs_domain_rating","ahrefs_domain_rating_history","ahrefs_keyword_overview","ahrefs_keywords_history","ahrefs_metrics","ahrefs_metrics_history","ahrefs_organic_competitors","ahrefs_organic_keywords","ahrefs_paid_pages","ahrefs_rank_tracker_competitors_overview","ahrefs_rank_tracker_competitors_stats","ahrefs_rank_tracker_overview","ahrefs_rank_tracker_serp_overview","ahrefs_refdomains_history","ahrefs_referring_domains","ahrefs_related_terms","ahrefs_site_audit_page_explorer","ahrefs_top_pages","airtable_create_records","airtable_delete_records","airtable_get_base_schema","airtable_get_record","airtable_list_bases","airtable_list_records","airtable_list_tables","airtable_update_multiple_records","airtable_update_record","airtable_upsert_records","airweave_search","algolia_add_record","algolia_batch_operations","algolia_browse_records","algolia_clear_records","algolia_copy_move_index","algolia_delete_by_filter","algolia_delete_index","algolia_delete_record","algolia_get_record","algolia_get_records","algolia_get_settings","algolia_get_task_status","algolia_list_indices","algolia_partial_update_record","algolia_search","algolia_update_settings","amplitude_event_segmentation","amplitude_funnels","amplitude_get_active_users","amplitude_get_revenue","amplitude_group_identify","amplitude_identify_user","amplitude_list_events","amplitude_realtime_active_users","amplitude_retention","amplitude_send_event","amplitude_user_activity","amplitude_user_profile","amplitude_user_search","apify_get_dataset_items","apify_get_run","apify_run_actor_async","apify_run_actor_sync","apify_run_task","apollo_account_bulk_create","apollo_account_bulk_update","apollo_account_create","apollo_account_search","apollo_account_update","apollo_contact_bulk_create","apollo_contact_bulk_update","apollo_contact_create","apollo_contact_search","apollo_contact_update","apollo_email_accounts","apollo_opportunity_create","apollo_opportunity_get","apollo_opportunity_search","apollo_opportunity_update","apollo_organization_bulk_enrich","apollo_organization_enrich","apollo_organization_search","apollo_people_bulk_enrich","apollo_people_enrich","apollo_people_search","apollo_sequence_add_contacts","apollo_sequence_search","apollo_task_create","apollo_task_search","appconfig_create_application","appconfig_create_configuration_profile","appconfig_create_environment","appconfig_create_hosted_configuration_version","appconfig_delete_application","appconfig_delete_configuration_profile","appconfig_delete_environment","appconfig_delete_hosted_configuration_version","appconfig_get_application","appconfig_get_configuration","appconfig_get_configuration_profile","appconfig_get_deployment","appconfig_get_environment","appconfig_get_hosted_configuration_version","appconfig_list_applications","appconfig_list_configuration_profiles","appconfig_list_deployment_strategies","appconfig_list_deployments","appconfig_list_environments","appconfig_list_hosted_configuration_versions","appconfig_start_deployment","appconfig_stop_deployment","appconfig_update_application","appconfig_update_configuration_profile","appconfig_update_environment","arxiv_get_author_papers","arxiv_get_paper","arxiv_search","asana_add_comment","asana_add_followers","asana_create_project","asana_create_section","asana_create_subtask","asana_create_task","asana_delete_task","asana_get_project","asana_get_projects","asana_get_task","asana_list_sections","asana_list_workspaces","asana_search_tasks","asana_update_task","ashby_add_candidate_tag","ashby_anonymize_candidate","ashby_change_application_source","ashby_change_application_stage","ashby_create_application","ashby_create_candidate","ashby_create_note","ashby_delete_application","ashby_get_application","ashby_get_candidate","ashby_get_job","ashby_get_job_posting","ashby_get_offer","ashby_list_applications","ashby_list_archive_reasons","ashby_list_candidate_tags","ashby_list_candidates","ashby_list_custom_fields","ashby_list_departments","ashby_list_interviews","ashby_list_job_postings","ashby_list_jobs","ashby_list_locations","ashby_list_notes","ashby_list_offers","ashby_list_openings","ashby_list_sources","ashby_list_users","ashby_remove_candidate_tag","ashby_search_candidates","ashby_set_custom_field_value","ashby_set_custom_field_values","ashby_update_candidate","athena_batch_get_query_execution","athena_create_named_query","athena_delete_named_query","athena_get_named_query","athena_get_query_execution","athena_get_query_results","athena_list_databases","athena_list_named_queries","athena_list_query_executions","athena_list_table_metadata","athena_start_query","athena_stop_query","attio_assert_record","attio_create_attribute","attio_create_comment","attio_create_list","attio_create_list_entry","attio_create_note","attio_create_object","attio_create_record","attio_create_task","attio_create_webhook","attio_delete_comment","attio_delete_list_entry","attio_delete_note","attio_delete_record","attio_delete_task","attio_delete_webhook","attio_get_attribute","attio_get_comment","attio_get_list","attio_get_list_entry","attio_get_member","attio_get_note","attio_get_object","attio_get_record","attio_get_task","attio_get_thread","attio_get_webhook","attio_list_attributes","attio_list_lists","attio_list_members","attio_list_notes","attio_list_objects","attio_list_records","attio_list_tasks","attio_list_threads","attio_list_webhooks","attio_query_list_entries","attio_search_records","attio_update_attribute","attio_update_list","attio_update_list_entry","attio_update_object","attio_update_record","attio_update_task","attio_update_webhook","azure_data_explorer_create_table","azure_data_explorer_drop_table","azure_data_explorer_ingest_from_query","azure_data_explorer_ingest_inline","azure_data_explorer_list_databases","azure_data_explorer_list_functions","azure_data_explorer_list_tables","azure_data_explorer_management","azure_data_explorer_query","azure_data_explorer_show_database_schema","azure_data_explorer_show_ingestion_failures","azure_data_explorer_show_operations","azure_data_explorer_show_table_details","azure_data_explorer_show_table_schema","azure_devops_add_comment","azure_devops_create_work_item","azure_devops_get_build_log","azure_devops_get_build_timeline","azure_devops_get_comments","azure_devops_get_pipeline","azure_devops_get_pipeline_run","azure_devops_get_work_item","azure_devops_get_work_items_batch","azure_devops_get_work_items_between_builds","azure_devops_list_build_logs","azure_devops_list_builds","azure_devops_list_pipeline_runs","azure_devops_list_pipelines","azure_devops_query_work_items","azure_devops_update_work_item","box_copy_file","box_create_folder","box_delete_file","box_delete_folder","box_download_file","box_get_file_info","box_list_folder_items","box_search","box_sign_cancel_request","box_sign_create_request","box_sign_get_request","box_sign_list_requests","box_sign_resend_request","box_update_file","box_upload_file","brandfetch_get_brand","brandfetch_search","brex_archive_budget","brex_create_budget","brex_create_spend_limit","brex_create_transfer","brex_create_vendor","brex_get_budget","brex_get_cash_account","brex_get_company","brex_get_current_user","brex_get_expense","brex_get_spend_limit","brex_get_transfer","brex_get_user","brex_get_vendor","brex_list_budgets","brex_list_card_accounts","brex_list_card_statements","brex_list_card_transactions","brex_list_cards","brex_list_cash_accounts","brex_list_cash_statements","brex_list_cash_transactions","brex_list_departments","brex_list_expenses","brex_list_locations","brex_list_spend_limits","brex_list_titles","brex_list_transfers","brex_list_users","brex_list_vendors","brex_match_receipt","brex_update_expense","brex_update_vendor","brex_upload_receipt","brightdata_cancel_snapshot","brightdata_discover","brightdata_download_snapshot","brightdata_scrape_dataset","brightdata_scrape_url","brightdata_serp_search","brightdata_snapshot_status","brightdata_sync_scrape","browser_use_run_task","buffer_create_idea","buffer_create_post","buffer_delete_post","buffer_edit_post","buffer_get_account","buffer_get_channels","buffer_get_idea_groups","buffer_get_ideas","buffer_get_post","buffer_get_posts","calcom_cancel_booking","calcom_confirm_booking","calcom_create_booking","calcom_create_event_type","calcom_create_schedule","calcom_decline_booking","calcom_delete_event_type","calcom_delete_schedule","calcom_get_booking","calcom_get_default_schedule","calcom_get_event_type","calcom_get_schedule","calcom_get_slots","calcom_list_bookings","calcom_list_event_types","calcom_list_schedules","calcom_reschedule_booking","calcom_update_event_type","calcom_update_schedule","calendly_cancel_event","calendly_create_event_invitee","calendly_create_invitee_no_show","calendly_create_scheduling_link","calendly_create_webhook","calendly_delete_invitee_no_show","calendly_delete_webhook","calendly_get_current_user","calendly_get_event_invitee","calendly_get_event_type","calendly_get_scheduled_event","calendly_get_user","calendly_list_event_invitees","calendly_list_event_type_available_times","calendly_list_event_types","calendly_list_organization_memberships","calendly_list_routing_form_submissions","calendly_list_routing_forms","calendly_list_scheduled_events","calendly_list_user_availability_schedules","calendly_list_user_busy_times","calendly_list_webhooks","clay_populate","clerk_add_organization_member","clerk_ban_user","clerk_create_actor_token","clerk_create_allowlist_identifier","clerk_create_blocklist_identifier","clerk_create_organization","clerk_create_organization_invitation","clerk_create_user","clerk_delete_allowlist_identifier","clerk_delete_blocklist_identifier","clerk_delete_organization","clerk_delete_user","clerk_get_jwt_template","clerk_get_organization","clerk_get_session","clerk_get_user","clerk_get_user_oauth_token","clerk_list_allowlist_identifiers","clerk_list_blocklist_identifiers","clerk_list_jwt_templates","clerk_list_organization_invitations","clerk_list_organization_memberships","clerk_list_organizations","clerk_list_sessions","clerk_list_users","clerk_lock_user","clerk_remove_organization_member","clerk_revoke_actor_token","clerk_revoke_session","clerk_unban_user","clerk_unlock_user","clerk_update_organization","clerk_update_organization_membership","clerk_update_user","clickhouse_count_rows","clickhouse_create_database","clickhouse_create_table","clickhouse_delete","clickhouse_describe_table","clickhouse_drop_database","clickhouse_drop_partition","clickhouse_drop_table","clickhouse_execute","clickhouse_insert","clickhouse_insert_rows","clickhouse_introspect","clickhouse_kill_query","clickhouse_list_clusters","clickhouse_list_databases","clickhouse_list_mutations","clickhouse_list_partitions","clickhouse_list_running_queries","clickhouse_list_tables","clickhouse_optimize_table","clickhouse_query","clickhouse_rename_table","clickhouse_show_create_table","clickhouse_table_stats","clickhouse_truncate_table","clickhouse_update","clickup_add_tag_to_task","clickup_create_checklist","clickup_create_checklist_item","clickup_create_comment","clickup_create_folder","clickup_create_list","clickup_create_task","clickup_create_time_entry","clickup_delete_checklist","clickup_delete_checklist_item","clickup_delete_comment","clickup_delete_task","clickup_delete_time_entry","clickup_get_comments","clickup_get_custom_fields","clickup_get_folders","clickup_get_list_members","clickup_get_lists","clickup_get_running_timer","clickup_get_space_tags","clickup_get_spaces","clickup_get_task","clickup_get_task_members","clickup_get_tasks","clickup_get_time_entries","clickup_get_workspaces","clickup_remove_custom_field_value","clickup_remove_tag_from_task","clickup_search_tasks","clickup_set_custom_field_value","clickup_start_timer","clickup_stop_timer","clickup_update_checklist","clickup_update_checklist_item","clickup_update_comment","clickup_update_task","clickup_update_time_entry","clickup_upload_attachment","cloudflare_create_dns_record","cloudflare_create_zone","cloudflare_delete_dns_record","cloudflare_delete_zone","cloudflare_dns_analytics","cloudflare_get_zone","cloudflare_get_zone_settings","cloudflare_list_certificates","cloudflare_list_dns_records","cloudflare_list_zones","cloudflare_purge_cache","cloudflare_update_dns_record","cloudflare_update_zone_setting","cloudformation_cancel_update_stack","cloudformation_create_change_set","cloudformation_create_stack","cloudformation_delete_stack","cloudformation_describe_change_set","cloudformation_describe_stack_drift_detection_status","cloudformation_describe_stack_events","cloudformation_describe_stacks","cloudformation_detect_stack_drift","cloudformation_execute_change_set","cloudformation_get_template","cloudformation_get_template_summary","cloudformation_list_stack_resources","cloudformation_update_stack","cloudformation_validate_template","cloudwatch_describe_alarm_history","cloudwatch_describe_alarms","cloudwatch_describe_log_groups","cloudwatch_describe_log_streams","cloudwatch_filter_log_events","cloudwatch_get_log_events","cloudwatch_get_metric_statistics","cloudwatch_list_metrics","cloudwatch_mute_alarm","cloudwatch_put_log_group_retention","cloudwatch_put_metric_data","cloudwatch_query_logs","cloudwatch_unmute_alarm","codepipeline_disable_stage_transition","codepipeline_enable_stage_transition","codepipeline_get_pipeline","codepipeline_get_pipeline_execution","codepipeline_get_pipeline_state","codepipeline_list_action_executions","codepipeline_list_pipeline_executions","codepipeline_list_pipelines","codepipeline_put_approval_result","codepipeline_retry_stage_execution","codepipeline_start_execution","codepipeline_stop_execution","confluence_add_label","confluence_create_blogpost","confluence_create_comment","confluence_create_page","confluence_create_page_property","confluence_create_space","confluence_create_space_property","confluence_delete_attachment","confluence_delete_blogpost","confluence_delete_comment","confluence_delete_label","confluence_delete_page","confluence_delete_page_property","confluence_delete_space","confluence_delete_space_property","confluence_get_blogpost","confluence_get_page_ancestors","confluence_get_page_children","confluence_get_page_descendants","confluence_get_page_version","confluence_get_pages_by_label","confluence_get_space","confluence_get_task","confluence_get_user","confluence_list_attachments","confluence_list_blogposts","confluence_list_blogposts_in_space","confluence_list_comments","confluence_list_labels","confluence_list_page_properties","confluence_list_page_versions","confluence_list_pages_in_space","confluence_list_space_labels","confluence_list_space_permissions","confluence_list_space_properties","confluence_list_spaces","confluence_list_tasks","confluence_retrieve","confluence_search","confluence_search_in_space","confluence_update","confluence_update_blogpost","confluence_update_comment","confluence_update_space","confluence_update_task","confluence_upload_attachment","context_dev_classify_naics","context_dev_classify_sic","context_dev_crawl","context_dev_extract","context_dev_extract_product","context_dev_extract_products","context_dev_get_brand","context_dev_get_brand_by_email","context_dev_get_brand_by_name","context_dev_get_brand_by_ticker","context_dev_identify_transaction","context_dev_map","context_dev_scrape_fonts","context_dev_scrape_html","context_dev_scrape_images","context_dev_scrape_markdown","context_dev_scrape_styleguide","context_dev_screenshot","context_dev_search","convex_action","convex_document_deltas","convex_list_documents","convex_list_tables","convex_mutation","convex_query","convex_run_function","crowdstrike_get_sensor_aggregates","crowdstrike_get_sensor_details","crowdstrike_query_sensors","cursor_add_followup","cursor_add_followup_v2","cursor_delete_agent","cursor_delete_agent_v2","cursor_download_artifact","cursor_download_artifact_v2","cursor_get_agent","cursor_get_agent_v2","cursor_get_api_key_info","cursor_get_api_key_info_v2","cursor_get_conversation","cursor_get_conversation_v2","cursor_launch_agent","cursor_launch_agent_v2","cursor_list_agents","cursor_list_agents_v2","cursor_list_artifacts","cursor_list_artifacts_v2","cursor_list_models","cursor_list_models_v2","cursor_list_repositories","cursor_list_repositories_v2","cursor_stop_agent","cursor_stop_agent_v2","dagster_delete_run","dagster_get_asset","dagster_get_run","dagster_get_run_logs","dagster_launch_run","dagster_list_assets","dagster_list_jobs","dagster_list_runs","dagster_list_schedules","dagster_list_sensors","dagster_materialize_assets","dagster_reexecute_run","dagster_report_asset_materialization","dagster_start_schedule","dagster_start_sensor","dagster_stop_schedule","dagster_stop_sensor","dagster_terminate_run","dagster_wipe_asset","databricks_cancel_run","databricks_execute_sql","databricks_get_cluster","databricks_get_job","databricks_get_run","databricks_get_run_output","databricks_get_statement","databricks_list_clusters","databricks_list_jobs","databricks_list_runs","databricks_list_warehouses","databricks_run_job","datadog_cancel_downtime","datadog_create_downtime","datadog_create_event","datadog_create_monitor","datadog_get_monitor","datadog_list_downtimes","datadog_list_monitors","datadog_mute_monitor","datadog_query_logs","datadog_query_timeseries","datadog_send_logs","datadog_submit_metrics","datagma_enrich_company","datagma_enrich_person","datagma_find_email","datagma_find_phone","datagma_get_credits","daytona_create_sandbox","daytona_delete_sandbox","daytona_download_file","daytona_execute_command","daytona_get_sandbox","daytona_git_clone","daytona_list_files","daytona_list_sandboxes","daytona_run_code","daytona_start_sandbox","daytona_stop_sandbox","daytona_upload_file","deployed_block_executor","deployments_deploy","deployments_get_version","deployments_list_versions","deployments_promote","deployments_undeploy","devin_append_session_tags","devin_archive_session","devin_create_session","devin_get_session","devin_get_session_tags","devin_list_session_attachments","devin_list_session_messages","devin_list_sessions","devin_replace_session_tags","devin_send_message","devin_terminate_session","discord_add_reaction","discord_archive_thread","discord_assign_role","discord_ban_member","discord_bulk_delete_messages","discord_create_channel","discord_create_invite","discord_create_role","discord_create_thread","discord_create_webhook","discord_delete_channel","discord_delete_invite","discord_delete_message","discord_delete_role","discord_delete_webhook","discord_edit_message","discord_execute_webhook","discord_get_channel","discord_get_invite","discord_get_member","discord_get_messages","discord_get_pinned_messages","discord_get_server","discord_get_user","discord_get_webhook","discord_join_thread","discord_kick_member","discord_leave_thread","discord_list_channels","discord_list_roles","discord_pin_message","discord_remove_reaction","discord_remove_role","discord_send_message","discord_unban_member","discord_unpin_message","discord_update_channel","discord_update_member","discord_update_role","docusign_create_from_template","docusign_download_document","docusign_get_envelope","docusign_list_envelopes","docusign_list_recipients","docusign_list_templates","docusign_send_envelope","docusign_void_envelope","downdetector_get_company","downdetector_get_company_attribution","downdetector_get_company_baseline","downdetector_get_company_events","downdetector_get_company_incidents","downdetector_get_company_indicators","downdetector_get_company_last_15","downdetector_get_company_status","downdetector_get_provider","downdetector_get_reports","downdetector_get_site_companies","downdetector_list_categories","downdetector_list_incidents","downdetector_list_sites","downdetector_search_companies","dropbox_copy","dropbox_create_folder","dropbox_create_shared_link","dropbox_delete","dropbox_download","dropbox_get_metadata","dropbox_list_folder","dropbox_list_revisions","dropbox_list_shared_links","dropbox_move","dropbox_restore","dropbox_search","dropbox_upload","dropcontact_enrich_contact","dspy_chain_of_thought","dspy_predict","dspy_react","dub_bulk_create_links","dub_bulk_delete_links","dub_bulk_update_links","dub_create_link","dub_create_tag","dub_delete_link","dub_get_analytics","dub_get_events","dub_get_link","dub_get_links_count","dub_get_qr_code","dub_list_domains","dub_list_folders","dub_list_links","dub_list_tags","dub_update_link","dub_upsert_link","duckduckgo_search","dynamodb_delete","dynamodb_get","dynamodb_introspect","dynamodb_put","dynamodb_query","dynamodb_scan","dynamodb_update","dynatrace_add_problem_comment","dynatrace_add_tags","dynatrace_close_problem","dynatrace_create_settings_object","dynatrace_create_slo","dynatrace_delete_problem_comment","dynatrace_delete_settings_object","dynatrace_delete_slo","dynatrace_delete_tag","dynatrace_execute_synthetic_monitors","dynatrace_get_attack","dynatrace_get_audit_logs","dynatrace_get_entity","dynatrace_get_event","dynatrace_get_metric","dynatrace_get_problem","dynatrace_get_problem_comment","dynatrace_get_security_problem","dynatrace_get_settings_object","dynatrace_get_slo","dynatrace_get_synthetic_batch","dynatrace_ingest_event","dynatrace_ingest_logs","dynatrace_ingest_metrics","dynatrace_list_attacks","dynatrace_list_entities","dynatrace_list_entity_types","dynatrace_list_events","dynatrace_list_metrics","dynatrace_list_problem_comments","dynatrace_list_problems","dynatrace_list_remediation_items","dynatrace_list_security_problems","dynatrace_list_settings_objects","dynatrace_list_settings_schemas","dynatrace_list_slos","dynatrace_list_synthetic_monitors","dynatrace_list_tags","dynatrace_mute_security_problem","dynatrace_mute_security_problems","dynatrace_query_metrics","dynatrace_search_logs","dynatrace_unmute_security_problem","dynatrace_unmute_security_problems","dynatrace_update_problem_comment","dynatrace_update_settings_object","dynatrace_update_slo","elasticsearch_bulk","elasticsearch_cluster_health","elasticsearch_cluster_stats","elasticsearch_count","elasticsearch_create_index","elasticsearch_delete_document","elasticsearch_delete_index","elasticsearch_get_document","elasticsearch_get_index","elasticsearch_index_document","elasticsearch_list_indices","elasticsearch_search","elasticsearch_update_document","elevenlabs_audio_isolation","elevenlabs_edit_voice_settings","elevenlabs_get_user","elevenlabs_get_voice","elevenlabs_get_voice_settings","elevenlabs_list_models","elevenlabs_list_voices","elevenlabs_sound_effects","elevenlabs_speech_to_speech","elevenlabs_tts","emailbison_attach_leads_to_campaign","emailbison_attach_tags_to_leads","emailbison_create_campaign","emailbison_create_lead","emailbison_create_tag","emailbison_get_lead","emailbison_list_campaigns","emailbison_list_leads","emailbison_list_replies","emailbison_list_tags","emailbison_update_campaign","emailbison_update_campaign_status","emailbison_update_lead","embeddings_cohere","embeddings_gemini","embeddings_mistral","embeddings_openai","embeddings_openrouter","enrich_check_credits","enrich_company_funding","enrich_company_lookup","enrich_company_revenue","enrich_disposable_email_check","enrich_email_to_ip","enrich_email_to_person_lite","enrich_email_to_phone","enrich_email_to_profile","enrich_find_email","enrich_get_post_details","enrich_ip_to_company","enrich_linkedin_profile","enrich_linkedin_to_personal_email","enrich_linkedin_to_work_email","enrich_phone_finder","enrich_reverse_hash_lookup","enrich_sales_pointer_people","enrich_search_company","enrich_search_company_activities","enrich_search_company_employees","enrich_search_jobs","enrich_search_logo","enrich_search_people","enrich_search_people_activities","enrich_search_post_comments","enrich_search_post_comments_by_url","enrich_search_post_reactions","enrich_search_post_reactions_by_url","enrich_search_posts","enrich_search_similar_companies","enrich_verify_email","enrichment_run","enrow_find_email","enrow_verify_email","evernote_copy_note","evernote_create_note","evernote_create_notebook","evernote_create_tag","evernote_delete_note","evernote_get_note","evernote_get_notebook","evernote_list_notebooks","evernote_list_tags","evernote_search_notes","evernote_update_note","exa_agent","exa_answer","exa_find_similar_links","exa_get_contents","exa_search","extend_parser","extend_parser_v2","fathom_get_summary","fathom_get_transcript","fathom_list_meeting_types","fathom_list_meetings","fathom_list_team_members","fathom_list_teams","file_append","file_compress","file_decompress","file_fetch","file_get","file_get_content","file_manage_sharing","file_parser","file_parser_v2","file_parser_v3","file_read","file_write","findymail_find_email_from_linkedin","findymail_find_email_from_name","findymail_find_emails_by_domain","findymail_find_employees","findymail_find_phone","findymail_get_company","findymail_get_credits","findymail_lookup_technologies","findymail_reverse_email_lookup","findymail_search_technologies","findymail_verify_email","firecrawl_agent","firecrawl_batch_scrape","firecrawl_batch_scrape_status","firecrawl_cancel_crawl","firecrawl_crawl","firecrawl_crawl_status","firecrawl_credit_usage","firecrawl_extract","firecrawl_extract_status","firecrawl_map","firecrawl_parse","firecrawl_scrape","firecrawl_search","fireflies_add_to_live_meeting","fireflies_create_bite","fireflies_delete_transcript","fireflies_get_transcript","fireflies_get_user","fireflies_list_bites","fireflies_list_contacts","fireflies_list_transcripts","fireflies_list_users","fireflies_upload_audio","flint_create_task","flint_generate_pages","flint_get_task","function_execute","gamma_check_status","gamma_generate","gamma_generate_from_template","gamma_list_folders","gamma_list_themes","github_add_assignees","github_add_assignees_v2","github_add_labels","github_add_labels_v2","github_cancel_workflow_run","github_cancel_workflow_run_v2","github_check_star","github_check_star_v2","github_close_issue","github_close_issue_v2","github_close_pr","github_close_pr_v2","github_comment","github_comment_v2","github_compare_commits","github_compare_commits_v2","github_create_branch","github_create_branch_v2","github_create_comment_reaction","github_create_comment_reaction_v2","github_create_file","github_create_file_v2","github_create_gist","github_create_gist_v2","github_create_issue","github_create_issue_reaction","github_create_issue_reaction_v2","github_create_issue_v2","github_create_milestone","github_create_milestone_v2","github_create_pr","github_create_pr_review","github_create_pr_review_v2","github_create_pr_v2","github_create_project","github_create_project_v2","github_create_release","github_create_release_v2","github_delete_branch","github_delete_branch_v2","github_delete_comment","github_delete_comment_reaction","github_delete_comment_reaction_v2","github_delete_comment_v2","github_delete_file","github_delete_file_v2","github_delete_gist","github_delete_gist_v2","github_delete_issue_reaction","github_delete_issue_reaction_v2","github_delete_milestone","github_delete_milestone_v2","github_delete_project","github_delete_project_v2","github_delete_release","github_delete_release_v2","github_fork_gist","github_fork_gist_v2","github_fork_repo","github_fork_repo_v2","github_get_branch","github_get_branch_protection","github_get_branch_protection_v2","github_get_branch_v2","github_get_commit","github_get_commit_v2","github_get_file_content","github_get_file_content_v2","github_get_gist","github_get_gist_v2","github_get_issue","github_get_issue_v2","github_get_latest_release","github_get_latest_release_v2","github_get_milestone","github_get_milestone_v2","github_get_pr_files","github_get_pr_files_v2","github_get_project","github_get_project_v2","github_get_readme","github_get_readme_v2","github_get_release","github_get_release_v2","github_get_tree","github_get_tree_v2","github_get_workflow","github_get_workflow_run","github_get_workflow_run_v2","github_get_workflow_v2","github_issue_comment","github_issue_comment_v2","github_job_logs","github_latest_commit","github_latest_commit_v2","github_list_branches","github_list_branches_v2","github_list_commits","github_list_commits_v2","github_list_forks","github_list_forks_v2","github_list_gists","github_list_gists_v2","github_list_issue_comments","github_list_issue_comments_v2","github_list_issues","github_list_issues_v2","github_list_milestones","github_list_milestones_v2","github_list_pr_comments","github_list_pr_comments_v2","github_list_projects","github_list_projects_v2","github_list_prs","github_list_prs_v2","github_list_releases","github_list_releases_v2","github_list_review_threads","github_list_stargazers","github_list_stargazers_v2","github_list_tags","github_list_tags_v2","github_list_workflow_runs","github_list_workflow_runs_v2","github_list_workflows","github_list_workflows_v2","github_merge_pr","github_merge_pr_v2","github_pr","github_pr_v2","github_remove_label","github_remove_label_v2","github_reply_review_thread","github_repo_info","github_repo_info_v2","github_request_reviewers","github_request_reviewers_v2","github_rerun_workflow","github_rerun_workflow_v2","github_resolve_review_thread","github_search_code","github_search_code_v2","github_search_commits","github_search_commits_v2","github_search_issues","github_search_issues_v2","github_search_repos","github_search_repos_v2","github_search_users","github_search_users_v2","github_star_gist","github_star_gist_v2","github_star_repo","github_star_repo_v2","github_status_check_rollup","github_trigger_workflow","github_trigger_workflow_v2","github_unstar_gist","github_unstar_gist_v2","github_unstar_repo","github_unstar_repo_v2","github_update_branch_protection","github_update_branch_protection_v2","github_update_comment","github_update_comment_v2","github_update_file","github_update_file_v2","github_update_gist","github_update_gist_v2","github_update_issue","github_update_issue_v2","github_update_milestone","github_update_milestone_v2","github_update_pr","github_update_pr_v2","github_update_project","github_update_project_v2","github_update_release","github_update_release_v2","gitlab_activate_user","gitlab_add_member","gitlab_add_saml_group_link","gitlab_approve_access_request","gitlab_approve_merge_request","gitlab_approve_user","gitlab_ban_user","gitlab_block_user","gitlab_cancel_pipeline","gitlab_compare_branches","gitlab_create_branch","gitlab_create_file","gitlab_create_issue","gitlab_create_issue_note","gitlab_create_merge_request","gitlab_create_merge_request_note","gitlab_create_pipeline","gitlab_create_release","gitlab_create_user","gitlab_deactivate_user","gitlab_delete_branch","gitlab_delete_issue","gitlab_delete_saml_group_link","gitlab_delete_user","gitlab_delete_user_identity","gitlab_deny_access_request","gitlab_get_file","gitlab_get_group","gitlab_get_issue","gitlab_get_job_log","gitlab_get_merge_request","gitlab_get_merge_request_changes","gitlab_get_pipeline","gitlab_get_project","gitlab_invite_member","gitlab_list_access_requests","gitlab_list_branches","gitlab_list_commits","gitlab_list_groups","gitlab_list_invitations","gitlab_list_issues","gitlab_list_members","gitlab_list_merge_requests","gitlab_list_pipeline_jobs","gitlab_list_pipelines","gitlab_list_projects","gitlab_list_releases","gitlab_list_repository_tree","gitlab_list_saml_group_links","gitlab_list_user_memberships","gitlab_merge_merge_request","gitlab_play_job","gitlab_reject_user","gitlab_remove_member","gitlab_retry_pipeline","gitlab_revoke_invitation","gitlab_search_users","gitlab_unban_user","gitlab_unblock_user","gitlab_update_file","gitlab_update_invitation","gitlab_update_issue","gitlab_update_member","gitlab_update_merge_request","gitlab_update_user","gmail_add_label","gmail_add_label_v2","gmail_archive","gmail_archive_v2","gmail_create_label_v2","gmail_delete","gmail_delete_draft_v2","gmail_delete_label_v2","gmail_delete_v2","gmail_draft","gmail_draft_v2","gmail_edit_draft_v2","gmail_get_draft_v2","gmail_get_thread_v2","gmail_list_drafts_v2","gmail_list_labels_v2","gmail_list_threads_v2","gmail_mark_read","gmail_mark_read_v2","gmail_mark_unread","gmail_mark_unread_v2","gmail_move","gmail_move_v2","gmail_read","gmail_read_v2","gmail_remove_label","gmail_remove_label_v2","gmail_search","gmail_search_v2","gmail_send","gmail_send_v2","gmail_trash_thread_v2","gmail_unarchive","gmail_unarchive_v2","gmail_untrash_thread_v2","gmail_update_label_v2","gong_aggregate_activity","gong_aggregate_by_period","gong_answered_scorecards","gong_ask_anything","gong_assign_flow_prospects","gong_create_call","gong_day_by_day_activity","gong_get_brief","gong_get_call","gong_get_call_transcript","gong_get_coaching","gong_get_extensive_calls","gong_get_folder_content","gong_get_logs","gong_get_prospect_flows","gong_get_user","gong_interaction_stats","gong_list_calls","gong_list_flows","gong_list_library_folders","gong_list_scorecards","gong_list_trackers","gong_list_users","gong_list_workspaces","gong_lookup_email","gong_lookup_phone","gong_purge_email_address","gong_purge_phone_number","gong_unassign_flow_prospects","google_ads_ad_performance","google_ads_campaign_performance","google_ads_list_ad_groups","google_ads_list_campaigns","google_ads_list_customers","google_ads_search","google_appsheet_add_rows","google_appsheet_delete_rows","google_appsheet_edit_rows","google_appsheet_find_rows","google_bigquery_create_dataset","google_bigquery_create_table","google_bigquery_delete_dataset","google_bigquery_delete_table","google_bigquery_get_query_results","google_bigquery_get_table","google_bigquery_insert_rows","google_bigquery_list_datasets","google_bigquery_list_table_data","google_bigquery_list_tables","google_bigquery_query","google_books_volume_details","google_books_volume_search","google_calendar_create","google_calendar_create_calendar","google_calendar_create_calendar_v2","google_calendar_create_v2","google_calendar_delete","google_calendar_delete_calendar","google_calendar_delete_calendar_v2","google_calendar_delete_v2","google_calendar_freebusy","google_calendar_freebusy_v2","google_calendar_get","google_calendar_get_v2","google_calendar_instances","google_calendar_instances_v2","google_calendar_invite","google_calendar_invite_v2","google_calendar_list","google_calendar_list_acl","google_calendar_list_acl_v2","google_calendar_list_calendars","google_calendar_list_calendars_v2","google_calendar_list_v2","google_calendar_move","google_calendar_move_v2","google_calendar_quick_add","google_calendar_quick_add_v2","google_calendar_share_calendar","google_calendar_share_calendar_v2","google_calendar_unshare_calendar","google_calendar_unshare_calendar_v2","google_calendar_update","google_calendar_update_acl","google_calendar_update_acl_v2","google_calendar_update_calendar","google_calendar_update_calendar_v2","google_calendar_update_v2","google_contacts_create","google_contacts_delete","google_contacts_get","google_contacts_list","google_contacts_search","google_contacts_update","google_docs_create","google_docs_create_named_range","google_docs_create_paragraph_bullets","google_docs_delete_content_range","google_docs_delete_named_range","google_docs_delete_paragraph_bullets","google_docs_insert_image","google_docs_insert_page_break","google_docs_insert_table","google_docs_insert_text","google_docs_read","google_docs_replace_text","google_docs_update_paragraph_style","google_docs_update_text_style","google_docs_write","google_drive_copy","google_drive_create_comment","google_drive_create_folder","google_drive_delete","google_drive_delete_comment","google_drive_download","google_drive_export","google_drive_get_about","google_drive_get_content","google_drive_get_file","google_drive_get_revision","google_drive_list","google_drive_list_comments","google_drive_list_permissions","google_drive_list_revisions","google_drive_move","google_drive_search","google_drive_share","google_drive_trash","google_drive_unshare","google_drive_untrash","google_drive_update","google_drive_upload","google_forms_batch_update","google_forms_create_form","google_forms_create_watch","google_forms_delete_watch","google_forms_get_form","google_forms_get_responses","google_forms_list_watches","google_forms_renew_watch","google_forms_set_publish_settings","google_groups_add_alias","google_groups_add_member","google_groups_create_group","google_groups_delete_group","google_groups_get_group","google_groups_get_member","google_groups_get_settings","google_groups_has_member","google_groups_list_aliases","google_groups_list_groups","google_groups_list_members","google_groups_remove_alias","google_groups_remove_member","google_groups_update_group","google_groups_update_member","google_groups_update_settings","google_maps_air_quality","google_maps_directions","google_maps_distance_matrix","google_maps_elevation","google_maps_geocode","google_maps_geolocate","google_maps_place_details","google_maps_places_nearby","google_maps_places_search","google_maps_pollen","google_maps_reverse_geocode","google_maps_snap_to_roads","google_maps_solar","google_maps_speed_limits","google_maps_timezone","google_maps_validate_address","google_meet_create_space","google_meet_end_conference","google_meet_get_conference_record","google_meet_get_space","google_meet_list_conference_records","google_meet_list_participants","google_pagespeed_analyze","google_search","google_sheets_append","google_sheets_append_v2","google_sheets_batch_clear_v2","google_sheets_batch_get_v2","google_sheets_batch_update_v2","google_sheets_clear_v2","google_sheets_copy_sheet_v2","google_sheets_create_spreadsheet_v2","google_sheets_delete_rows_v2","google_sheets_delete_sheet_v2","google_sheets_delete_spreadsheet_v2","google_sheets_get_spreadsheet_v2","google_sheets_read","google_sheets_read_v2","google_sheets_update","google_sheets_update_v2","google_sheets_write","google_sheets_write_v2","google_slides_add_image","google_slides_add_slide","google_slides_batch_update","google_slides_copy_presentation","google_slides_create","google_slides_create_line","google_slides_create_paragraph_bullets","google_slides_create_shape","google_slides_create_sheets_chart","google_slides_create_table","google_slides_create_video","google_slides_delete_object","google_slides_delete_paragraph_bullets","google_slides_delete_table_column","google_slides_delete_table_row","google_slides_delete_text","google_slides_duplicate_object","google_slides_export_presentation","google_slides_get_page","google_slides_get_thumbnail","google_slides_group_objects","google_slides_insert_table_columns","google_slides_insert_table_rows","google_slides_insert_text","google_slides_merge_table_cells","google_slides_read","google_slides_refresh_sheets_chart","google_slides_replace_all_shapes_with_image","google_slides_replace_all_shapes_with_sheets_chart","google_slides_replace_all_text","google_slides_replace_image","google_slides_reroute_line","google_slides_ungroup_objects","google_slides_unmerge_table_cells","google_slides_update_image_properties","google_slides_update_line_category","google_slides_update_line_properties","google_slides_update_page_element_alt_text","google_slides_update_page_element_transform","google_slides_update_page_elements_z_order","google_slides_update_page_properties","google_slides_update_paragraph_style","google_slides_update_shape_properties","google_slides_update_slide_properties","google_slides_update_slides_position","google_slides_update_table_border_properties","google_slides_update_table_cell_properties","google_slides_update_table_column_properties","google_slides_update_table_row_properties","google_slides_update_text_style","google_slides_update_video_properties","google_slides_write","google_tasks_create","google_tasks_delete","google_tasks_get","google_tasks_list","google_tasks_list_task_lists","google_tasks_update","google_translate_detect","google_translate_text","google_vault_add_held_accounts","google_vault_add_matters_permissions","google_vault_close_matters","google_vault_create_matters","google_vault_create_matters_export","google_vault_create_matters_holds","google_vault_create_saved_query","google_vault_delete_matters","google_vault_delete_matters_export","google_vault_delete_matters_holds","google_vault_delete_saved_query","google_vault_download_export_file","google_vault_list_matters","google_vault_list_matters_export","google_vault_list_matters_holds","google_vault_list_saved_queries","google_vault_remove_held_accounts","google_vault_remove_matters_permissions","google_vault_reopen_matters","google_vault_undelete_matters","google_vault_update_matters","google_vault_update_matters_holds","grafana_check_data_source_health","grafana_create_alert_rule","grafana_create_annotation","grafana_create_contact_point","grafana_create_dashboard","grafana_create_folder","grafana_delete_alert_rule","grafana_delete_annotation","grafana_delete_contact_point","grafana_delete_dashboard","grafana_delete_folder","grafana_get_alert_rule","grafana_get_alert_rule_group","grafana_get_dashboard","grafana_get_data_source","grafana_get_folder","grafana_get_health","grafana_list_alert_rules","grafana_list_annotations","grafana_list_contact_points","grafana_list_dashboards","grafana_list_data_sources","grafana_list_folders","grafana_move_folder","grafana_query_data_source","grafana_update_alert_rule","grafana_update_annotation","grafana_update_contact_point","grafana_update_dashboard","grafana_update_folder","grain_create_hook","grain_create_hook_v2","grain_delete_hook","grain_delete_hook_v2","grain_get_recording","grain_get_transcript","grain_list_hooks","grain_list_hooks_v2","grain_list_meeting_types","grain_list_recordings","grain_list_teams","grain_list_views","granola_get_note","granola_list_folders","granola_list_notes","greenhouse_get_application","greenhouse_get_candidate","greenhouse_get_job","greenhouse_get_user","greenhouse_list_applications","greenhouse_list_candidates","greenhouse_list_departments","greenhouse_list_job_stages","greenhouse_list_jobs","greenhouse_list_offices","greenhouse_list_users","greptile_index_repo","greptile_query","greptile_search","greptile_status","guardrails_validate","hex_cancel_run","hex_create_collection","hex_create_group","hex_deactivate_user","hex_delete_group","hex_get_collection","hex_get_data_connection","hex_get_group","hex_get_project","hex_get_project_runs","hex_get_queried_tables","hex_get_run_status","hex_list_collections","hex_list_data_connections","hex_list_groups","hex_list_projects","hex_list_users","hex_run_project","hex_update_collection","hex_update_group","hex_update_project","http_request","hubspot_add_list_memberships","hubspot_create_appointment","hubspot_create_association","hubspot_create_company","hubspot_create_contact","hubspot_create_deal","hubspot_create_email","hubspot_create_line_item","hubspot_create_list","hubspot_create_note","hubspot_create_ticket","hubspot_delete_association","hubspot_delete_company","hubspot_delete_contact","hubspot_delete_deal","hubspot_delete_line_item","hubspot_delete_ticket","hubspot_get_appointment","hubspot_get_association_labels","hubspot_get_cart","hubspot_get_company","hubspot_get_contact","hubspot_get_deal","hubspot_get_email","hubspot_get_line_item","hubspot_get_list","hubspot_get_list_memberships","hubspot_get_marketing_event","hubspot_get_note","hubspot_get_properties","hubspot_get_quote","hubspot_get_ticket","hubspot_get_users","hubspot_list_appointments","hubspot_list_associations","hubspot_list_carts","hubspot_list_companies","hubspot_list_contacts","hubspot_list_deals","hubspot_list_emails","hubspot_list_line_items","hubspot_list_lists","hubspot_list_marketing_events","hubspot_list_notes","hubspot_list_owners","hubspot_list_quotes","hubspot_list_tickets","hubspot_remove_list_memberships","hubspot_search_companies","hubspot_search_contacts","hubspot_search_deals","hubspot_search_emails","hubspot_search_line_items","hubspot_search_notes","hubspot_search_quotes","hubspot_search_tickets","hubspot_update_appointment","hubspot_update_company","hubspot_update_contact","hubspot_update_deal","hubspot_update_line_item","hubspot_update_ticket","huggingface_chat","hunter_companies_find","hunter_discover","hunter_domain_search","hunter_email_count","hunter_email_finder","hunter_email_verifier","iam_add_user_to_group","iam_attach_role_policy","iam_attach_user_policy","iam_create_access_key","iam_create_role","iam_create_user","iam_delete_access_key","iam_delete_role","iam_delete_user","iam_detach_role_policy","iam_detach_user_policy","iam_get_role","iam_get_user","iam_list_attached_role_policies","iam_list_attached_user_policies","iam_list_groups","iam_list_policies","iam_list_roles","iam_list_users","iam_remove_user_from_group","iam_simulate_principal_policy","icypeas_find_email","icypeas_verify_email","identity_center_check_assignment_deletion_status","identity_center_check_assignment_status","identity_center_create_account_assignment","identity_center_delete_account_assignment","identity_center_describe_account","identity_center_get_group","identity_center_get_user","identity_center_list_account_assignments","identity_center_list_accounts","identity_center_list_groups","identity_center_list_instances","identity_center_list_permission_sets","image_generate","incidentio_actions_create","incidentio_actions_list","incidentio_actions_show","incidentio_actions_update","incidentio_alert_events_create","incidentio_alerts_list","incidentio_alerts_resolve","incidentio_alerts_show","incidentio_catalog_entries_list","incidentio_catalog_types_list","incidentio_custom_fields_create","incidentio_custom_fields_delete","incidentio_custom_fields_list","incidentio_custom_fields_show","incidentio_custom_fields_update","incidentio_escalation_paths_create","incidentio_escalation_paths_delete","incidentio_escalation_paths_list","incidentio_escalation_paths_show","incidentio_escalation_paths_update","incidentio_escalations_cancel","incidentio_escalations_create","incidentio_escalations_list","incidentio_escalations_show","incidentio_follow_ups_create","incidentio_follow_ups_list","incidentio_follow_ups_show","incidentio_follow_ups_update","incidentio_incident_alerts_list","incidentio_incident_memberships_create","incidentio_incident_memberships_revoke","incidentio_incident_participants_list","incidentio_incident_roles_create","incidentio_incident_roles_delete","incidentio_incident_roles_list","incidentio_incident_roles_show","incidentio_incident_roles_update","incidentio_incident_statuses_list","incidentio_incident_timestamps_list","incidentio_incident_timestamps_show","incidentio_incident_types_list","incidentio_incident_updates_list","incidentio_incidents_create","incidentio_incidents_list","incidentio_incidents_show","incidentio_incidents_update","incidentio_on_call_now","incidentio_schedule_entries_list","incidentio_schedule_overrides_create","incidentio_schedule_overrides_list","incidentio_schedules_create","incidentio_schedules_delete","incidentio_schedules_list","incidentio_schedules_show","incidentio_schedules_update","incidentio_severities_list","incidentio_teams_list","incidentio_teams_show","incidentio_users_list","incidentio_users_show","incidentio_workflows_create","incidentio_workflows_delete","incidentio_workflows_list","incidentio_workflows_show","incidentio_workflows_update","infisical_create_secret","infisical_delete_secret","infisical_get_secret","infisical_list_secrets","infisical_update_secret","instagram_delete_comment","instagram_download_media","instagram_get_account_insights","instagram_get_container_status","instagram_get_conversation_messages","instagram_get_media","instagram_get_media_insights","instagram_get_message","instagram_get_profile","instagram_get_publishing_limit","instagram_hide_comment","instagram_list_comments","instagram_list_conversations","instagram_list_media","instagram_list_stories","instagram_private_reply","instagram_publish_carousel","instagram_publish_image","instagram_publish_reel","instagram_publish_story","instagram_publish_video","instagram_reply_to_comment","instagram_send_text_message","instagram_set_comments_enabled","instantly_activate_campaign","instantly_create_campaign","instantly_create_lead","instantly_create_lead_list","instantly_delete_campaign","instantly_delete_leads","instantly_get_lead","instantly_list_campaigns","instantly_list_emails","instantly_list_lead_lists","instantly_list_leads","instantly_patch_campaign","instantly_patch_lead","instantly_pause_campaign","instantly_reply_to_email","instantly_update_lead_interest_status","intercom_assign_conversation_v2","intercom_attach_contact_to_company_v2","intercom_close_conversation_v2","intercom_create_company","intercom_create_company_v2","intercom_create_contact","intercom_create_contact_v2","intercom_create_event_v2","intercom_create_message","intercom_create_message_v2","intercom_create_note_v2","intercom_create_tag_v2","intercom_create_ticket","intercom_create_ticket_v2","intercom_delete_contact","intercom_delete_contact_v2","intercom_detach_contact_from_company_v2","intercom_get_company","intercom_get_company_v2","intercom_get_contact","intercom_get_contact_v2","intercom_get_conversation","intercom_get_conversation_v2","intercom_get_ticket","intercom_get_ticket_v2","intercom_list_admins_v2","intercom_list_companies","intercom_list_companies_v2","intercom_list_contacts","intercom_list_contacts_v2","intercom_list_conversations","intercom_list_conversations_v2","intercom_list_tags_v2","intercom_open_conversation_v2","intercom_reply_conversation","intercom_reply_conversation_v2","intercom_search_contacts","intercom_search_contacts_v2","intercom_search_conversations","intercom_search_conversations_v2","intercom_snooze_conversation_v2","intercom_tag_contact_v2","intercom_tag_conversation_v2","intercom_untag_contact_v2","intercom_update_contact","intercom_update_contact_v2","intercom_update_ticket_v2","jina_read_url","jina_search","jira_add_attachment","jira_add_comment","jira_add_watcher","jira_add_worklog","jira_assign_issue","jira_bulk_read","jira_create_issue_link","jira_delete_attachment","jira_delete_comment","jira_delete_issue","jira_delete_issue_link","jira_delete_worklog","jira_get_attachments","jira_get_comments","jira_get_fields","jira_get_project","jira_get_transitions","jira_get_users","jira_get_worklogs","jira_list_issue_types","jira_list_projects","jira_remove_watcher","jira_retrieve","jira_search_issues","jira_search_users","jira_transition_issue","jira_update","jira_update_comment","jira_update_worklog","jira_write","jsm_add_comment","jsm_add_customer","jsm_add_organization","jsm_add_participants","jsm_answer_approval","jsm_attach_form","jsm_copy_forms","jsm_create_object","jsm_create_organization","jsm_create_request","jsm_delete_form","jsm_delete_object","jsm_externalise_form","jsm_get_approvals","jsm_get_comments","jsm_get_customers","jsm_get_form","jsm_get_form_answers","jsm_get_form_structure","jsm_get_form_templates","jsm_get_issue_forms","jsm_get_object","jsm_get_object_schema","jsm_get_object_type_attributes","jsm_get_organizations","jsm_get_participants","jsm_get_queues","jsm_get_request","jsm_get_request_type_fields","jsm_get_request_types","jsm_get_requests","jsm_get_service_desks","jsm_get_sla","jsm_get_transitions","jsm_internalise_form","jsm_list_object_schemas","jsm_list_object_types","jsm_reopen_form","jsm_save_form_answers","jsm_search_objects_aql","jsm_submit_form","jsm_transition_request","jsm_update_object","jupyter_copy_content","jupyter_create_file","jupyter_create_session","jupyter_delete_content","jupyter_delete_session","jupyter_get_content","jupyter_interrupt_kernel","jupyter_list_contents","jupyter_list_kernels","jupyter_list_kernelspecs","jupyter_list_sessions","jupyter_rename_content","jupyter_restart_kernel","jupyter_start_kernel","jupyter_stop_kernel","jupyter_upload_file","kalshi_amend_order","kalshi_amend_order_v2","kalshi_cancel_order","kalshi_cancel_order_v2","kalshi_create_order","kalshi_create_order_v2","kalshi_get_balance","kalshi_get_balance_v2","kalshi_get_candlesticks","kalshi_get_candlesticks_v2","kalshi_get_event","kalshi_get_event_candlesticks","kalshi_get_event_candlesticks_v2","kalshi_get_event_v2","kalshi_get_events","kalshi_get_events_v2","kalshi_get_exchange_announcements","kalshi_get_exchange_announcements_v2","kalshi_get_exchange_schedule","kalshi_get_exchange_schedule_v2","kalshi_get_exchange_status","kalshi_get_exchange_status_v2","kalshi_get_fills","kalshi_get_fills_v2","kalshi_get_market","kalshi_get_market_v2","kalshi_get_markets","kalshi_get_markets_v2","kalshi_get_order","kalshi_get_order_v2","kalshi_get_orderbook","kalshi_get_orderbook_v2","kalshi_get_orders","kalshi_get_orders_v2","kalshi_get_positions","kalshi_get_positions_v2","kalshi_get_series_by_ticker","kalshi_get_series_by_ticker_v2","kalshi_get_series_list","kalshi_get_series_list_v2","kalshi_get_settlements","kalshi_get_settlements_v2","kalshi_get_trades","kalshi_get_trades_v2","ketch_get_consent","ketch_get_subscriptions","ketch_invoke_right","ketch_set_consent","ketch_set_subscriptions","knowledge_create_document","knowledge_delete_chunk","knowledge_delete_document","knowledge_get_connector","knowledge_get_document","knowledge_list_chunks","knowledge_list_connectors","knowledge_list_documents","knowledge_list_tags","knowledge_search","knowledge_trigger_sync","knowledge_update_chunk","knowledge_upload_chunk","knowledge_upsert_document","langsmith_create_feedback","langsmith_create_run","langsmith_create_runs_batch","langsmith_get_run","langsmith_update_run","latex_compile","latex_get_package","latex_list_fonts","latex_search_packages","launchdarkly_create_flag","launchdarkly_delete_flag","launchdarkly_get_audit_log","launchdarkly_get_flag","launchdarkly_get_flag_status","launchdarkly_list_environments","launchdarkly_list_flags","launchdarkly_list_members","launchdarkly_list_projects","launchdarkly_list_segments","launchdarkly_toggle_flag","launchdarkly_update_flag","leadmagic_company_search","leadmagic_email_to_profile","leadmagic_find_email","leadmagic_find_mobile","leadmagic_get_credits","leadmagic_profile_search","leadmagic_profile_to_email","leadmagic_role_finder","leadmagic_validate_email","lemlist_get_activities","lemlist_get_lead","lemlist_send_email","linear_add_label_to_issue","linear_add_label_to_project","linear_archive_issue","linear_archive_label","linear_archive_project","linear_create_attachment","linear_create_comment","linear_create_customer","linear_create_customer_request","linear_create_customer_status","linear_create_customer_tier","linear_create_cycle","linear_create_favorite","linear_create_issue","linear_create_issue_relation","linear_create_label","linear_create_project","linear_create_project_label","linear_create_project_milestone","linear_create_project_status","linear_create_project_update","linear_create_workflow_state","linear_delete_attachment","linear_delete_comment","linear_delete_customer","linear_delete_customer_status","linear_delete_customer_tier","linear_delete_issue","linear_delete_issue_relation","linear_delete_project","linear_delete_project_label","linear_delete_project_milestone","linear_delete_project_status","linear_get_active_cycle","linear_get_customer","linear_get_cycle","linear_get_issue","linear_get_project","linear_get_viewer","linear_list_attachments","linear_list_comments","linear_list_customer_requests","linear_list_customer_statuses","linear_list_customer_tiers","linear_list_customers","linear_list_cycles","linear_list_favorites","linear_list_issue_relations","linear_list_labels","linear_list_notifications","linear_list_project_labels","linear_list_project_milestones","linear_list_project_statuses","linear_list_project_updates","linear_list_projects","linear_list_teams","linear_list_users","linear_list_workflow_states","linear_merge_customers","linear_read_issues","linear_remove_label_from_issue","linear_remove_label_from_project","linear_search_issues","linear_unarchive_issue","linear_update_attachment","linear_update_comment","linear_update_customer","linear_update_customer_request","linear_update_customer_status","linear_update_customer_tier","linear_update_issue","linear_update_label","linear_update_notification","linear_update_project","linear_update_project_label","linear_update_project_milestone","linear_update_project_status","linear_update_workflow_state","linkedin_get_profile","linkedin_share_post","linkup_search","linq_add_participant","linq_check_imessage","linq_check_rcs","linq_create_attachment","linq_create_chat","linq_create_contact_card","linq_create_webhook_subscription","linq_delete_attachment","linq_delete_message","linq_delete_webhook_subscription","linq_edit_message","linq_get_attachment","linq_get_chat","linq_get_contact_card","linq_get_message","linq_get_webhook_subscription","linq_leave_chat","linq_list_chats","linq_list_messages","linq_list_phone_numbers","linq_list_thread","linq_list_webhook_events","linq_list_webhook_subscriptions","linq_mark_chat_read","linq_react_to_message","linq_remove_participant","linq_send_message","linq_send_voice_memo","linq_share_contact_card","linq_start_typing","linq_stop_typing","linq_update_chat","linq_update_contact_card","linq_update_webhook_subscription","llm_chat","logfire_get_token_info","logfire_get_trace","logfire_query","logfire_search_records","logrocket_create_release","logrocket_get_audit_logs","logrocket_get_highlights","logrocket_identify_user","logrocket_list_exported_sessions","logrocket_request_highlights","logs_get","logs_get_execution","logs_get_run_details","logs_query","logs_query_runs","loops_check_contact_suppression","loops_create_contact","loops_create_contact_property","loops_delete_contact","loops_find_contact","loops_get_transactional_email","loops_list_contact_properties","loops_list_mailing_lists","loops_list_transactional_emails","loops_remove_contact_suppression","loops_send_event","loops_send_transactional_email","loops_update_contact","luma_add_guests","luma_cancel_event","luma_create_event","luma_get_event","luma_get_guest","luma_get_guests","luma_list_events","luma_lookup_event","luma_send_invites","luma_update_event","luma_update_guest_status","mailchimp_add_member","mailchimp_add_member_tags","mailchimp_add_or_update_member","mailchimp_add_segment_member","mailchimp_add_subscriber_to_automation","mailchimp_archive_member","mailchimp_create_audience","mailchimp_create_batch_operation","mailchimp_create_campaign","mailchimp_create_interest","mailchimp_create_interest_category","mailchimp_create_landing_page","mailchimp_create_merge_field","mailchimp_create_segment","mailchimp_create_template","mailchimp_delete_audience","mailchimp_delete_batch_operation","mailchimp_delete_campaign","mailchimp_delete_interest","mailchimp_delete_interest_category","mailchimp_delete_landing_page","mailchimp_delete_member","mailchimp_delete_merge_field","mailchimp_delete_segment","mailchimp_delete_template","mailchimp_get_audience","mailchimp_get_audiences","mailchimp_get_automation","mailchimp_get_automations","mailchimp_get_batch_operation","mailchimp_get_batch_operations","mailchimp_get_campaign","mailchimp_get_campaign_content","mailchimp_get_campaign_report","mailchimp_get_campaign_reports","mailchimp_get_campaigns","mailchimp_get_interest","mailchimp_get_interest_categories","mailchimp_get_interest_category","mailchimp_get_interests","mailchimp_get_landing_page","mailchimp_get_landing_pages","mailchimp_get_member","mailchimp_get_member_tags","mailchimp_get_members","mailchimp_get_merge_field","mailchimp_get_merge_fields","mailchimp_get_segment","mailchimp_get_segment_members","mailchimp_get_segments","mailchimp_get_template","mailchimp_get_templates","mailchimp_pause_automation","mailchimp_publish_landing_page","mailchimp_remove_member_tags","mailchimp_remove_segment_member","mailchimp_replicate_campaign","mailchimp_schedule_campaign","mailchimp_send_campaign","mailchimp_set_campaign_content","mailchimp_start_automation","mailchimp_unarchive_member","mailchimp_unpublish_landing_page","mailchimp_unschedule_campaign","mailchimp_update_audience","mailchimp_update_campaign","mailchimp_update_interest","mailchimp_update_interest_category","mailchimp_update_landing_page","mailchimp_update_member","mailchimp_update_merge_field","mailchimp_update_segment","mailchimp_update_template","mailgun_add_list_member","mailgun_create_mailing_list","mailgun_get_domain","mailgun_get_mailing_list","mailgun_get_message","mailgun_list_domains","mailgun_list_messages","mailgun_send_message","managed_agent_archive_session","managed_agent_create_session","managed_agent_delete_session","managed_agent_get_session","managed_agent_interrupt_session","managed_agent_list_events","managed_agent_respond_custom_tool","managed_agent_respond_tool_confirmation","managed_agent_run_session","managed_agent_send_message","managed_agent_update_session","mem0_add_memories","mem0_get_memories","mem0_search_memories","memory_add","memory_delete","memory_get","memory_get_all","microsoft_ad_add_group_member","microsoft_ad_create_group","microsoft_ad_create_user","microsoft_ad_delete_group","microsoft_ad_delete_user","microsoft_ad_get_group","microsoft_ad_get_user","microsoft_ad_list_group_members","microsoft_ad_list_groups","microsoft_ad_list_users","microsoft_ad_remove_group_member","microsoft_ad_update_group","microsoft_ad_update_user","microsoft_dataverse_associate","microsoft_dataverse_create_multiple","microsoft_dataverse_create_record","microsoft_dataverse_delete_record","microsoft_dataverse_disassociate","microsoft_dataverse_download_file","microsoft_dataverse_execute_action","microsoft_dataverse_execute_function","microsoft_dataverse_fetchxml_query","microsoft_dataverse_get_entity_metadata","microsoft_dataverse_get_record","microsoft_dataverse_list_records","microsoft_dataverse_search","microsoft_dataverse_update_multiple","microsoft_dataverse_update_record","microsoft_dataverse_upload_file","microsoft_dataverse_upsert_record","microsoft_dataverse_whoami","microsoft_excel_clear_range","microsoft_excel_create_table","microsoft_excel_delete_worksheet","microsoft_excel_format_range","microsoft_excel_read","microsoft_excel_read_v2","microsoft_excel_sort_range","microsoft_excel_table_add","microsoft_excel_worksheet_add","microsoft_excel_write","microsoft_excel_write_v2","microsoft_planner_create_bucket","microsoft_planner_create_plan","microsoft_planner_create_task","microsoft_planner_delete_bucket","microsoft_planner_delete_plan","microsoft_planner_delete_task","microsoft_planner_get_plan_details","microsoft_planner_get_task_details","microsoft_planner_list_buckets","microsoft_planner_list_plans","microsoft_planner_read_bucket","microsoft_planner_read_plan","microsoft_planner_read_task","microsoft_planner_update_bucket","microsoft_planner_update_plan","microsoft_planner_update_plan_details","microsoft_planner_update_task","microsoft_planner_update_task_details","microsoft_teams_delete_channel_message","microsoft_teams_delete_chat_message","microsoft_teams_get_message","microsoft_teams_list_channel_members","microsoft_teams_list_channels","microsoft_teams_list_chat_members","microsoft_teams_list_chats","microsoft_teams_list_team_members","microsoft_teams_list_teams","microsoft_teams_read_channel","microsoft_teams_read_chat","microsoft_teams_reply_to_message","microsoft_teams_set_reaction","microsoft_teams_unset_reaction","microsoft_teams_update_channel_message","microsoft_teams_update_chat_message","microsoft_teams_write_channel","microsoft_teams_write_chat","millionverifier_get_credits","millionverifier_verify_email","mintlify_create_agent_job","mintlify_create_assistant_message","mintlify_detect_ai_prose","mintlify_get_agent_job","mintlify_get_assistant_caller_stats","mintlify_get_assistant_conversations","mintlify_get_feedback","mintlify_get_feedback_by_page","mintlify_get_page_content","mintlify_get_searches","mintlify_get_update_status","mintlify_get_views","mintlify_get_visitors","mintlify_search","mintlify_send_agent_message","mintlify_trigger_automation","mintlify_trigger_preview","mintlify_trigger_update","mistral_parser","mistral_parser_v2","mistral_parser_v3","monday_archive_item","monday_change_column_value","monday_create_board","monday_create_column","monday_create_group","monday_create_item","monday_create_subitem","monday_create_update","monday_delete_item","monday_duplicate_item","monday_get_board","monday_get_groups","monday_get_item","monday_get_items","monday_list_boards","monday_move_item_to_group","monday_search_items","monday_update_item","mongodb_delete","mongodb_execute","mongodb_insert","mongodb_introspect","mongodb_query","mongodb_update","mysql_delete","mysql_execute","mysql_insert","mysql_introspect","mysql_query","mysql_update","neo4j_create","neo4j_delete","neo4j_execute","neo4j_introspect","neo4j_merge","neo4j_query","neo4j_update","netsuite_attach_record","netsuite_batch_create_records","netsuite_batch_delete_records","netsuite_batch_get_records","netsuite_batch_update_records","netsuite_batch_upsert_records","netsuite_create_record","netsuite_delete_record","netsuite_detach_record","netsuite_execute_action","netsuite_execute_dataset","netsuite_execute_suiteql","netsuite_get_async_result","netsuite_get_async_status","netsuite_get_governance_limits","netsuite_get_record","netsuite_get_record_form","netsuite_get_record_metadata","netsuite_get_select_options","netsuite_get_server_time","netsuite_get_subresource","netsuite_list_datasets","netsuite_list_record_types","netsuite_list_records","netsuite_transform_record","netsuite_update_record","netsuite_upsert_record","neverbounce_get_credits","neverbounce_verify_email","new_relic_create_deployment_event","new_relic_get_entity","new_relic_nrql_query","new_relic_search_entities","notion_add_database_row","notion_add_database_row_v2","notion_append_blocks","notion_append_blocks_v2","notion_create_comment","notion_create_comment_v2","notion_create_database","notion_create_database_v2","notion_create_page","notion_create_page_v2","notion_delete_block","notion_delete_block_v2","notion_list_comments","notion_list_comments_v2","notion_list_users","notion_list_users_v2","notion_query_database","notion_query_database_v2","notion_read","notion_read_database","notion_read_database_v2","notion_read_v2","notion_retrieve_block","notion_retrieve_block_children","notion_retrieve_block_children_v2","notion_retrieve_block_v2","notion_retrieve_user","notion_retrieve_user_v2","notion_search","notion_search_v2","notion_update_block","notion_update_block_v2","notion_update_page","notion_update_page_v2","notion_write","notion_write_v2","obsidian_append_active","obsidian_append_note","obsidian_append_periodic_note","obsidian_create_note","obsidian_delete_note","obsidian_execute_command","obsidian_get_active","obsidian_get_note","obsidian_get_periodic_note","obsidian_list_commands","obsidian_list_files","obsidian_open_file","obsidian_patch_active","obsidian_patch_note","obsidian_search","okta_activate_group_rule","okta_activate_user","okta_add_user_to_group","okta_assign_group_to_app","okta_assign_user_role","okta_assign_user_to_app","okta_clear_user_sessions","okta_create_group","okta_create_group_rule","okta_create_user","okta_deactivate_group_rule","okta_deactivate_user","okta_delete_group","okta_delete_group_rule","okta_delete_user","okta_enroll_factor","okta_get_app","okta_get_factor","okta_get_group","okta_get_group_rule","okta_get_logs","okta_get_session","okta_get_user","okta_list_app_groups","okta_list_app_users","okta_list_apps","okta_list_factors","okta_list_group_members","okta_list_group_rules","okta_list_groups","okta_list_user_roles","okta_list_users","okta_remove_group_from_app","okta_remove_user_from_app","okta_remove_user_from_group","okta_remove_user_role","okta_reset_all_factors","okta_reset_factor","okta_reset_password","okta_revoke_session","okta_suspend_user","okta_unsuspend_user","okta_update_group","okta_update_user","onedrive_copy","onedrive_create_folder","onedrive_create_share_link","onedrive_delete","onedrive_download","onedrive_get_drive_info","onedrive_get_item","onedrive_list","onedrive_move","onedrive_search","onedrive_upload","onepassword_create_item","onepassword_delete_item","onepassword_get_item","onepassword_get_item_file","onepassword_get_vault","onepassword_list_items","onepassword_list_vaults","onepassword_replace_item","onepassword_resolve_secret","onepassword_update_item","openai_embeddings","openai_image","outlook_calendar_create_event","outlook_calendar_delete_event","outlook_calendar_get_event","outlook_calendar_list_events","outlook_calendar_respond","outlook_calendar_update_event","outlook_copy","outlook_create_folder","outlook_delete","outlook_draft","outlook_forward","outlook_get_attachment","outlook_list_attachments","outlook_list_folders","outlook_mark_read","outlook_mark_unread","outlook_move","outlook_read","outlook_reply","outlook_reply_all","outlook_search","outlook_send","outlook_update_message","pagerduty_add_note","pagerduty_create_incident","pagerduty_get_incident","pagerduty_get_service","pagerduty_list_escalation_policies","pagerduty_list_incident_alerts","pagerduty_list_incidents","pagerduty_list_oncalls","pagerduty_list_schedules","pagerduty_list_services","pagerduty_list_users","pagerduty_merge_incidents","pagerduty_send_event","pagerduty_snooze_incident","pagerduty_update_incident","parallel_deep_research","parallel_extract","parallel_search","pdl_autocomplete","pdl_bulk_company_enrich","pdl_bulk_person_enrich","pdl_clean_company","pdl_clean_location","pdl_clean_school","pdl_company_enrich","pdl_company_search","pdl_person_enrich","pdl_person_identify","pdl_person_search","perplexity_chat","perplexity_search","persona_approve_inquiry","persona_create_account","persona_create_inquiry","persona_create_report","persona_decline_inquiry","persona_expire_inquiry","persona_generate_inquiry_link","persona_get_account","persona_get_case","persona_get_document","persona_get_inquiry","persona_get_report","persona_get_verification","persona_import_accounts","persona_list_accounts","persona_list_cases","persona_list_inquiries","persona_list_inquiry_templates","persona_list_reports","persona_mark_inquiry_for_review","persona_print_inquiry_pdf","persona_redact_account","persona_redact_inquiry","persona_resume_inquiry","persona_update_account","persona_update_inquiry","pinecone_delete_vectors","pinecone_describe_index","pinecone_describe_index_stats","pinecone_fetch","pinecone_generate_embeddings","pinecone_list_indexes","pinecone_list_vector_ids","pinecone_search_text","pinecone_search_vector","pinecone_update_vector","pinecone_upsert_text","pipedrive_create_activity","pipedrive_create_deal","pipedrive_create_lead","pipedrive_create_project","pipedrive_delete_lead","pipedrive_get_activities","pipedrive_get_all_deals","pipedrive_get_deal","pipedrive_get_files","pipedrive_get_leads","pipedrive_get_mail_messages","pipedrive_get_mail_thread","pipedrive_get_pipeline_deals","pipedrive_get_pipelines","pipedrive_get_projects","pipedrive_update_activity","pipedrive_update_deal","pipedrive_update_lead","polymarket_get_activity","polymarket_get_event","polymarket_get_events","polymarket_get_holders","polymarket_get_last_trade_price","polymarket_get_leaderboard","polymarket_get_market","polymarket_get_markets","polymarket_get_midpoint","polymarket_get_orderbook","polymarket_get_positions","polymarket_get_price","polymarket_get_price_history","polymarket_get_series","polymarket_get_series_by_id","polymarket_get_spread","polymarket_get_tags","polymarket_get_tick_size","polymarket_get_trades","polymarket_search","postgresql_delete","postgresql_execute","postgresql_insert","postgresql_introspect","postgresql_query","postgresql_update","posthog_batch_events","posthog_capture_event","posthog_create_annotation","posthog_create_cohort","posthog_create_dashboard","posthog_create_experiment","posthog_create_feature_flag","posthog_create_insight","posthog_create_survey","posthog_delete_feature_flag","posthog_delete_person","posthog_delete_survey","posthog_evaluate_flags","posthog_get_cohort","posthog_get_dashboard","posthog_get_event_definition","posthog_get_experiment","posthog_get_feature_flag","posthog_get_insight","posthog_get_organization","posthog_get_person","posthog_get_project","posthog_get_property_definition","posthog_get_session_recording","posthog_get_survey","posthog_list_actions","posthog_list_annotations","posthog_list_cohorts","posthog_list_dashboards","posthog_list_event_definitions","posthog_list_experiments","posthog_list_feature_flags","posthog_list_insights","posthog_list_organizations","posthog_list_persons","posthog_list_projects","posthog_list_property_definitions","posthog_list_recording_playlists","posthog_list_session_recordings","posthog_list_surveys","posthog_query","posthog_update_cohort","posthog_update_event_definition","posthog_update_experiment","posthog_update_feature_flag","posthog_update_insight","posthog_update_property_definition","posthog_update_survey","profound_bot_logs","profound_bots_report","profound_category_assets","profound_category_personas","profound_category_prompts","profound_category_tags","profound_category_topics","profound_citation_prompts","profound_citations_report","profound_list_assets","profound_list_categories","profound_list_domains","profound_list_models","profound_list_optimizations","profound_list_personas","profound_list_regions","profound_optimization_analysis","profound_prompt_answers","profound_prompt_volume","profound_query_fanouts","profound_raw_logs","profound_referrals_report","profound_sentiment_report","profound_visibility_report","prospeo_account_information","prospeo_bulk_enrich_company","prospeo_bulk_enrich_person","prospeo_enrich_company","prospeo_enrich_person","prospeo_search_company","prospeo_search_person","prospeo_search_suggestions","pulse_parser","pulse_parser_v2","qdrant_fetch_points","qdrant_search_vector","qdrant_upsert_points","quartr_get_audio","quartr_get_company","quartr_get_event","quartr_get_event_summary","quartr_get_report","quartr_get_slide_deck","quartr_get_transcript","quartr_list_audio","quartr_list_companies","quartr_list_document_types","quartr_list_documents","quartr_list_event_types","quartr_list_events","quartr_list_live_events","quartr_list_reports","quartr_list_slide_decks","quartr_list_transcripts","quiver_image_to_svg","quiver_list_models","quiver_text_to_svg","rabbitmq_create_binding","rabbitmq_create_exchange","rabbitmq_create_policy","rabbitmq_create_queue","rabbitmq_delete_binding","rabbitmq_delete_exchange","rabbitmq_delete_policy","rabbitmq_delete_queue","rabbitmq_get_exchange","rabbitmq_get_messages","rabbitmq_get_overview","rabbitmq_get_queue","rabbitmq_health_check","rabbitmq_list_bindings","rabbitmq_list_channels","rabbitmq_list_connections","rabbitmq_list_consumers","rabbitmq_list_exchange_bindings","rabbitmq_list_exchanges","rabbitmq_list_nodes","rabbitmq_list_policies","rabbitmq_list_queues","rabbitmq_list_vhosts","rabbitmq_publish_message","rabbitmq_purge_queue","railway_create_environment","railway_create_project","railway_create_service","railway_delete_environment","railway_delete_project","railway_delete_service","railway_delete_variable","railway_deploy_service","railway_get_deployment","railway_get_deployment_logs","railway_get_project","railway_list_deployments","railway_list_project_members","railway_list_projects","railway_list_variables","railway_restart_deployment","railway_rollback_deployment","railway_transfer_project","railway_update_project","railway_upsert_variable","rb2b_credit_check","rb2b_email_to_activity","rb2b_hem_to_best_linkedin","rb2b_hem_to_business_profile","rb2b_hem_to_linkedin","rb2b_hem_to_maid","rb2b_ip_to_company","rb2b_ip_to_hem","rb2b_ip_to_maid","rb2b_linkedin_slug_search","rb2b_linkedin_to_best_personal_email","rb2b_linkedin_to_business_profile","rb2b_linkedin_to_hashed_emails","rb2b_linkedin_to_mobile_phone","rb2b_linkedin_to_personal_email","rds_delete","rds_execute","rds_insert","rds_introspect","rds_query","rds_update","reddit_delete","reddit_edit","reddit_get_comments","reddit_get_controversial","reddit_get_info","reddit_get_me","reddit_get_messages","reddit_get_posts","reddit_get_saved","reddit_get_subreddit_info","reddit_get_subreddit_rules","reddit_get_user","reddit_get_user_comments","reddit_get_user_posts","reddit_hide","reddit_hot_posts","reddit_list_my_subreddits","reddit_lock","reddit_mark_all_read","reddit_mark_read","reddit_marknsfw","reddit_mod_approve","reddit_mod_distinguish","reddit_mod_remove","reddit_mod_sticky","reddit_reply","reddit_report","reddit_save","reddit_search","reddit_search_subreddits","reddit_send_message","reddit_submit_post","reddit_subscribe","reddit_unhide","reddit_unlock","reddit_unmarknsfw","reddit_unsave","reddit_vote","redis_command","redis_delete","redis_exists","redis_expire","redis_get","redis_hdel","redis_hget","redis_hgetall","redis_hset","redis_incr","redis_incrby","redis_keys","redis_llen","redis_lpop","redis_lpush","redis_lrange","redis_persist","redis_rpop","redis_rpush","redis_set","redis_setnx","redis_ttl","reducto_parser","reducto_parser_v2","resend_cancel_email","resend_create_audience","resend_create_broadcast","resend_create_contact","resend_delete_audience","resend_delete_contact","resend_get_audience","resend_get_broadcast","resend_get_contact","resend_get_email","resend_list_audiences","resend_list_contacts","resend_list_domains","resend_send","resend_send_broadcast","resend_update_contact","revenuecat_create_purchase","revenuecat_defer_google_subscription","revenuecat_delete_customer","revenuecat_get_customer","revenuecat_grant_entitlement","revenuecat_list_offerings","revenuecat_refund_google_subscription","revenuecat_revoke_entitlement","revenuecat_revoke_google_subscription","revenuecat_update_subscriber_attributes","rippling_bulk_create_custom_object_records","rippling_bulk_delete_custom_object_records","rippling_bulk_update_custom_object_records","rippling_create_business_partner","rippling_create_business_partner_group","rippling_create_custom_app","rippling_create_custom_object","rippling_create_custom_object_field","rippling_create_custom_object_record","rippling_create_custom_page","rippling_create_custom_setting","rippling_create_department","rippling_create_draft_hires","rippling_create_object_category","rippling_create_title","rippling_create_work_location","rippling_delete_business_partner","rippling_delete_business_partner_group","rippling_delete_custom_app","rippling_delete_custom_object","rippling_delete_custom_object_field","rippling_delete_custom_object_record","rippling_delete_custom_page","rippling_delete_custom_setting","rippling_delete_object_category","rippling_delete_title","rippling_delete_work_location","rippling_get_business_partner","rippling_get_business_partner_group","rippling_get_current_user","rippling_get_custom_app","rippling_get_custom_object","rippling_get_custom_object_field","rippling_get_custom_object_record","rippling_get_custom_object_record_by_external_id","rippling_get_custom_page","rippling_get_custom_setting","rippling_get_department","rippling_get_employment_type","rippling_get_job_function","rippling_get_object_category","rippling_get_report_run","rippling_get_supergroup","rippling_get_team","rippling_get_title","rippling_get_user","rippling_get_work_location","rippling_get_worker","rippling_list_business_partner_groups","rippling_list_business_partners","rippling_list_companies","rippling_list_custom_apps","rippling_list_custom_fields","rippling_list_custom_object_fields","rippling_list_custom_object_records","rippling_list_custom_objects","rippling_list_custom_pages","rippling_list_custom_settings","rippling_list_departments","rippling_list_employment_types","rippling_list_entitlements","rippling_list_job_functions","rippling_list_object_categories","rippling_list_supergroup_exclusion_members","rippling_list_supergroup_inclusion_members","rippling_list_supergroup_members","rippling_list_supergroups","rippling_list_teams","rippling_list_titles","rippling_list_users","rippling_list_work_locations","rippling_list_workers","rippling_query_custom_object_records","rippling_trigger_report_run","rippling_update_custom_app","rippling_update_custom_object","rippling_update_custom_object_field","rippling_update_custom_object_record","rippling_update_custom_page","rippling_update_custom_setting","rippling_update_department","rippling_update_object_category","rippling_update_supergroup_exclusion_members","rippling_update_supergroup_inclusion_members","rippling_update_title","rippling_update_work_location","rocketlane_add_field_option","rocketlane_add_project_members","rocketlane_add_task_assignees","rocketlane_add_task_dependencies","rocketlane_add_task_followers","rocketlane_archive_project","rocketlane_assign_placeholders","rocketlane_create_field","rocketlane_create_phase","rocketlane_create_project","rocketlane_create_space","rocketlane_create_space_document","rocketlane_create_task","rocketlane_create_time_entry","rocketlane_create_time_off","rocketlane_delete_field","rocketlane_delete_phase","rocketlane_delete_project","rocketlane_delete_space","rocketlane_delete_space_document","rocketlane_delete_task","rocketlane_delete_time_entry","rocketlane_delete_time_off","rocketlane_get_field","rocketlane_get_invoice","rocketlane_get_invoice_line_items","rocketlane_get_invoice_payments","rocketlane_get_phase","rocketlane_get_project","rocketlane_get_space","rocketlane_get_space_document","rocketlane_get_task","rocketlane_get_time_entry","rocketlane_get_time_off","rocketlane_get_user","rocketlane_import_template","rocketlane_list_fields","rocketlane_list_invoices","rocketlane_list_phases","rocketlane_list_placeholders","rocketlane_list_projects","rocketlane_list_resource_allocations","rocketlane_list_space_documents","rocketlane_list_spaces","rocketlane_list_tasks","rocketlane_list_time_entries","rocketlane_list_time_entry_categories","rocketlane_list_time_offs","rocketlane_list_users","rocketlane_move_task_to_phase","rocketlane_remove_project_members","rocketlane_remove_task_assignees","rocketlane_remove_task_dependencies","rocketlane_remove_task_followers","rocketlane_search_time_entries","rocketlane_unassign_placeholders","rocketlane_update_field","rocketlane_update_field_option","rocketlane_update_phase","rocketlane_update_project","rocketlane_update_space","rocketlane_update_space_document","rocketlane_update_task","rocketlane_update_time_entry","rootly_acknowledge_alert","rootly_add_incident_event","rootly_add_subscribers","rootly_assign_incident_role","rootly_create_action_item","rootly_create_alert","rootly_create_incident","rootly_create_status_page_event","rootly_delete_action_item","rootly_delete_incident","rootly_escalate_alert","rootly_get_alert","rootly_get_incident","rootly_list_action_items","rootly_list_alerts","rootly_list_causes","rootly_list_environments","rootly_list_escalation_policies","rootly_list_functionalities","rootly_list_incident_events","rootly_list_incident_roles","rootly_list_incident_types","rootly_list_incidents","rootly_list_on_calls","rootly_list_playbooks","rootly_list_retrospectives","rootly_list_schedules","rootly_list_services","rootly_list_severities","rootly_list_teams","rootly_list_users","rootly_mitigate_incident","rootly_remove_subscribers","rootly_resolve_alert","rootly_resolve_incident","rootly_run_workflow","rootly_snooze_alert","rootly_unassign_incident_role","rootly_update_action_item","rootly_update_alert","rootly_update_incident","s3_copy_object","s3_create_bucket","s3_delete_bucket","s3_delete_object","s3_delete_objects","s3_get_object","s3_head_object","s3_list_buckets","s3_list_objects","s3_presigned_url","s3_put_object","salesforce_create_account","salesforce_create_case","salesforce_create_contact","salesforce_create_custom_field","salesforce_create_custom_object","salesforce_create_lead","salesforce_create_opportunity","salesforce_create_task","salesforce_delete_account","salesforce_delete_case","salesforce_delete_contact","salesforce_delete_custom_field","salesforce_delete_lead","salesforce_delete_opportunity","salesforce_delete_task","salesforce_describe_object","salesforce_get_accounts","salesforce_get_cases","salesforce_get_contacts","salesforce_get_dashboard","salesforce_get_leads","salesforce_get_opportunities","salesforce_get_report","salesforce_get_tasks","salesforce_list_dashboards","salesforce_list_objects","salesforce_list_report_types","salesforce_list_reports","salesforce_query","salesforce_query_more","salesforce_refresh_dashboard","salesforce_run_report","salesforce_tooling_query","salesforce_update_account","salesforce_update_case","salesforce_update_contact","salesforce_update_custom_field","salesforce_update_lead","salesforce_update_opportunity","salesforce_update_task","sap_concur_approve_expense_report","sap_concur_associate_attendees","sap_concur_create_cash_advance","sap_concur_create_expected_expense","sap_concur_create_expense_report","sap_concur_create_list_item","sap_concur_create_purchase_request","sap_concur_create_quick_expense","sap_concur_create_quick_expense_with_image","sap_concur_create_report_comment","sap_concur_create_travel_request","sap_concur_create_user","sap_concur_delete_expected_expense","sap_concur_delete_expense","sap_concur_delete_expense_report","sap_concur_delete_list_item","sap_concur_delete_travel_request","sap_concur_delete_user","sap_concur_get_allocation","sap_concur_get_budget","sap_concur_get_cash_advance","sap_concur_get_expected_expense","sap_concur_get_expense","sap_concur_get_expense_report","sap_concur_get_itemizations","sap_concur_get_itinerary","sap_concur_get_list","sap_concur_get_list_item","sap_concur_get_purchase_request","sap_concur_get_receipt","sap_concur_get_receipt_status","sap_concur_get_request_cash_advance","sap_concur_get_travel_profile","sap_concur_get_travel_request","sap_concur_get_user","sap_concur_issue_cash_advance","sap_concur_list_allocations","sap_concur_list_attendee_associations","sap_concur_list_budget_categories","sap_concur_list_budgets","sap_concur_list_exceptions","sap_concur_list_expected_expenses","sap_concur_list_expense_reports","sap_concur_list_expenses","sap_concur_list_itineraries","sap_concur_list_list_items","sap_concur_list_lists","sap_concur_list_receipts","sap_concur_list_report_comments","sap_concur_list_reports_to_approve","sap_concur_list_travel_profiles_summary","sap_concur_list_travel_request_comments","sap_concur_list_travel_requests","sap_concur_list_users","sap_concur_move_travel_request","sap_concur_recall_expense_report","sap_concur_remove_all_attendees","sap_concur_search_locations","sap_concur_search_users","sap_concur_send_back_expense_report","sap_concur_submit_expense_report","sap_concur_update_allocation","sap_concur_update_expected_expense","sap_concur_update_expense","sap_concur_update_expense_report","sap_concur_update_list_item","sap_concur_update_travel_request","sap_concur_update_user","sap_concur_upload_exchange_rates","sap_concur_upload_receipt_image","sap_s4hana_create_business_partner","sap_s4hana_create_purchase_order","sap_s4hana_create_purchase_requisition","sap_s4hana_create_sales_order","sap_s4hana_delete_sales_order","sap_s4hana_get_billing_document","sap_s4hana_get_business_partner","sap_s4hana_get_customer","sap_s4hana_get_inbound_delivery","sap_s4hana_get_material_document","sap_s4hana_get_outbound_delivery","sap_s4hana_get_product","sap_s4hana_get_purchase_order","sap_s4hana_get_purchase_requisition","sap_s4hana_get_sales_order","sap_s4hana_get_supplier","sap_s4hana_get_supplier_invoice","sap_s4hana_list_billing_documents","sap_s4hana_list_business_partners","sap_s4hana_list_customers","sap_s4hana_list_inbound_deliveries","sap_s4hana_list_material_documents","sap_s4hana_list_material_stock","sap_s4hana_list_outbound_deliveries","sap_s4hana_list_products","sap_s4hana_list_purchase_orders","sap_s4hana_list_purchase_requisitions","sap_s4hana_list_sales_orders","sap_s4hana_list_supplier_invoices","sap_s4hana_list_suppliers","sap_s4hana_odata_query","sap_s4hana_update_business_partner","sap_s4hana_update_customer","sap_s4hana_update_product","sap_s4hana_update_purchase_order","sap_s4hana_update_purchase_requisition","sap_s4hana_update_sales_order","sap_s4hana_update_supplier","search_tool","secrets_manager_create_secret","secrets_manager_delete_secret","secrets_manager_describe_secret","secrets_manager_get_secret","secrets_manager_list_secrets","secrets_manager_restore_secret","secrets_manager_rotate_secret","secrets_manager_tag_resource","secrets_manager_untag_resource","secrets_manager_update_secret","sendblue_evaluate_service","sendblue_get_message","sendblue_send_group_message","sendblue_send_message","sendblue_send_typing_indicator","sendgrid_add_contact","sendgrid_add_contacts_to_list","sendgrid_create_list","sendgrid_create_template","sendgrid_create_template_version","sendgrid_delete_contacts","sendgrid_delete_list","sendgrid_delete_template","sendgrid_get_contact","sendgrid_get_list","sendgrid_get_template","sendgrid_list_all_lists","sendgrid_list_templates","sendgrid_remove_contacts_from_list","sendgrid_search_contacts","sendgrid_send_mail","sentry_events_get","sentry_events_list","sentry_issues_get","sentry_issues_list","sentry_issues_update","sentry_projects_create","sentry_projects_get","sentry_projects_list","sentry_projects_update","sentry_releases_create","sentry_releases_deploy","sentry_releases_list","sentry_teams_list","serper_search","servicenow_aggregate","servicenow_create_record","servicenow_delete_record","servicenow_download_attachment","servicenow_list_attachments","servicenow_read_record","servicenow_update_record","servicenow_upload_attachment","ses_create_configuration_set","ses_create_email_identity","ses_create_template","ses_delete_email_identity","ses_delete_suppressed_destination","ses_delete_template","ses_get_account","ses_get_email_identity","ses_get_suppressed_destination","ses_get_template","ses_list_identities","ses_list_suppressed_destinations","ses_list_templates","ses_put_suppressed_destination","ses_send_bulk_email","ses_send_custom_verification_email","ses_send_email","ses_send_templated_email","ses_update_template","sftp_delete","sftp_download","sftp_list","sftp_mkdir","sftp_upload","sharepoint_add_list_items","sharepoint_create_list","sharepoint_create_page","sharepoint_delete_file","sharepoint_delete_list_item","sharepoint_delete_page","sharepoint_download_file","sharepoint_get_drive_item","sharepoint_get_list","sharepoint_get_list_item","sharepoint_list_sites","sharepoint_publish_page","sharepoint_read_page","sharepoint_update_list","sharepoint_update_page","sharepoint_upload_file","shopify_adjust_inventory","shopify_cancel_order","shopify_create_customer","shopify_create_fulfillment","shopify_create_product","shopify_delete_customer","shopify_delete_product","shopify_get_collection","shopify_get_customer","shopify_get_inventory_level","shopify_get_order","shopify_get_product","shopify_list_collections","shopify_list_customers","shopify_list_inventory_items","shopify_list_locations","shopify_list_orders","shopify_list_products","shopify_update_customer","shopify_update_order","shopify_update_product","similarweb_bounce_rate","similarweb_page_views","similarweb_pages_per_visit","similarweb_traffic_visits","similarweb_visit_duration","similarweb_website_overview","sixtyfour_enrich_company","sixtyfour_enrich_lead","sixtyfour_find_email","sixtyfour_find_phone","slack_add_reaction","slack_archive_conversation","slack_canvas","slack_create_channel_canvas","slack_create_conversation","slack_delete_canvas","slack_delete_message","slack_delete_scheduled_message","slack_download","slack_edit_canvas","slack_ephemeral_message","slack_get_canvas","slack_get_channel_history","slack_get_channel_info","slack_get_message","slack_get_permalink","slack_get_thread","slack_get_thread_replies","slack_get_user","slack_get_user_presence","slack_invite_to_conversation","slack_list_canvases","slack_list_channels","slack_list_members","slack_list_scheduled_messages","slack_list_users","slack_lookup_canvas_sections","slack_message","slack_message_reader","slack_open_view","slack_publish_view","slack_push_view","slack_remove_reaction","slack_rename_conversation","slack_schedule_message","slack_set_conversation_purpose","slack_set_conversation_topic","slack_set_status","slack_set_suggested_prompts","slack_set_title","slack_update_message","slack_update_view","smartlead_add_email_accounts_to_campaign","smartlead_add_leads_to_campaign","smartlead_create_campaign","smartlead_create_lead_list","smartlead_delete_campaign","smartlead_delete_campaign_webhook","smartlead_delete_lead_from_campaign","smartlead_delete_lead_list","smartlead_duplicate_campaign","smartlead_export_campaign_leads","smartlead_get_campaign","smartlead_get_campaign_analytics","smartlead_get_campaign_analytics_by_date","smartlead_get_campaign_lead_statistics","smartlead_get_campaign_mailbox_statistics","smartlead_get_campaign_sequences","smartlead_get_campaign_statistics","smartlead_get_campaign_top_level_analytics_by_date","smartlead_get_campaign_webhook_summary","smartlead_get_lead_by_email","smartlead_get_lead_by_id","smartlead_get_lead_list","smartlead_get_lead_message_history","smartlead_list_campaign_email_accounts","smartlead_list_campaign_leads","smartlead_list_campaign_webhooks","smartlead_list_campaigns","smartlead_list_clients","smartlead_list_email_accounts","smartlead_list_inbox_replies","smartlead_list_lead_activities","smartlead_list_lead_categories","smartlead_list_lead_lists","smartlead_mark_lead_complete","smartlead_pause_lead","smartlead_remove_email_accounts_from_campaign","smartlead_resume_lead","smartlead_save_campaign_sequences","smartlead_unsubscribe_lead_from_campaign","smartlead_unsubscribe_lead_globally","smartlead_update_campaign_schedule","smartlead_update_campaign_settings","smartlead_update_campaign_status","smartlead_update_lead","smartlead_update_lead_category","smartlead_update_lead_list","smartlead_upsert_campaign_webhook","sms_send","smtp_send_mail","snowflake_alter_warehouse","snowflake_call_procedure","snowflake_cancel_statement","snowflake_cancel_task_run","snowflake_delete_rows","snowflake_execute_sql","snowflake_get_statement","snowflake_get_task","snowflake_get_task_run","snowflake_get_task_run_output","snowflake_get_warehouse","snowflake_insert_rows","snowflake_introspect_schema","snowflake_list_copy_history","snowflake_list_databases","snowflake_list_query_history","snowflake_list_schemas","snowflake_list_tables","snowflake_list_task_runs","snowflake_list_tasks","snowflake_list_warehouses","snowflake_load_data","snowflake_resume_task","snowflake_resume_warehouse","snowflake_run_task","snowflake_suspend_task","snowflake_suspend_warehouse","snowflake_unload_data","snowflake_update_rows","snowflake_upsert_rows","splunk_cancel_search_job","splunk_create_search_job","splunk_dispatch_saved_search","splunk_get_fired_alerts","splunk_get_saved_search","splunk_get_search_job","splunk_get_search_results","splunk_list_apps","splunk_list_fired_alerts","splunk_list_indexes","splunk_list_saved_searches","splunk_run_search","sportmonks_core_get_cities","sportmonks_core_get_city","sportmonks_core_get_continent","sportmonks_core_get_continents","sportmonks_core_get_countries","sportmonks_core_get_country","sportmonks_core_get_entity_filters","sportmonks_core_get_my_usage","sportmonks_core_get_region","sportmonks_core_get_regions","sportmonks_core_get_timezones","sportmonks_core_get_type","sportmonks_core_get_type_by_entity","sportmonks_core_get_types","sportmonks_core_search_cities","sportmonks_core_search_countries","sportmonks_core_search_regions","sportmonks_football_expected_by_player","sportmonks_football_expected_by_team","sportmonks_football_get_all_commentaries","sportmonks_football_get_all_fixtures","sportmonks_football_get_all_players","sportmonks_football_get_all_rivals","sportmonks_football_get_all_teams","sportmonks_football_get_all_transfer_rumours","sportmonks_football_get_all_transfers","sportmonks_football_get_brackets_by_season","sportmonks_football_get_coach","sportmonks_football_get_coaches","sportmonks_football_get_coaches_by_country","sportmonks_football_get_commentaries_by_fixture","sportmonks_football_get_current_leagues_by_team","sportmonks_football_get_expected_lineups_by_player","sportmonks_football_get_expected_lineups_by_team","sportmonks_football_get_extended_team_squad","sportmonks_football_get_fixture","sportmonks_football_get_fixtures_by_date","sportmonks_football_get_fixtures_by_date_range","sportmonks_football_get_fixtures_by_date_range_for_team","sportmonks_football_get_fixtures_by_ids","sportmonks_football_get_grouped_standings_by_round","sportmonks_football_get_head_to_head","sportmonks_football_get_inplay_livescores","sportmonks_football_get_latest_coaches","sportmonks_football_get_latest_fixtures","sportmonks_football_get_latest_livescores","sportmonks_football_get_latest_players","sportmonks_football_get_latest_totw","sportmonks_football_get_latest_transfers","sportmonks_football_get_league","sportmonks_football_get_leagues","sportmonks_football_get_leagues_by_country","sportmonks_football_get_leagues_by_date","sportmonks_football_get_leagues_by_team","sportmonks_football_get_live_leagues","sportmonks_football_get_live_probabilities","sportmonks_football_get_live_probabilities_by_fixture","sportmonks_football_get_live_standings_by_league","sportmonks_football_get_livescores","sportmonks_football_get_match_facts","sportmonks_football_get_match_facts_by_date_range","sportmonks_football_get_match_facts_by_fixture","sportmonks_football_get_match_facts_by_league","sportmonks_football_get_past_fixtures_by_tv_station","sportmonks_football_get_player","sportmonks_football_get_players_by_country","sportmonks_football_get_postmatch_news","sportmonks_football_get_postmatch_news_by_season","sportmonks_football_get_predictability_by_league","sportmonks_football_get_prematch_news","sportmonks_football_get_prematch_news_by_season","sportmonks_football_get_prematch_news_upcoming","sportmonks_football_get_probabilities","sportmonks_football_get_probabilities_by_fixture","sportmonks_football_get_referee","sportmonks_football_get_referees","sportmonks_football_get_referees_by_country","sportmonks_football_get_referees_by_season","sportmonks_football_get_rivals_by_team","sportmonks_football_get_round","sportmonks_football_get_round_statistics","sportmonks_football_get_rounds","sportmonks_football_get_rounds_by_season","sportmonks_football_get_schedules_by_season","sportmonks_football_get_schedules_by_season_and_team","sportmonks_football_get_schedules_by_team","sportmonks_football_get_season","sportmonks_football_get_seasons","sportmonks_football_get_seasons_by_team","sportmonks_football_get_stage","sportmonks_football_get_stage_statistics","sportmonks_football_get_stages","sportmonks_football_get_stages_by_season","sportmonks_football_get_standing_corrections_by_season","sportmonks_football_get_standings","sportmonks_football_get_standings_by_round","sportmonks_football_get_standings_by_season","sportmonks_football_get_state","sportmonks_football_get_states","sportmonks_football_get_team","sportmonks_football_get_team_rankings","sportmonks_football_get_team_rankings_by_date","sportmonks_football_get_team_rankings_by_team","sportmonks_football_get_team_squad","sportmonks_football_get_team_squad_by_season","sportmonks_football_get_teams_by_country","sportmonks_football_get_teams_by_season","sportmonks_football_get_topscorers_by_season","sportmonks_football_get_topscorers_by_stage","sportmonks_football_get_totw","sportmonks_football_get_totw_by_round","sportmonks_football_get_transfer","sportmonks_football_get_transfer_rumour","sportmonks_football_get_transfer_rumours_between_dates","sportmonks_football_get_transfer_rumours_by_player","sportmonks_football_get_transfer_rumours_by_team","sportmonks_football_get_transfers_between_dates","sportmonks_football_get_transfers_by_player","sportmonks_football_get_transfers_by_team","sportmonks_football_get_tv_station","sportmonks_football_get_tv_stations","sportmonks_football_get_tv_stations_by_fixture","sportmonks_football_get_upcoming_fixtures_by_market","sportmonks_football_get_upcoming_fixtures_by_tv_station","sportmonks_football_get_value_bets","sportmonks_football_get_value_bets_by_fixture","sportmonks_football_get_venue","sportmonks_football_get_venues","sportmonks_football_get_venues_by_season","sportmonks_football_search_coaches","sportmonks_football_search_fixtures","sportmonks_football_search_leagues","sportmonks_football_search_players","sportmonks_football_search_referees","sportmonks_football_search_rounds","sportmonks_football_search_seasons","sportmonks_football_search_stages","sportmonks_football_search_teams","sportmonks_football_search_venues","sportmonks_motorsport_get_all_fixtures","sportmonks_motorsport_get_current_leagues_by_team","sportmonks_motorsport_get_driver","sportmonks_motorsport_get_driver_standings","sportmonks_motorsport_get_driver_standings_by_season","sportmonks_motorsport_get_drivers","sportmonks_motorsport_get_drivers_by_country","sportmonks_motorsport_get_drivers_by_season","sportmonks_motorsport_get_fixture","sportmonks_motorsport_get_fixtures_by_date","sportmonks_motorsport_get_fixtures_by_date_range","sportmonks_motorsport_get_fixtures_by_ids","sportmonks_motorsport_get_laps_by_fixture","sportmonks_motorsport_get_laps_by_fixture_and_driver","sportmonks_motorsport_get_laps_by_fixture_and_lap","sportmonks_motorsport_get_latest_laps_by_fixture","sportmonks_motorsport_get_latest_pitstops_by_fixture","sportmonks_motorsport_get_latest_stints_by_fixture","sportmonks_motorsport_get_latest_updated_drivers","sportmonks_motorsport_get_latest_updated_fixtures","sportmonks_motorsport_get_league","sportmonks_motorsport_get_leagues","sportmonks_motorsport_get_leagues_by_country","sportmonks_motorsport_get_leagues_by_date","sportmonks_motorsport_get_leagues_by_live","sportmonks_motorsport_get_leagues_by_team","sportmonks_motorsport_get_livescores","sportmonks_motorsport_get_pitstops_by_fixture","sportmonks_motorsport_get_pitstops_by_fixture_and_driver","sportmonks_motorsport_get_pitstops_by_fixture_and_lap","sportmonks_motorsport_get_race_results_by_season_and_driver","sportmonks_motorsport_get_race_results_by_season_and_team","sportmonks_motorsport_get_schedules_by_season","sportmonks_motorsport_get_season","sportmonks_motorsport_get_seasons","sportmonks_motorsport_get_stage","sportmonks_motorsport_get_stages","sportmonks_motorsport_get_stages_by_season","sportmonks_motorsport_get_state","sportmonks_motorsport_get_states","sportmonks_motorsport_get_stints_by_fixture","sportmonks_motorsport_get_stints_by_fixture_and_driver","sportmonks_motorsport_get_stints_by_fixture_and_stint","sportmonks_motorsport_get_team","sportmonks_motorsport_get_team_standings","sportmonks_motorsport_get_team_standings_by_season","sportmonks_motorsport_get_teams","sportmonks_motorsport_get_teams_by_country","sportmonks_motorsport_get_teams_by_season","sportmonks_motorsport_get_venue","sportmonks_motorsport_get_venues","sportmonks_motorsport_get_venues_by_season","sportmonks_motorsport_search_drivers","sportmonks_motorsport_search_leagues","sportmonks_motorsport_search_stages","sportmonks_motorsport_search_teams","sportmonks_motorsport_search_venues","sportmonks_odds_get_all_historical_odds","sportmonks_odds_get_all_inplay_odds","sportmonks_odds_get_all_pre_match_odds","sportmonks_odds_get_all_premium_odds","sportmonks_odds_get_bookmaker","sportmonks_odds_get_bookmaker_event_ids_by_fixture","sportmonks_odds_get_bookmakers","sportmonks_odds_get_bookmakers_by_fixture","sportmonks_odds_get_inplay_odds_by_fixture","sportmonks_odds_get_inplay_odds_by_fixture_and_bookmaker","sportmonks_odds_get_inplay_odds_by_fixture_and_market","sportmonks_odds_get_last_updated_inplay_odds","sportmonks_odds_get_last_updated_pre_match_odds","sportmonks_odds_get_market","sportmonks_odds_get_markets","sportmonks_odds_get_pre_match_odds_by_fixture","sportmonks_odds_get_pre_match_odds_by_fixture_and_bookmaker","sportmonks_odds_get_pre_match_odds_by_fixture_and_market","sportmonks_odds_get_premium_odds_by_fixture","sportmonks_odds_get_premium_odds_by_fixture_and_bookmaker","sportmonks_odds_get_premium_odds_by_fixture_and_market","sportmonks_odds_get_updated_historical_odds_between","sportmonks_odds_get_updated_premium_odds_between","sportmonks_odds_search_bookmakers","sportmonks_odds_search_markets","spotify_add_playlist_cover","spotify_add_to_queue","spotify_add_tracks_to_playlist","spotify_check_following","spotify_check_playlist_followers","spotify_check_saved_albums","spotify_check_saved_audiobooks","spotify_check_saved_episodes","spotify_check_saved_shows","spotify_check_saved_tracks","spotify_create_playlist","spotify_follow_artists","spotify_follow_playlist","spotify_get_album","spotify_get_album_tracks","spotify_get_albums","spotify_get_artist","spotify_get_artist_albums","spotify_get_artist_top_tracks","spotify_get_artists","spotify_get_audiobook","spotify_get_audiobook_chapters","spotify_get_audiobooks","spotify_get_categories","spotify_get_current_user","spotify_get_currently_playing","spotify_get_devices","spotify_get_episode","spotify_get_episodes","spotify_get_followed_artists","spotify_get_markets","spotify_get_new_releases","spotify_get_playback_state","spotify_get_playlist","spotify_get_playlist_cover","spotify_get_playlist_tracks","spotify_get_queue","spotify_get_recently_played","spotify_get_saved_albums","spotify_get_saved_audiobooks","spotify_get_saved_episodes","spotify_get_saved_shows","spotify_get_saved_tracks","spotify_get_show","spotify_get_show_episodes","spotify_get_shows","spotify_get_top_artists","spotify_get_top_tracks","spotify_get_track","spotify_get_tracks","spotify_get_user_playlists","spotify_get_user_profile","spotify_pause","spotify_play","spotify_remove_saved_albums","spotify_remove_saved_audiobooks","spotify_remove_saved_episodes","spotify_remove_saved_shows","spotify_remove_saved_tracks","spotify_remove_tracks_from_playlist","spotify_reorder_playlist_items","spotify_replace_playlist_items","spotify_save_albums","spotify_save_audiobooks","spotify_save_episodes","spotify_save_shows","spotify_save_tracks","spotify_search","spotify_seek","spotify_set_repeat","spotify_set_shuffle","spotify_set_volume","spotify_skip_next","spotify_skip_previous","spotify_transfer_playback","spotify_unfollow_artists","spotify_unfollow_playlist","spotify_update_playlist","sqs_send","square_batch_retrieve_inventory_counts","square_cancel_invoice","square_cancel_payment","square_complete_payment","square_create_catalog_image","square_create_customer","square_create_invoice","square_create_order","square_create_payment","square_delete_catalog_object","square_delete_customer","square_delete_invoice","square_get_catalog_object","square_get_customer","square_get_invoice","square_get_location","square_get_order","square_get_payment","square_get_refund","square_list_catalog","square_list_customers","square_list_invoices","square_list_locations","square_list_payments","square_list_refunds","square_pay_order","square_publish_invoice","square_refund_payment","square_search_catalog_objects","square_search_customers","square_search_invoices","square_search_orders","square_update_customer","square_upsert_catalog_object","ssh_check_command_exists","ssh_check_file_exists","ssh_create_directory","ssh_delete_file","ssh_download_file","ssh_execute_command","ssh_execute_script","ssh_get_system_info","ssh_list_directory","ssh_move_rename","ssh_read_file_content","ssh_upload_file","ssh_write_file_content","stagehand_agent","stagehand_extract","stripe_cancel_payment_intent","stripe_cancel_subscription","stripe_capture_charge","stripe_capture_payment_intent","stripe_confirm_payment_intent","stripe_create_charge","stripe_create_customer","stripe_create_invoice","stripe_create_payment_intent","stripe_create_price","stripe_create_product","stripe_create_subscription","stripe_delete_customer","stripe_delete_invoice","stripe_delete_product","stripe_finalize_invoice","stripe_list_charges","stripe_list_customers","stripe_list_events","stripe_list_invoices","stripe_list_payment_intents","stripe_list_prices","stripe_list_products","stripe_list_subscriptions","stripe_pay_invoice","stripe_resume_subscription","stripe_retrieve_charge","stripe_retrieve_customer","stripe_retrieve_event","stripe_retrieve_invoice","stripe_retrieve_payment_intent","stripe_retrieve_price","stripe_retrieve_product","stripe_retrieve_subscription","stripe_search_charges","stripe_search_customers","stripe_search_invoices","stripe_search_payment_intents","stripe_search_prices","stripe_search_products","stripe_search_subscriptions","stripe_send_invoice","stripe_update_charge","stripe_update_customer","stripe_update_invoice","stripe_update_payment_intent","stripe_update_price","stripe_update_product","stripe_update_subscription","stripe_void_invoice","sts_assume_role","sts_assume_role_with_saml","sts_assume_role_with_web_identity","sts_get_access_key_info","sts_get_caller_identity","sts_get_session_token","stt_assemblyai","stt_assemblyai_v2","stt_deepgram","stt_deepgram_v2","stt_elevenlabs","stt_elevenlabs_v2","stt_gemini","stt_gemini_v2","stt_whisper","stt_whisper_v2","supabase_count","supabase_delete","supabase_get_row","supabase_insert","supabase_introspect","supabase_invoke_function","supabase_query","supabase_rpc","supabase_storage_copy","supabase_storage_create_bucket","supabase_storage_create_signed_upload_url","supabase_storage_create_signed_url","supabase_storage_delete","supabase_storage_delete_bucket","supabase_storage_download","supabase_storage_empty_bucket","supabase_storage_get_public_url","supabase_storage_list","supabase_storage_list_buckets","supabase_storage_move","supabase_storage_update_bucket","supabase_storage_upload","supabase_text_search","supabase_update","supabase_upsert","supabase_vector_search","table_batch_insert_rows","table_create","table_delete_row","table_delete_rows_by_filter","table_get_row","table_get_schema","table_insert_row","table_list","table_query_rows","table_query_rows_v2","table_update_row","table_update_rows_by_filter","table_upsert_row","tailscale_authorize_device","tailscale_create_auth_key","tailscale_delete_auth_key","tailscale_delete_device","tailscale_delete_user","tailscale_expire_device_key","tailscale_get_acl","tailscale_get_auth_key","tailscale_get_device","tailscale_get_device_routes","tailscale_get_dns_preferences","tailscale_get_dns_searchpaths","tailscale_list_auth_keys","tailscale_list_devices","tailscale_list_dns_nameservers","tailscale_list_users","tailscale_set_acl","tailscale_set_device_routes","tailscale_set_device_tags","tailscale_set_dns_nameservers","tailscale_set_dns_preferences","tailscale_set_dns_searchpaths","tailscale_suspend_user","tailscale_update_device_key","tavily_crawl","tavily_extract","tavily_map","tavily_search","telegram_copy_message","telegram_delete_message","telegram_edit_message_text","telegram_forward_message","telegram_get_chat","telegram_get_chat_member","telegram_message","telegram_pin_message","telegram_send_animation","telegram_send_audio","telegram_send_chat_action","telegram_send_contact","telegram_send_document","telegram_send_location","telegram_send_photo","telegram_send_poll","telegram_send_video","telegram_set_message_reaction","telegram_unpin_message","temporal_cancel_workflow","temporal_count_workflows","temporal_create_schedule","temporal_delete_schedule","temporal_describe_schedule","temporal_describe_task_queue","temporal_describe_workflow","temporal_get_workflow_history","temporal_list_schedules","temporal_list_workflows","temporal_pause_schedule","temporal_query_workflow","temporal_reset_workflow","temporal_signal_with_start","temporal_signal_workflow","temporal_start_workflow","temporal_terminate_workflow","temporal_trigger_schedule","temporal_unpause_schedule","temporal_update_workflow","textract_analyze_expense","textract_analyze_id","textract_parser","textract_parser_v2","thinking_tool","thrive_add_audience_managers","thrive_add_audience_members","thrive_add_user_tags","thrive_create_assignment","thrive_create_audience","thrive_create_completion","thrive_create_user","thrive_delete_assignment","thrive_delete_audience","thrive_delete_user","thrive_get_activity","thrive_get_assignment","thrive_get_audience","thrive_get_completion","thrive_get_content","thrive_get_cpd_category","thrive_get_cpd_entry","thrive_get_cpd_requirement","thrive_get_enrolment","thrive_get_skill_levels","thrive_get_tag","thrive_get_user_by_id","thrive_get_user_by_ref","thrive_list_assignments","thrive_list_audience_managers","thrive_list_audience_members","thrive_list_audiences","thrive_list_completions","thrive_list_enrolments","thrive_list_tags","thrive_query_activities","thrive_query_content","thrive_query_cpd_categories","thrive_query_cpd_entries","thrive_query_cpd_requirements","thrive_query_cpd_user_summaries","thrive_remove_audience_manager","thrive_remove_audience_member","thrive_remove_user_tags","thrive_replace_audience_managers","thrive_replace_audience_members","thrive_search_users","thrive_suspend_user","thrive_update_assignment","thrive_update_audience","thrive_update_user","thrive_update_user_skills","tiktok_get_post_status","tiktok_get_user","tiktok_list_videos","tiktok_query_videos","tiktok_upload_video_draft","tinybird_append_datasource","tinybird_delete_datasource_rows","tinybird_events","tinybird_get_job","tinybird_query","tinybird_query_pipe","tinybird_truncate_datasource","trello_add_checklist","trello_add_checklist_item","trello_add_comment","trello_add_label","trello_add_member","trello_create_board","trello_create_card","trello_create_list","trello_delete_card","trello_get_actions","trello_get_board","trello_get_card","trello_list_cards","trello_list_lists","trello_list_members","trello_remove_label","trello_remove_member","trello_search","trello_update_card","trello_update_checklist_item","trello_update_list","trigger_dev_activate_schedule","trigger_dev_add_run_tags","trigger_dev_batch_trigger_task","trigger_dev_cancel_run","trigger_dev_complete_waitpoint_token","trigger_dev_create_env_var","trigger_dev_create_schedule","trigger_dev_create_waitpoint_token","trigger_dev_deactivate_schedule","trigger_dev_delete_env_var","trigger_dev_delete_schedule","trigger_dev_execute_query","trigger_dev_get_batch","trigger_dev_get_batch_results","trigger_dev_get_deployment","trigger_dev_get_env_var","trigger_dev_get_latest_deployment","trigger_dev_get_query_schema","trigger_dev_get_queue","trigger_dev_get_run","trigger_dev_get_run_events","trigger_dev_get_run_result","trigger_dev_get_run_trace","trigger_dev_get_schedule","trigger_dev_get_waitpoint_token","trigger_dev_import_env_vars","trigger_dev_list_deployments","trigger_dev_list_env_vars","trigger_dev_list_queues","trigger_dev_list_runs","trigger_dev_list_schedules","trigger_dev_list_timezones","trigger_dev_list_waitpoint_tokens","trigger_dev_override_queue_concurrency","trigger_dev_pause_queue","trigger_dev_promote_deployment","trigger_dev_replay_run","trigger_dev_reschedule_run","trigger_dev_reset_queue_concurrency","trigger_dev_resume_queue","trigger_dev_trigger_task","trigger_dev_update_env_var","trigger_dev_update_run_metadata","trigger_dev_update_schedule","tts_azure","tts_cartesia","tts_deepgram","tts_elevenlabs","tts_google","tts_openai","tts_playht","twilio_send_sms","twilio_voice_get_recording","twilio_voice_list_calls","twilio_voice_make_call","typeform_create_form","typeform_delete_form","typeform_files","typeform_get_form","typeform_insights","typeform_list_forms","typeform_responses","typeform_update_form","upstash_redis_command","upstash_redis_delete","upstash_redis_exists","upstash_redis_expire","upstash_redis_get","upstash_redis_hget","upstash_redis_hgetall","upstash_redis_hset","upstash_redis_incr","upstash_redis_incrby","upstash_redis_keys","upstash_redis_lpush","upstash_redis_lrange","upstash_redis_set","upstash_redis_setnx","upstash_redis_ttl","uptimerobot_create_alert_contact","uptimerobot_create_maintenance_window","uptimerobot_create_monitor","uptimerobot_create_psp","uptimerobot_delete_alert_contact","uptimerobot_delete_maintenance_window","uptimerobot_delete_monitor","uptimerobot_delete_psp","uptimerobot_get_account","uptimerobot_get_alert_contact","uptimerobot_get_incident","uptimerobot_get_maintenance_window","uptimerobot_get_monitor","uptimerobot_get_psp","uptimerobot_list_alert_contacts","uptimerobot_list_incidents","uptimerobot_list_maintenance_windows","uptimerobot_list_monitors","uptimerobot_list_psps","uptimerobot_pause_monitor","uptimerobot_start_monitor","uptimerobot_update_maintenance_window","uptimerobot_update_monitor","uptimerobot_update_psp","vanta_download_document_file","vanta_get_control","vanta_get_document","vanta_get_framework","vanta_get_person","vanta_get_policy","vanta_get_risk_scenario","vanta_get_test","vanta_get_vendor","vanta_get_vulnerable_asset","vanta_list_control_documents","vanta_list_control_tests","vanta_list_controls","vanta_list_document_uploads","vanta_list_documents","vanta_list_framework_controls","vanta_list_frameworks","vanta_list_monitored_computers","vanta_list_people","vanta_list_policies","vanta_list_risk_scenarios","vanta_list_test_entities","vanta_list_tests","vanta_list_vendors","vanta_list_vulnerabilities","vanta_list_vulnerability_remediations","vanta_list_vulnerable_assets","vanta_submit_document","vanta_upload_document_file","vercel_add_domain","vercel_add_project_domain","vercel_cancel_deployment","vercel_create_alias","vercel_create_check","vercel_create_deployment","vercel_create_dns_record","vercel_create_edge_config","vercel_create_env_var","vercel_create_project","vercel_create_webhook","vercel_delete_alias","vercel_delete_deployment","vercel_delete_dns_record","vercel_delete_domain","vercel_delete_edge_config","vercel_delete_env_var","vercel_delete_project","vercel_delete_webhook","vercel_get_alias","vercel_get_check","vercel_get_deployment","vercel_get_deployment_events","vercel_get_domain","vercel_get_domain_config","vercel_get_edge_config","vercel_get_edge_config_items","vercel_get_env_vars","vercel_get_project","vercel_get_team","vercel_get_user","vercel_get_webhook","vercel_list_aliases","vercel_list_checks","vercel_list_deployment_files","vercel_list_deployments","vercel_list_dns_records","vercel_list_domains","vercel_list_edge_configs","vercel_list_project_domains","vercel_list_projects","vercel_list_team_members","vercel_list_teams","vercel_list_webhooks","vercel_pause_project","vercel_promote_deployment","vercel_remove_project_domain","vercel_rerequest_check","vercel_unpause_project","vercel_update_check","vercel_update_dns_record","vercel_update_edge_config_items","vercel_update_env_var","vercel_update_project","vercel_update_project_domain","vercel_verify_project_domain","video_falai","video_luma","video_minimax","video_runway","video_veo","vision_tool","vision_tool_v2","wealthbox_read_contact","wealthbox_read_note","wealthbox_read_task","wealthbox_write_contact","wealthbox_write_note","wealthbox_write_task","webflow_create_item","webflow_delete_item","webflow_get_item","webflow_list_items","webflow_update_item","webhook_request","whatsapp_get_media","whatsapp_mark_read","whatsapp_send_interactive","whatsapp_send_media","whatsapp_send_message","whatsapp_send_reaction","whatsapp_send_template","whatsapp_upload_media","wikipedia_content","wikipedia_random","wikipedia_search","wikipedia_summary","windchill_check_in_document","windchill_check_in_documents","windchill_check_out_document","windchill_check_out_documents","windchill_create_document","windchill_create_documents","windchill_delete_document","windchill_delete_documents","windchill_download_attachment","windchill_download_primary_content","windchill_get_document","windchill_get_document_structure","windchill_get_primary_content","windchill_get_valid_state_transitions","windchill_list_attachments","windchill_list_documents","windchill_revise_document","windchill_revise_documents","windchill_set_lifecycle_state","windchill_undo_check_out_document","windchill_undo_check_out_documents","windchill_update_common_properties","windchill_update_document","windchill_update_document_security_labels","windchill_update_documents","windchill_upload_attachments","windchill_upload_primary_content","wiza_company_enrichment","wiza_get_credits","wiza_individual_reveal","wiza_prospect_search","wordpress_create_category","wordpress_create_comment","wordpress_create_page","wordpress_create_post","wordpress_create_tag","wordpress_delete_category","wordpress_delete_comment","wordpress_delete_media","wordpress_delete_page","wordpress_delete_post","wordpress_delete_tag","wordpress_get_category","wordpress_get_current_user","wordpress_get_media","wordpress_get_page","wordpress_get_post","wordpress_get_tag","wordpress_get_user","wordpress_list_categories","wordpress_list_comments","wordpress_list_media","wordpress_list_pages","wordpress_list_posts","wordpress_list_tags","wordpress_list_users","wordpress_search_content","wordpress_update_category","wordpress_update_comment","wordpress_update_page","wordpress_update_post","wordpress_update_tag","wordpress_upload_media","workday_assign_onboarding","workday_change_job","workday_create_prehire","workday_get_compensation","workday_get_organizations","workday_get_worker","workday_hire_employee","workday_list_workers","workday_terminate_worker","workday_update_worker","workflow_executor","x_create_bookmark","x_create_tweet","x_delete_bookmark","x_delete_tweet","x_get_blocking","x_get_bookmarks","x_get_followers","x_get_following","x_get_liked_tweets","x_get_liking_users","x_get_me","x_get_personalized_trends","x_get_quote_tweets","x_get_retweeted_by","x_get_trends_by_woeid","x_get_tweets_by_ids","x_get_usage","x_get_user_mentions","x_get_user_timeline","x_get_user_tweets","x_hide_reply","x_manage_block","x_manage_follow","x_manage_like","x_manage_mute","x_manage_retweet","x_read","x_search","x_search_tweets","x_search_users","x_user","x_write","youtube_channel_info","youtube_channel_playlists","youtube_channel_videos","youtube_comments","youtube_playlist_items","youtube_search","youtube_trending","youtube_video_categories","youtube_video_details","zendesk_autocomplete_organizations","zendesk_create_organization","zendesk_create_organizations_bulk","zendesk_create_ticket","zendesk_create_tickets_bulk","zendesk_create_user","zendesk_create_users_bulk","zendesk_delete_organization","zendesk_delete_ticket","zendesk_delete_user","zendesk_get_current_user","zendesk_get_organization","zendesk_get_organizations","zendesk_get_ticket","zendesk_get_tickets","zendesk_get_user","zendesk_get_users","zendesk_merge_tickets","zendesk_search","zendesk_search_count","zendesk_search_users","zendesk_update_organization","zendesk_update_ticket","zendesk_update_tickets_bulk","zendesk_update_user","zendesk_update_users_bulk","zep_add_messages","zep_add_user","zep_create_thread","zep_delete_thread","zep_get_context","zep_get_messages","zep_get_threads","zep_get_user","zep_get_user_threads","zerobounce_get_credits","zerobounce_verify_email","zoho_desk_add_comment","zoho_desk_get_attachment","zoho_desk_get_contact","zoho_desk_get_thread","zoho_desk_get_ticket","zoho_desk_list_comments","zoho_desk_list_organizations","zoho_desk_list_threads","zoho_desk_list_tickets","zoho_desk_update_ticket","zoom_create_meeting","zoom_delete_meeting","zoom_delete_recording","zoom_get_meeting","zoom_get_meeting_invitation","zoom_get_meeting_recordings","zoom_list_meetings","zoom_list_past_participants","zoom_list_recordings","zoom_update_meeting","zoominfo_enrich_companies","zoominfo_enrich_contacts","zoominfo_search_companies","zoominfo_search_contacts","zoominfo_search_intent","zoominfo_search_news"]' + '["a2a_cancel_task","a2a_get_agent_card","a2a_get_task","a2a_send_message","agentmail_create_draft","agentmail_create_inbox","agentmail_delete_draft","agentmail_delete_inbox","agentmail_delete_thread","agentmail_forward_message","agentmail_get_draft","agentmail_get_inbox","agentmail_get_message","agentmail_get_thread","agentmail_list_drafts","agentmail_list_inboxes","agentmail_list_messages","agentmail_list_threads","agentmail_reply_message","agentmail_send_draft","agentmail_send_message","agentmail_update_draft","agentmail_update_inbox","agentmail_update_message","agentmail_update_thread","agentphone_create_call","agentphone_create_contact","agentphone_create_number","agentphone_delete_contact","agentphone_get_call","agentphone_get_call_transcript","agentphone_get_contact","agentphone_get_conversation","agentphone_get_conversation_messages","agentphone_get_number_messages","agentphone_get_usage","agentphone_get_usage_daily","agentphone_get_usage_monthly","agentphone_list_calls","agentphone_list_contacts","agentphone_list_conversations","agentphone_list_numbers","agentphone_react_to_message","agentphone_release_number","agentphone_send_message","agentphone_update_contact","agentphone_update_conversation","agiloft_async_status","agiloft_attach_file","agiloft_attachment_info","agiloft_create_record","agiloft_delete_record","agiloft_get_choice_line_id","agiloft_list_tables","agiloft_lock_record","agiloft_nlp_search","agiloft_read_record","agiloft_remove_attachment","agiloft_retrieve_attachment","agiloft_run_action_button","agiloft_saved_search","agiloft_search_records","agiloft_select_records","agiloft_update_record","agiloft_upsert_record","ahrefs_anchors","ahrefs_backlinks","ahrefs_backlinks_stats","ahrefs_batch_analysis","ahrefs_broken_backlinks","ahrefs_domain_rating","ahrefs_domain_rating_history","ahrefs_keyword_overview","ahrefs_keywords_history","ahrefs_metrics","ahrefs_metrics_history","ahrefs_organic_competitors","ahrefs_organic_keywords","ahrefs_paid_pages","ahrefs_rank_tracker_competitors_overview","ahrefs_rank_tracker_competitors_stats","ahrefs_rank_tracker_overview","ahrefs_rank_tracker_serp_overview","ahrefs_refdomains_history","ahrefs_referring_domains","ahrefs_related_terms","ahrefs_site_audit_page_explorer","ahrefs_top_pages","airtable_create_records","airtable_delete_records","airtable_get_base_schema","airtable_get_record","airtable_list_bases","airtable_list_records","airtable_list_tables","airtable_update_multiple_records","airtable_update_record","airtable_upsert_records","airweave_search","algolia_add_record","algolia_batch_operations","algolia_browse_records","algolia_clear_records","algolia_copy_move_index","algolia_delete_by_filter","algolia_delete_index","algolia_delete_record","algolia_get_record","algolia_get_records","algolia_get_settings","algolia_get_task_status","algolia_list_indices","algolia_partial_update_record","algolia_search","algolia_update_settings","amplitude_event_segmentation","amplitude_funnels","amplitude_get_active_users","amplitude_get_revenue","amplitude_group_identify","amplitude_identify_user","amplitude_list_events","amplitude_realtime_active_users","amplitude_retention","amplitude_send_event","amplitude_user_activity","amplitude_user_profile","amplitude_user_search","apify_get_dataset_items","apify_get_run","apify_run_actor_async","apify_run_actor_sync","apify_run_task","apollo_account_bulk_create","apollo_account_bulk_update","apollo_account_create","apollo_account_search","apollo_account_update","apollo_contact_bulk_create","apollo_contact_bulk_update","apollo_contact_create","apollo_contact_search","apollo_contact_update","apollo_email_accounts","apollo_opportunity_create","apollo_opportunity_get","apollo_opportunity_search","apollo_opportunity_update","apollo_organization_bulk_enrich","apollo_organization_enrich","apollo_organization_search","apollo_people_bulk_enrich","apollo_people_enrich","apollo_people_search","apollo_sequence_add_contacts","apollo_sequence_search","apollo_task_create","apollo_task_search","appconfig_create_application","appconfig_create_configuration_profile","appconfig_create_environment","appconfig_create_hosted_configuration_version","appconfig_delete_application","appconfig_delete_configuration_profile","appconfig_delete_environment","appconfig_delete_hosted_configuration_version","appconfig_get_application","appconfig_get_configuration","appconfig_get_configuration_profile","appconfig_get_deployment","appconfig_get_environment","appconfig_get_hosted_configuration_version","appconfig_list_applications","appconfig_list_configuration_profiles","appconfig_list_deployment_strategies","appconfig_list_deployments","appconfig_list_environments","appconfig_list_hosted_configuration_versions","appconfig_start_deployment","appconfig_stop_deployment","appconfig_update_application","appconfig_update_configuration_profile","appconfig_update_environment","arxiv_get_author_papers","arxiv_get_paper","arxiv_search","asana_add_comment","asana_add_followers","asana_create_project","asana_create_section","asana_create_subtask","asana_create_task","asana_delete_task","asana_get_project","asana_get_projects","asana_get_task","asana_list_sections","asana_list_workspaces","asana_search_tasks","asana_update_task","ashby_add_candidate_tag","ashby_anonymize_candidate","ashby_change_application_source","ashby_change_application_stage","ashby_create_application","ashby_create_candidate","ashby_create_note","ashby_delete_application","ashby_get_application","ashby_get_candidate","ashby_get_job","ashby_get_job_posting","ashby_get_offer","ashby_list_applications","ashby_list_archive_reasons","ashby_list_candidate_tags","ashby_list_candidates","ashby_list_custom_fields","ashby_list_departments","ashby_list_interviews","ashby_list_job_postings","ashby_list_jobs","ashby_list_locations","ashby_list_notes","ashby_list_offers","ashby_list_openings","ashby_list_sources","ashby_list_users","ashby_remove_candidate_tag","ashby_search_candidates","ashby_set_custom_field_value","ashby_set_custom_field_values","ashby_update_candidate","athena_batch_get_query_execution","athena_create_named_query","athena_delete_named_query","athena_get_named_query","athena_get_query_execution","athena_get_query_results","athena_list_databases","athena_list_named_queries","athena_list_query_executions","athena_list_table_metadata","athena_start_query","athena_stop_query","attio_assert_record","attio_create_attribute","attio_create_comment","attio_create_list","attio_create_list_entry","attio_create_note","attio_create_object","attio_create_record","attio_create_task","attio_create_webhook","attio_delete_comment","attio_delete_list_entry","attio_delete_note","attio_delete_record","attio_delete_task","attio_delete_webhook","attio_get_attribute","attio_get_comment","attio_get_list","attio_get_list_entry","attio_get_member","attio_get_note","attio_get_object","attio_get_record","attio_get_task","attio_get_thread","attio_get_webhook","attio_list_attributes","attio_list_lists","attio_list_members","attio_list_notes","attio_list_objects","attio_list_records","attio_list_tasks","attio_list_threads","attio_list_webhooks","attio_query_list_entries","attio_search_records","attio_update_attribute","attio_update_list","attio_update_list_entry","attio_update_object","attio_update_record","attio_update_task","attio_update_webhook","azure_data_explorer_create_table","azure_data_explorer_drop_table","azure_data_explorer_ingest_from_query","azure_data_explorer_ingest_inline","azure_data_explorer_list_databases","azure_data_explorer_list_functions","azure_data_explorer_list_tables","azure_data_explorer_management","azure_data_explorer_query","azure_data_explorer_show_database_schema","azure_data_explorer_show_ingestion_failures","azure_data_explorer_show_operations","azure_data_explorer_show_table_details","azure_data_explorer_show_table_schema","azure_devops_add_comment","azure_devops_create_work_item","azure_devops_get_build_log","azure_devops_get_build_timeline","azure_devops_get_comments","azure_devops_get_pipeline","azure_devops_get_pipeline_run","azure_devops_get_work_item","azure_devops_get_work_items_batch","azure_devops_get_work_items_between_builds","azure_devops_list_build_logs","azure_devops_list_builds","azure_devops_list_pipeline_runs","azure_devops_list_pipelines","azure_devops_query_work_items","azure_devops_update_work_item","box_copy_file","box_create_folder","box_delete_file","box_delete_folder","box_download_file","box_get_file_info","box_list_folder_items","box_search","box_sign_cancel_request","box_sign_create_request","box_sign_get_request","box_sign_list_requests","box_sign_resend_request","box_update_file","box_upload_file","brandfetch_get_brand","brandfetch_search","brex_archive_budget","brex_create_budget","brex_create_spend_limit","brex_create_transfer","brex_create_vendor","brex_get_budget","brex_get_cash_account","brex_get_company","brex_get_current_user","brex_get_expense","brex_get_spend_limit","brex_get_transfer","brex_get_user","brex_get_vendor","brex_list_budgets","brex_list_card_accounts","brex_list_card_statements","brex_list_card_transactions","brex_list_cards","brex_list_cash_accounts","brex_list_cash_statements","brex_list_cash_transactions","brex_list_departments","brex_list_expenses","brex_list_locations","brex_list_spend_limits","brex_list_titles","brex_list_transfers","brex_list_users","brex_list_vendors","brex_match_receipt","brex_update_expense","brex_update_vendor","brex_upload_receipt","brightdata_cancel_snapshot","brightdata_discover","brightdata_download_snapshot","brightdata_scrape_dataset","brightdata_scrape_url","brightdata_serp_search","brightdata_snapshot_status","brightdata_sync_scrape","browser_use_run_task","buffer_create_idea","buffer_create_post","buffer_delete_post","buffer_edit_post","buffer_get_account","buffer_get_channels","buffer_get_idea_groups","buffer_get_ideas","buffer_get_post","buffer_get_posts","calcom_cancel_booking","calcom_confirm_booking","calcom_create_booking","calcom_create_event_type","calcom_create_schedule","calcom_decline_booking","calcom_delete_event_type","calcom_delete_schedule","calcom_get_booking","calcom_get_default_schedule","calcom_get_event_type","calcom_get_schedule","calcom_get_slots","calcom_list_bookings","calcom_list_event_types","calcom_list_schedules","calcom_reschedule_booking","calcom_update_event_type","calcom_update_schedule","calendly_cancel_event","calendly_create_event_invitee","calendly_create_invitee_no_show","calendly_create_scheduling_link","calendly_create_webhook","calendly_delete_invitee_no_show","calendly_delete_webhook","calendly_get_current_user","calendly_get_event_invitee","calendly_get_event_type","calendly_get_scheduled_event","calendly_get_user","calendly_list_event_invitees","calendly_list_event_type_available_times","calendly_list_event_types","calendly_list_organization_memberships","calendly_list_routing_form_submissions","calendly_list_routing_forms","calendly_list_scheduled_events","calendly_list_user_availability_schedules","calendly_list_user_busy_times","calendly_list_webhooks","clay_populate","clerk_add_organization_member","clerk_ban_user","clerk_create_actor_token","clerk_create_allowlist_identifier","clerk_create_blocklist_identifier","clerk_create_organization","clerk_create_organization_invitation","clerk_create_user","clerk_delete_allowlist_identifier","clerk_delete_blocklist_identifier","clerk_delete_organization","clerk_delete_user","clerk_get_jwt_template","clerk_get_organization","clerk_get_session","clerk_get_user","clerk_get_user_oauth_token","clerk_list_allowlist_identifiers","clerk_list_blocklist_identifiers","clerk_list_jwt_templates","clerk_list_organization_invitations","clerk_list_organization_memberships","clerk_list_organizations","clerk_list_sessions","clerk_list_users","clerk_lock_user","clerk_remove_organization_member","clerk_revoke_actor_token","clerk_revoke_session","clerk_unban_user","clerk_unlock_user","clerk_update_organization","clerk_update_organization_membership","clerk_update_user","clickhouse_count_rows","clickhouse_create_database","clickhouse_create_table","clickhouse_delete","clickhouse_describe_table","clickhouse_drop_database","clickhouse_drop_partition","clickhouse_drop_table","clickhouse_execute","clickhouse_insert","clickhouse_insert_rows","clickhouse_introspect","clickhouse_kill_query","clickhouse_list_clusters","clickhouse_list_databases","clickhouse_list_mutations","clickhouse_list_partitions","clickhouse_list_running_queries","clickhouse_list_tables","clickhouse_optimize_table","clickhouse_query","clickhouse_rename_table","clickhouse_show_create_table","clickhouse_table_stats","clickhouse_truncate_table","clickhouse_update","clickup_add_tag_to_task","clickup_create_checklist","clickup_create_checklist_item","clickup_create_comment","clickup_create_folder","clickup_create_list","clickup_create_task","clickup_create_time_entry","clickup_delete_checklist","clickup_delete_checklist_item","clickup_delete_comment","clickup_delete_task","clickup_delete_time_entry","clickup_get_comments","clickup_get_custom_fields","clickup_get_folders","clickup_get_list_members","clickup_get_lists","clickup_get_running_timer","clickup_get_space_tags","clickup_get_spaces","clickup_get_task","clickup_get_task_members","clickup_get_tasks","clickup_get_time_entries","clickup_get_workspaces","clickup_remove_custom_field_value","clickup_remove_tag_from_task","clickup_search_tasks","clickup_set_custom_field_value","clickup_start_timer","clickup_stop_timer","clickup_update_checklist","clickup_update_checklist_item","clickup_update_comment","clickup_update_task","clickup_update_time_entry","clickup_upload_attachment","cloudflare_create_dns_record","cloudflare_create_zone","cloudflare_delete_dns_record","cloudflare_delete_zone","cloudflare_dns_analytics","cloudflare_get_zone","cloudflare_get_zone_settings","cloudflare_list_certificates","cloudflare_list_dns_records","cloudflare_list_zones","cloudflare_purge_cache","cloudflare_update_dns_record","cloudflare_update_zone_setting","cloudformation_cancel_update_stack","cloudformation_create_change_set","cloudformation_create_stack","cloudformation_delete_stack","cloudformation_describe_change_set","cloudformation_describe_stack_drift_detection_status","cloudformation_describe_stack_events","cloudformation_describe_stacks","cloudformation_detect_stack_drift","cloudformation_execute_change_set","cloudformation_get_template","cloudformation_get_template_summary","cloudformation_list_stack_resources","cloudformation_update_stack","cloudformation_validate_template","cloudwatch_describe_alarm_history","cloudwatch_describe_alarms","cloudwatch_describe_log_groups","cloudwatch_describe_log_streams","cloudwatch_filter_log_events","cloudwatch_get_log_events","cloudwatch_get_metric_statistics","cloudwatch_list_metrics","cloudwatch_mute_alarm","cloudwatch_put_log_group_retention","cloudwatch_put_metric_data","cloudwatch_query_logs","cloudwatch_unmute_alarm","codepipeline_disable_stage_transition","codepipeline_enable_stage_transition","codepipeline_get_pipeline","codepipeline_get_pipeline_execution","codepipeline_get_pipeline_state","codepipeline_list_action_executions","codepipeline_list_pipeline_executions","codepipeline_list_pipelines","codepipeline_put_approval_result","codepipeline_retry_stage_execution","codepipeline_start_execution","codepipeline_stop_execution","confluence_add_label","confluence_create_blogpost","confluence_create_comment","confluence_create_page","confluence_create_page_property","confluence_create_space","confluence_create_space_property","confluence_delete_attachment","confluence_delete_blogpost","confluence_delete_comment","confluence_delete_label","confluence_delete_page","confluence_delete_page_property","confluence_delete_space","confluence_delete_space_property","confluence_get_blogpost","confluence_get_page_ancestors","confluence_get_page_children","confluence_get_page_descendants","confluence_get_page_version","confluence_get_pages_by_label","confluence_get_space","confluence_get_task","confluence_get_user","confluence_list_attachments","confluence_list_blogposts","confluence_list_blogposts_in_space","confluence_list_comments","confluence_list_labels","confluence_list_page_properties","confluence_list_page_versions","confluence_list_pages_in_space","confluence_list_space_labels","confluence_list_space_permissions","confluence_list_space_properties","confluence_list_spaces","confluence_list_tasks","confluence_retrieve","confluence_search","confluence_search_in_space","confluence_update","confluence_update_blogpost","confluence_update_comment","confluence_update_space","confluence_update_task","confluence_upload_attachment","context_dev_classify_naics","context_dev_classify_sic","context_dev_crawl","context_dev_extract","context_dev_extract_product","context_dev_extract_products","context_dev_get_brand","context_dev_get_brand_by_email","context_dev_get_brand_by_name","context_dev_get_brand_by_ticker","context_dev_identify_transaction","context_dev_map","context_dev_scrape_fonts","context_dev_scrape_html","context_dev_scrape_images","context_dev_scrape_markdown","context_dev_scrape_styleguide","context_dev_screenshot","context_dev_search","convex_action","convex_document_deltas","convex_list_documents","convex_list_tables","convex_mutation","convex_query","convex_run_function","crowdstrike_create_indicators","crowdstrike_delete_indicators","crowdstrike_delete_rtr_session","crowdstrike_execute_rtr_command","crowdstrike_get_alert_details","crowdstrike_get_case_details","crowdstrike_get_host_group_details","crowdstrike_get_indicator_details","crowdstrike_get_rtr_command_status","crowdstrike_get_sensor_aggregates","crowdstrike_get_sensor_details","crowdstrike_get_vulnerability_details","crowdstrike_init_rtr_session","crowdstrike_perform_host_action","crowdstrike_perform_host_group_action","crowdstrike_query_alerts","crowdstrike_query_cases","crowdstrike_query_host_groups","crowdstrike_query_indicators","crowdstrike_query_sensors","crowdstrike_query_vulnerabilities","crowdstrike_update_alerts","crowdstrike_update_indicators","cursor_add_followup","cursor_add_followup_v2","cursor_delete_agent","cursor_delete_agent_v2","cursor_download_artifact","cursor_download_artifact_v2","cursor_get_agent","cursor_get_agent_v2","cursor_get_api_key_info","cursor_get_api_key_info_v2","cursor_get_conversation","cursor_get_conversation_v2","cursor_launch_agent","cursor_launch_agent_v2","cursor_list_agents","cursor_list_agents_v2","cursor_list_artifacts","cursor_list_artifacts_v2","cursor_list_models","cursor_list_models_v2","cursor_list_repositories","cursor_list_repositories_v2","cursor_stop_agent","cursor_stop_agent_v2","dagster_delete_run","dagster_get_asset","dagster_get_run","dagster_get_run_logs","dagster_launch_run","dagster_list_assets","dagster_list_jobs","dagster_list_runs","dagster_list_schedules","dagster_list_sensors","dagster_materialize_assets","dagster_reexecute_run","dagster_report_asset_materialization","dagster_start_schedule","dagster_start_sensor","dagster_stop_schedule","dagster_stop_sensor","dagster_terminate_run","dagster_wipe_asset","databricks_cancel_run","databricks_execute_sql","databricks_get_cluster","databricks_get_job","databricks_get_run","databricks_get_run_output","databricks_get_statement","databricks_list_clusters","databricks_list_jobs","databricks_list_runs","databricks_list_warehouses","databricks_run_job","datadog_cancel_downtime","datadog_create_downtime","datadog_create_event","datadog_create_monitor","datadog_get_monitor","datadog_list_downtimes","datadog_list_monitors","datadog_mute_monitor","datadog_query_logs","datadog_query_timeseries","datadog_send_logs","datadog_submit_metrics","datagma_enrich_company","datagma_enrich_person","datagma_find_email","datagma_find_phone","datagma_get_credits","daytona_create_sandbox","daytona_delete_sandbox","daytona_download_file","daytona_execute_command","daytona_get_sandbox","daytona_git_clone","daytona_list_files","daytona_list_sandboxes","daytona_run_code","daytona_start_sandbox","daytona_stop_sandbox","daytona_upload_file","deployed_block_executor","deployments_deploy","deployments_get_version","deployments_list_versions","deployments_promote","deployments_undeploy","devin_append_session_tags","devin_archive_session","devin_create_session","devin_get_session","devin_get_session_tags","devin_list_session_attachments","devin_list_session_messages","devin_list_sessions","devin_replace_session_tags","devin_send_message","devin_terminate_session","discord_add_reaction","discord_archive_thread","discord_assign_role","discord_ban_member","discord_bulk_delete_messages","discord_create_channel","discord_create_invite","discord_create_role","discord_create_thread","discord_create_webhook","discord_delete_channel","discord_delete_invite","discord_delete_message","discord_delete_role","discord_delete_webhook","discord_edit_message","discord_execute_webhook","discord_get_channel","discord_get_invite","discord_get_member","discord_get_messages","discord_get_pinned_messages","discord_get_server","discord_get_user","discord_get_webhook","discord_join_thread","discord_kick_member","discord_leave_thread","discord_list_channels","discord_list_roles","discord_pin_message","discord_remove_reaction","discord_remove_role","discord_send_message","discord_unban_member","discord_unpin_message","discord_update_channel","discord_update_member","discord_update_role","docusign_create_from_template","docusign_download_document","docusign_get_envelope","docusign_list_envelopes","docusign_list_recipients","docusign_list_templates","docusign_send_envelope","docusign_void_envelope","downdetector_get_company","downdetector_get_company_attribution","downdetector_get_company_baseline","downdetector_get_company_events","downdetector_get_company_incidents","downdetector_get_company_indicators","downdetector_get_company_last_15","downdetector_get_company_status","downdetector_get_provider","downdetector_get_reports","downdetector_get_site_companies","downdetector_list_categories","downdetector_list_incidents","downdetector_list_sites","downdetector_search_companies","dropbox_copy","dropbox_create_folder","dropbox_create_shared_link","dropbox_delete","dropbox_download","dropbox_get_metadata","dropbox_list_folder","dropbox_list_revisions","dropbox_list_shared_links","dropbox_move","dropbox_restore","dropbox_search","dropbox_upload","dropcontact_enrich_contact","dspy_chain_of_thought","dspy_predict","dspy_react","dub_bulk_create_links","dub_bulk_delete_links","dub_bulk_update_links","dub_create_link","dub_create_tag","dub_delete_link","dub_get_analytics","dub_get_events","dub_get_link","dub_get_links_count","dub_get_qr_code","dub_list_domains","dub_list_folders","dub_list_links","dub_list_tags","dub_update_link","dub_upsert_link","duckduckgo_search","dynamodb_delete","dynamodb_get","dynamodb_introspect","dynamodb_put","dynamodb_query","dynamodb_scan","dynamodb_update","dynatrace_add_problem_comment","dynatrace_add_tags","dynatrace_close_problem","dynatrace_create_settings_object","dynatrace_create_slo","dynatrace_delete_problem_comment","dynatrace_delete_settings_object","dynatrace_delete_slo","dynatrace_delete_tag","dynatrace_execute_synthetic_monitors","dynatrace_get_attack","dynatrace_get_audit_logs","dynatrace_get_entity","dynatrace_get_event","dynatrace_get_metric","dynatrace_get_problem","dynatrace_get_problem_comment","dynatrace_get_security_problem","dynatrace_get_settings_object","dynatrace_get_slo","dynatrace_get_synthetic_batch","dynatrace_ingest_event","dynatrace_ingest_logs","dynatrace_ingest_metrics","dynatrace_list_attacks","dynatrace_list_entities","dynatrace_list_entity_types","dynatrace_list_events","dynatrace_list_metrics","dynatrace_list_problem_comments","dynatrace_list_problems","dynatrace_list_remediation_items","dynatrace_list_security_problems","dynatrace_list_settings_objects","dynatrace_list_settings_schemas","dynatrace_list_slos","dynatrace_list_synthetic_monitors","dynatrace_list_tags","dynatrace_mute_security_problem","dynatrace_mute_security_problems","dynatrace_query_metrics","dynatrace_search_logs","dynatrace_unmute_security_problem","dynatrace_unmute_security_problems","dynatrace_update_problem_comment","dynatrace_update_settings_object","dynatrace_update_slo","elasticsearch_bulk","elasticsearch_cluster_health","elasticsearch_cluster_stats","elasticsearch_count","elasticsearch_create_index","elasticsearch_delete_document","elasticsearch_delete_index","elasticsearch_get_document","elasticsearch_get_index","elasticsearch_index_document","elasticsearch_list_indices","elasticsearch_search","elasticsearch_update_document","elevenlabs_audio_isolation","elevenlabs_edit_voice_settings","elevenlabs_get_user","elevenlabs_get_voice","elevenlabs_get_voice_settings","elevenlabs_list_models","elevenlabs_list_voices","elevenlabs_sound_effects","elevenlabs_speech_to_speech","elevenlabs_tts","emailbison_attach_leads_to_campaign","emailbison_attach_tags_to_leads","emailbison_create_campaign","emailbison_create_lead","emailbison_create_tag","emailbison_get_lead","emailbison_list_campaigns","emailbison_list_leads","emailbison_list_replies","emailbison_list_tags","emailbison_update_campaign","emailbison_update_campaign_status","emailbison_update_lead","embeddings_cohere","embeddings_gemini","embeddings_mistral","embeddings_openai","embeddings_openrouter","enrich_check_credits","enrich_company_funding","enrich_company_lookup","enrich_company_revenue","enrich_disposable_email_check","enrich_email_to_ip","enrich_email_to_person_lite","enrich_email_to_phone","enrich_email_to_profile","enrich_find_email","enrich_get_post_details","enrich_ip_to_company","enrich_linkedin_profile","enrich_linkedin_to_personal_email","enrich_linkedin_to_work_email","enrich_phone_finder","enrich_reverse_hash_lookup","enrich_sales_pointer_people","enrich_search_company","enrich_search_company_activities","enrich_search_company_employees","enrich_search_jobs","enrich_search_logo","enrich_search_people","enrich_search_people_activities","enrich_search_post_comments","enrich_search_post_comments_by_url","enrich_search_post_reactions","enrich_search_post_reactions_by_url","enrich_search_posts","enrich_search_similar_companies","enrich_verify_email","enrichment_run","enrow_find_email","enrow_verify_email","evernote_copy_note","evernote_create_note","evernote_create_notebook","evernote_create_tag","evernote_delete_note","evernote_get_note","evernote_get_notebook","evernote_list_notebooks","evernote_list_tags","evernote_search_notes","evernote_update_note","exa_agent","exa_answer","exa_find_similar_links","exa_get_contents","exa_search","extend_parser","extend_parser_v2","fathom_get_summary","fathom_get_transcript","fathom_list_meeting_types","fathom_list_meetings","fathom_list_team_members","fathom_list_teams","file_append","file_compress","file_decompress","file_fetch","file_get","file_get_content","file_manage_sharing","file_parser","file_parser_v2","file_parser_v3","file_read","file_write","findymail_find_email_from_linkedin","findymail_find_email_from_name","findymail_find_emails_by_domain","findymail_find_employees","findymail_find_phone","findymail_get_company","findymail_get_credits","findymail_lookup_technologies","findymail_reverse_email_lookup","findymail_search_technologies","findymail_verify_email","firecrawl_agent","firecrawl_batch_scrape","firecrawl_batch_scrape_status","firecrawl_cancel_crawl","firecrawl_crawl","firecrawl_crawl_status","firecrawl_credit_usage","firecrawl_extract","firecrawl_extract_status","firecrawl_map","firecrawl_parse","firecrawl_scrape","firecrawl_search","fireflies_add_to_live_meeting","fireflies_create_bite","fireflies_delete_transcript","fireflies_get_transcript","fireflies_get_user","fireflies_list_bites","fireflies_list_contacts","fireflies_list_transcripts","fireflies_list_users","fireflies_upload_audio","flint_create_task","flint_generate_pages","flint_get_task","function_execute","gamma_check_status","gamma_generate","gamma_generate_from_template","gamma_list_folders","gamma_list_themes","github_add_assignees","github_add_assignees_v2","github_add_labels","github_add_labels_v2","github_cancel_workflow_run","github_cancel_workflow_run_v2","github_check_star","github_check_star_v2","github_close_issue","github_close_issue_v2","github_close_pr","github_close_pr_v2","github_comment","github_comment_v2","github_compare_commits","github_compare_commits_v2","github_create_branch","github_create_branch_v2","github_create_comment_reaction","github_create_comment_reaction_v2","github_create_file","github_create_file_v2","github_create_gist","github_create_gist_v2","github_create_issue","github_create_issue_reaction","github_create_issue_reaction_v2","github_create_issue_v2","github_create_milestone","github_create_milestone_v2","github_create_pr","github_create_pr_review","github_create_pr_review_v2","github_create_pr_v2","github_create_project","github_create_project_v2","github_create_release","github_create_release_v2","github_delete_branch","github_delete_branch_v2","github_delete_comment","github_delete_comment_reaction","github_delete_comment_reaction_v2","github_delete_comment_v2","github_delete_file","github_delete_file_v2","github_delete_gist","github_delete_gist_v2","github_delete_issue_reaction","github_delete_issue_reaction_v2","github_delete_milestone","github_delete_milestone_v2","github_delete_project","github_delete_project_v2","github_delete_release","github_delete_release_v2","github_fork_gist","github_fork_gist_v2","github_fork_repo","github_fork_repo_v2","github_get_branch","github_get_branch_protection","github_get_branch_protection_v2","github_get_branch_v2","github_get_commit","github_get_commit_v2","github_get_file_content","github_get_file_content_v2","github_get_gist","github_get_gist_v2","github_get_issue","github_get_issue_v2","github_get_latest_release","github_get_latest_release_v2","github_get_milestone","github_get_milestone_v2","github_get_pr_files","github_get_pr_files_v2","github_get_project","github_get_project_v2","github_get_readme","github_get_readme_v2","github_get_release","github_get_release_v2","github_get_tree","github_get_tree_v2","github_get_workflow","github_get_workflow_run","github_get_workflow_run_v2","github_get_workflow_v2","github_issue_comment","github_issue_comment_v2","github_job_logs","github_latest_commit","github_latest_commit_v2","github_list_branches","github_list_branches_v2","github_list_commits","github_list_commits_v2","github_list_forks","github_list_forks_v2","github_list_gists","github_list_gists_v2","github_list_issue_comments","github_list_issue_comments_v2","github_list_issues","github_list_issues_v2","github_list_milestones","github_list_milestones_v2","github_list_pr_comments","github_list_pr_comments_v2","github_list_projects","github_list_projects_v2","github_list_prs","github_list_prs_v2","github_list_releases","github_list_releases_v2","github_list_review_threads","github_list_stargazers","github_list_stargazers_v2","github_list_tags","github_list_tags_v2","github_list_workflow_runs","github_list_workflow_runs_v2","github_list_workflows","github_list_workflows_v2","github_merge_pr","github_merge_pr_v2","github_pr","github_pr_v2","github_remove_label","github_remove_label_v2","github_reply_review_thread","github_repo_info","github_repo_info_v2","github_request_reviewers","github_request_reviewers_v2","github_rerun_workflow","github_rerun_workflow_v2","github_resolve_review_thread","github_search_code","github_search_code_v2","github_search_commits","github_search_commits_v2","github_search_issues","github_search_issues_v2","github_search_repos","github_search_repos_v2","github_search_users","github_search_users_v2","github_star_gist","github_star_gist_v2","github_star_repo","github_star_repo_v2","github_status_check_rollup","github_trigger_workflow","github_trigger_workflow_v2","github_unstar_gist","github_unstar_gist_v2","github_unstar_repo","github_unstar_repo_v2","github_update_branch_protection","github_update_branch_protection_v2","github_update_comment","github_update_comment_v2","github_update_file","github_update_file_v2","github_update_gist","github_update_gist_v2","github_update_issue","github_update_issue_v2","github_update_milestone","github_update_milestone_v2","github_update_pr","github_update_pr_v2","github_update_project","github_update_project_v2","github_update_release","github_update_release_v2","gitlab_activate_user","gitlab_add_member","gitlab_add_saml_group_link","gitlab_approve_access_request","gitlab_approve_merge_request","gitlab_approve_user","gitlab_ban_user","gitlab_block_user","gitlab_cancel_pipeline","gitlab_compare_branches","gitlab_create_branch","gitlab_create_file","gitlab_create_issue","gitlab_create_issue_note","gitlab_create_merge_request","gitlab_create_merge_request_note","gitlab_create_pipeline","gitlab_create_release","gitlab_create_user","gitlab_deactivate_user","gitlab_delete_branch","gitlab_delete_issue","gitlab_delete_saml_group_link","gitlab_delete_user","gitlab_delete_user_identity","gitlab_deny_access_request","gitlab_get_file","gitlab_get_group","gitlab_get_issue","gitlab_get_job_log","gitlab_get_merge_request","gitlab_get_merge_request_changes","gitlab_get_pipeline","gitlab_get_project","gitlab_invite_member","gitlab_list_access_requests","gitlab_list_branches","gitlab_list_commits","gitlab_list_groups","gitlab_list_invitations","gitlab_list_issues","gitlab_list_members","gitlab_list_merge_requests","gitlab_list_pipeline_jobs","gitlab_list_pipelines","gitlab_list_projects","gitlab_list_releases","gitlab_list_repository_tree","gitlab_list_saml_group_links","gitlab_list_user_memberships","gitlab_merge_merge_request","gitlab_play_job","gitlab_reject_user","gitlab_remove_member","gitlab_retry_pipeline","gitlab_revoke_invitation","gitlab_search_users","gitlab_unban_user","gitlab_unblock_user","gitlab_update_file","gitlab_update_invitation","gitlab_update_issue","gitlab_update_member","gitlab_update_merge_request","gitlab_update_user","gmail_add_label","gmail_add_label_v2","gmail_archive","gmail_archive_v2","gmail_create_label_v2","gmail_delete","gmail_delete_draft_v2","gmail_delete_label_v2","gmail_delete_v2","gmail_draft","gmail_draft_v2","gmail_edit_draft_v2","gmail_get_draft_v2","gmail_get_thread_v2","gmail_list_drafts_v2","gmail_list_labels_v2","gmail_list_threads_v2","gmail_mark_read","gmail_mark_read_v2","gmail_mark_unread","gmail_mark_unread_v2","gmail_move","gmail_move_v2","gmail_read","gmail_read_v2","gmail_remove_label","gmail_remove_label_v2","gmail_search","gmail_search_v2","gmail_send","gmail_send_v2","gmail_trash_thread_v2","gmail_unarchive","gmail_unarchive_v2","gmail_untrash_thread_v2","gmail_update_label_v2","gong_aggregate_activity","gong_aggregate_by_period","gong_answered_scorecards","gong_ask_anything","gong_assign_flow_prospects","gong_create_call","gong_day_by_day_activity","gong_get_brief","gong_get_call","gong_get_call_transcript","gong_get_coaching","gong_get_extensive_calls","gong_get_folder_content","gong_get_logs","gong_get_prospect_flows","gong_get_user","gong_interaction_stats","gong_list_calls","gong_list_flows","gong_list_library_folders","gong_list_scorecards","gong_list_trackers","gong_list_users","gong_list_workspaces","gong_lookup_email","gong_lookup_phone","gong_purge_email_address","gong_purge_phone_number","gong_unassign_flow_prospects","google_ads_ad_performance","google_ads_campaign_performance","google_ads_list_ad_groups","google_ads_list_campaigns","google_ads_list_customers","google_ads_search","google_appsheet_add_rows","google_appsheet_delete_rows","google_appsheet_edit_rows","google_appsheet_find_rows","google_bigquery_create_dataset","google_bigquery_create_table","google_bigquery_delete_dataset","google_bigquery_delete_table","google_bigquery_get_query_results","google_bigquery_get_table","google_bigquery_insert_rows","google_bigquery_list_datasets","google_bigquery_list_table_data","google_bigquery_list_tables","google_bigquery_query","google_books_volume_details","google_books_volume_search","google_calendar_create","google_calendar_create_calendar","google_calendar_create_calendar_v2","google_calendar_create_v2","google_calendar_delete","google_calendar_delete_calendar","google_calendar_delete_calendar_v2","google_calendar_delete_v2","google_calendar_freebusy","google_calendar_freebusy_v2","google_calendar_get","google_calendar_get_v2","google_calendar_instances","google_calendar_instances_v2","google_calendar_invite","google_calendar_invite_v2","google_calendar_list","google_calendar_list_acl","google_calendar_list_acl_v2","google_calendar_list_calendars","google_calendar_list_calendars_v2","google_calendar_list_v2","google_calendar_move","google_calendar_move_v2","google_calendar_quick_add","google_calendar_quick_add_v2","google_calendar_share_calendar","google_calendar_share_calendar_v2","google_calendar_unshare_calendar","google_calendar_unshare_calendar_v2","google_calendar_update","google_calendar_update_acl","google_calendar_update_acl_v2","google_calendar_update_calendar","google_calendar_update_calendar_v2","google_calendar_update_v2","google_contacts_create","google_contacts_delete","google_contacts_get","google_contacts_list","google_contacts_search","google_contacts_update","google_docs_create","google_docs_create_named_range","google_docs_create_paragraph_bullets","google_docs_delete_content_range","google_docs_delete_named_range","google_docs_delete_paragraph_bullets","google_docs_insert_image","google_docs_insert_page_break","google_docs_insert_table","google_docs_insert_text","google_docs_read","google_docs_replace_text","google_docs_update_paragraph_style","google_docs_update_text_style","google_docs_write","google_drive_copy","google_drive_create_comment","google_drive_create_folder","google_drive_delete","google_drive_delete_comment","google_drive_download","google_drive_export","google_drive_get_about","google_drive_get_content","google_drive_get_file","google_drive_get_revision","google_drive_list","google_drive_list_comments","google_drive_list_permissions","google_drive_list_revisions","google_drive_move","google_drive_search","google_drive_share","google_drive_trash","google_drive_unshare","google_drive_untrash","google_drive_update","google_drive_upload","google_forms_batch_update","google_forms_create_form","google_forms_create_watch","google_forms_delete_watch","google_forms_get_form","google_forms_get_responses","google_forms_list_watches","google_forms_renew_watch","google_forms_set_publish_settings","google_groups_add_alias","google_groups_add_member","google_groups_create_group","google_groups_delete_group","google_groups_get_group","google_groups_get_member","google_groups_get_settings","google_groups_has_member","google_groups_list_aliases","google_groups_list_groups","google_groups_list_members","google_groups_remove_alias","google_groups_remove_member","google_groups_update_group","google_groups_update_member","google_groups_update_settings","google_maps_air_quality","google_maps_directions","google_maps_distance_matrix","google_maps_elevation","google_maps_geocode","google_maps_geolocate","google_maps_place_details","google_maps_places_nearby","google_maps_places_search","google_maps_pollen","google_maps_reverse_geocode","google_maps_snap_to_roads","google_maps_solar","google_maps_speed_limits","google_maps_timezone","google_maps_validate_address","google_meet_create_space","google_meet_end_conference","google_meet_get_conference_record","google_meet_get_space","google_meet_list_conference_records","google_meet_list_participants","google_pagespeed_analyze","google_search","google_sheets_append","google_sheets_append_v2","google_sheets_batch_clear_v2","google_sheets_batch_get_v2","google_sheets_batch_update_v2","google_sheets_clear_v2","google_sheets_copy_sheet_v2","google_sheets_create_spreadsheet_v2","google_sheets_delete_rows_v2","google_sheets_delete_sheet_v2","google_sheets_delete_spreadsheet_v2","google_sheets_get_spreadsheet_v2","google_sheets_read","google_sheets_read_v2","google_sheets_update","google_sheets_update_v2","google_sheets_write","google_sheets_write_v2","google_slides_add_image","google_slides_add_slide","google_slides_batch_update","google_slides_copy_presentation","google_slides_create","google_slides_create_line","google_slides_create_paragraph_bullets","google_slides_create_shape","google_slides_create_sheets_chart","google_slides_create_table","google_slides_create_video","google_slides_delete_object","google_slides_delete_paragraph_bullets","google_slides_delete_table_column","google_slides_delete_table_row","google_slides_delete_text","google_slides_duplicate_object","google_slides_export_presentation","google_slides_get_page","google_slides_get_thumbnail","google_slides_group_objects","google_slides_insert_table_columns","google_slides_insert_table_rows","google_slides_insert_text","google_slides_merge_table_cells","google_slides_read","google_slides_refresh_sheets_chart","google_slides_replace_all_shapes_with_image","google_slides_replace_all_shapes_with_sheets_chart","google_slides_replace_all_text","google_slides_replace_image","google_slides_reroute_line","google_slides_ungroup_objects","google_slides_unmerge_table_cells","google_slides_update_image_properties","google_slides_update_line_category","google_slides_update_line_properties","google_slides_update_page_element_alt_text","google_slides_update_page_element_transform","google_slides_update_page_elements_z_order","google_slides_update_page_properties","google_slides_update_paragraph_style","google_slides_update_shape_properties","google_slides_update_slide_properties","google_slides_update_slides_position","google_slides_update_table_border_properties","google_slides_update_table_cell_properties","google_slides_update_table_column_properties","google_slides_update_table_row_properties","google_slides_update_text_style","google_slides_update_video_properties","google_slides_write","google_tasks_create","google_tasks_delete","google_tasks_get","google_tasks_list","google_tasks_list_task_lists","google_tasks_update","google_translate_detect","google_translate_text","google_vault_add_held_accounts","google_vault_add_matters_permissions","google_vault_close_matters","google_vault_create_matters","google_vault_create_matters_export","google_vault_create_matters_holds","google_vault_create_saved_query","google_vault_delete_matters","google_vault_delete_matters_export","google_vault_delete_matters_holds","google_vault_delete_saved_query","google_vault_download_export_file","google_vault_list_matters","google_vault_list_matters_export","google_vault_list_matters_holds","google_vault_list_saved_queries","google_vault_remove_held_accounts","google_vault_remove_matters_permissions","google_vault_reopen_matters","google_vault_undelete_matters","google_vault_update_matters","google_vault_update_matters_holds","grafana_check_data_source_health","grafana_create_alert_rule","grafana_create_annotation","grafana_create_contact_point","grafana_create_dashboard","grafana_create_folder","grafana_delete_alert_rule","grafana_delete_annotation","grafana_delete_contact_point","grafana_delete_dashboard","grafana_delete_folder","grafana_get_alert_rule","grafana_get_alert_rule_group","grafana_get_dashboard","grafana_get_data_source","grafana_get_folder","grafana_get_health","grafana_list_alert_rules","grafana_list_annotations","grafana_list_contact_points","grafana_list_dashboards","grafana_list_data_sources","grafana_list_folders","grafana_move_folder","grafana_query_data_source","grafana_update_alert_rule","grafana_update_annotation","grafana_update_contact_point","grafana_update_dashboard","grafana_update_folder","grain_create_hook","grain_create_hook_v2","grain_delete_hook","grain_delete_hook_v2","grain_get_recording","grain_get_transcript","grain_list_hooks","grain_list_hooks_v2","grain_list_meeting_types","grain_list_recordings","grain_list_teams","grain_list_views","granola_get_note","granola_list_folders","granola_list_notes","greenhouse_get_application","greenhouse_get_candidate","greenhouse_get_job","greenhouse_get_user","greenhouse_list_applications","greenhouse_list_candidates","greenhouse_list_departments","greenhouse_list_job_stages","greenhouse_list_jobs","greenhouse_list_offices","greenhouse_list_users","greptile_index_repo","greptile_query","greptile_search","greptile_status","guardrails_validate","hex_cancel_run","hex_create_collection","hex_create_group","hex_deactivate_user","hex_delete_group","hex_get_collection","hex_get_data_connection","hex_get_group","hex_get_project","hex_get_project_runs","hex_get_queried_tables","hex_get_run_status","hex_list_collections","hex_list_data_connections","hex_list_groups","hex_list_projects","hex_list_users","hex_run_project","hex_update_collection","hex_update_group","hex_update_project","http_request","hubspot_add_list_memberships","hubspot_create_appointment","hubspot_create_association","hubspot_create_company","hubspot_create_contact","hubspot_create_deal","hubspot_create_email","hubspot_create_line_item","hubspot_create_list","hubspot_create_note","hubspot_create_ticket","hubspot_delete_association","hubspot_delete_company","hubspot_delete_contact","hubspot_delete_deal","hubspot_delete_line_item","hubspot_delete_ticket","hubspot_get_appointment","hubspot_get_association_labels","hubspot_get_cart","hubspot_get_company","hubspot_get_contact","hubspot_get_deal","hubspot_get_email","hubspot_get_line_item","hubspot_get_list","hubspot_get_list_memberships","hubspot_get_marketing_event","hubspot_get_note","hubspot_get_properties","hubspot_get_quote","hubspot_get_ticket","hubspot_get_users","hubspot_list_appointments","hubspot_list_associations","hubspot_list_carts","hubspot_list_companies","hubspot_list_contacts","hubspot_list_deals","hubspot_list_emails","hubspot_list_line_items","hubspot_list_lists","hubspot_list_marketing_events","hubspot_list_notes","hubspot_list_owners","hubspot_list_quotes","hubspot_list_tickets","hubspot_remove_list_memberships","hubspot_search_companies","hubspot_search_contacts","hubspot_search_deals","hubspot_search_emails","hubspot_search_line_items","hubspot_search_notes","hubspot_search_quotes","hubspot_search_tickets","hubspot_update_appointment","hubspot_update_company","hubspot_update_contact","hubspot_update_deal","hubspot_update_line_item","hubspot_update_ticket","huggingface_chat","hunter_companies_find","hunter_discover","hunter_domain_search","hunter_email_count","hunter_email_finder","hunter_email_verifier","iam_add_user_to_group","iam_attach_role_policy","iam_attach_user_policy","iam_create_access_key","iam_create_role","iam_create_user","iam_delete_access_key","iam_delete_role","iam_delete_user","iam_detach_role_policy","iam_detach_user_policy","iam_get_role","iam_get_user","iam_list_attached_role_policies","iam_list_attached_user_policies","iam_list_groups","iam_list_policies","iam_list_roles","iam_list_users","iam_remove_user_from_group","iam_simulate_principal_policy","icypeas_find_email","icypeas_verify_email","identity_center_check_assignment_deletion_status","identity_center_check_assignment_status","identity_center_create_account_assignment","identity_center_delete_account_assignment","identity_center_describe_account","identity_center_get_group","identity_center_get_user","identity_center_list_account_assignments","identity_center_list_accounts","identity_center_list_groups","identity_center_list_instances","identity_center_list_permission_sets","image_generate","incidentio_actions_create","incidentio_actions_list","incidentio_actions_show","incidentio_actions_update","incidentio_alert_events_create","incidentio_alerts_list","incidentio_alerts_resolve","incidentio_alerts_show","incidentio_catalog_entries_list","incidentio_catalog_types_list","incidentio_custom_fields_create","incidentio_custom_fields_delete","incidentio_custom_fields_list","incidentio_custom_fields_show","incidentio_custom_fields_update","incidentio_escalation_paths_create","incidentio_escalation_paths_delete","incidentio_escalation_paths_list","incidentio_escalation_paths_show","incidentio_escalation_paths_update","incidentio_escalations_cancel","incidentio_escalations_create","incidentio_escalations_list","incidentio_escalations_show","incidentio_follow_ups_create","incidentio_follow_ups_list","incidentio_follow_ups_show","incidentio_follow_ups_update","incidentio_incident_alerts_list","incidentio_incident_memberships_create","incidentio_incident_memberships_revoke","incidentio_incident_participants_list","incidentio_incident_roles_create","incidentio_incident_roles_delete","incidentio_incident_roles_list","incidentio_incident_roles_show","incidentio_incident_roles_update","incidentio_incident_statuses_list","incidentio_incident_timestamps_list","incidentio_incident_timestamps_show","incidentio_incident_types_list","incidentio_incident_updates_list","incidentio_incidents_create","incidentio_incidents_list","incidentio_incidents_show","incidentio_incidents_update","incidentio_on_call_now","incidentio_schedule_entries_list","incidentio_schedule_overrides_create","incidentio_schedule_overrides_list","incidentio_schedules_create","incidentio_schedules_delete","incidentio_schedules_list","incidentio_schedules_show","incidentio_schedules_update","incidentio_severities_list","incidentio_teams_list","incidentio_teams_show","incidentio_users_list","incidentio_users_show","incidentio_workflows_create","incidentio_workflows_delete","incidentio_workflows_list","incidentio_workflows_show","incidentio_workflows_update","infisical_create_secret","infisical_delete_secret","infisical_get_secret","infisical_list_secrets","infisical_update_secret","instagram_delete_comment","instagram_download_media","instagram_get_account_insights","instagram_get_container_status","instagram_get_conversation_messages","instagram_get_media","instagram_get_media_insights","instagram_get_message","instagram_get_profile","instagram_get_publishing_limit","instagram_hide_comment","instagram_list_comments","instagram_list_conversations","instagram_list_media","instagram_list_stories","instagram_private_reply","instagram_publish_carousel","instagram_publish_image","instagram_publish_reel","instagram_publish_story","instagram_publish_video","instagram_reply_to_comment","instagram_send_text_message","instagram_set_comments_enabled","instantly_activate_campaign","instantly_create_campaign","instantly_create_lead","instantly_create_lead_list","instantly_delete_campaign","instantly_delete_leads","instantly_get_lead","instantly_list_campaigns","instantly_list_emails","instantly_list_lead_lists","instantly_list_leads","instantly_patch_campaign","instantly_patch_lead","instantly_pause_campaign","instantly_reply_to_email","instantly_update_lead_interest_status","intercom_assign_conversation_v2","intercom_attach_contact_to_company_v2","intercom_close_conversation_v2","intercom_create_company","intercom_create_company_v2","intercom_create_contact","intercom_create_contact_v2","intercom_create_event_v2","intercom_create_message","intercom_create_message_v2","intercom_create_note_v2","intercom_create_tag_v2","intercom_create_ticket","intercom_create_ticket_v2","intercom_delete_contact","intercom_delete_contact_v2","intercom_detach_contact_from_company_v2","intercom_get_company","intercom_get_company_v2","intercom_get_contact","intercom_get_contact_v2","intercom_get_conversation","intercom_get_conversation_v2","intercom_get_ticket","intercom_get_ticket_v2","intercom_list_admins_v2","intercom_list_companies","intercom_list_companies_v2","intercom_list_contacts","intercom_list_contacts_v2","intercom_list_conversations","intercom_list_conversations_v2","intercom_list_tags_v2","intercom_open_conversation_v2","intercom_reply_conversation","intercom_reply_conversation_v2","intercom_search_contacts","intercom_search_contacts_v2","intercom_search_conversations","intercom_search_conversations_v2","intercom_snooze_conversation_v2","intercom_tag_contact_v2","intercom_tag_conversation_v2","intercom_untag_contact_v2","intercom_update_contact","intercom_update_contact_v2","intercom_update_ticket_v2","jina_read_url","jina_search","jira_add_attachment","jira_add_comment","jira_add_watcher","jira_add_worklog","jira_assign_issue","jira_bulk_read","jira_create_issue_link","jira_delete_attachment","jira_delete_comment","jira_delete_issue","jira_delete_issue_link","jira_delete_worklog","jira_get_attachments","jira_get_comments","jira_get_fields","jira_get_project","jira_get_transitions","jira_get_users","jira_get_worklogs","jira_list_issue_types","jira_list_projects","jira_remove_watcher","jira_retrieve","jira_search_issues","jira_search_users","jira_transition_issue","jira_update","jira_update_comment","jira_update_worklog","jira_write","jsm_add_comment","jsm_add_customer","jsm_add_organization","jsm_add_participants","jsm_answer_approval","jsm_attach_form","jsm_copy_forms","jsm_create_object","jsm_create_organization","jsm_create_request","jsm_delete_form","jsm_delete_object","jsm_externalise_form","jsm_get_approvals","jsm_get_comments","jsm_get_customers","jsm_get_form","jsm_get_form_answers","jsm_get_form_structure","jsm_get_form_templates","jsm_get_issue_forms","jsm_get_object","jsm_get_object_schema","jsm_get_object_type_attributes","jsm_get_organizations","jsm_get_participants","jsm_get_queues","jsm_get_request","jsm_get_request_type_fields","jsm_get_request_types","jsm_get_requests","jsm_get_service_desks","jsm_get_sla","jsm_get_transitions","jsm_internalise_form","jsm_list_object_schemas","jsm_list_object_types","jsm_reopen_form","jsm_save_form_answers","jsm_search_objects_aql","jsm_submit_form","jsm_transition_request","jsm_update_object","jupyter_copy_content","jupyter_create_file","jupyter_create_session","jupyter_delete_content","jupyter_delete_session","jupyter_get_content","jupyter_interrupt_kernel","jupyter_list_contents","jupyter_list_kernels","jupyter_list_kernelspecs","jupyter_list_sessions","jupyter_rename_content","jupyter_restart_kernel","jupyter_start_kernel","jupyter_stop_kernel","jupyter_upload_file","kalshi_amend_order","kalshi_amend_order_v2","kalshi_cancel_order","kalshi_cancel_order_v2","kalshi_create_order","kalshi_create_order_v2","kalshi_get_balance","kalshi_get_balance_v2","kalshi_get_candlesticks","kalshi_get_candlesticks_v2","kalshi_get_event","kalshi_get_event_candlesticks","kalshi_get_event_candlesticks_v2","kalshi_get_event_v2","kalshi_get_events","kalshi_get_events_v2","kalshi_get_exchange_announcements","kalshi_get_exchange_announcements_v2","kalshi_get_exchange_schedule","kalshi_get_exchange_schedule_v2","kalshi_get_exchange_status","kalshi_get_exchange_status_v2","kalshi_get_fills","kalshi_get_fills_v2","kalshi_get_market","kalshi_get_market_v2","kalshi_get_markets","kalshi_get_markets_v2","kalshi_get_order","kalshi_get_order_v2","kalshi_get_orderbook","kalshi_get_orderbook_v2","kalshi_get_orders","kalshi_get_orders_v2","kalshi_get_positions","kalshi_get_positions_v2","kalshi_get_series_by_ticker","kalshi_get_series_by_ticker_v2","kalshi_get_series_list","kalshi_get_series_list_v2","kalshi_get_settlements","kalshi_get_settlements_v2","kalshi_get_trades","kalshi_get_trades_v2","ketch_get_consent","ketch_get_subscriptions","ketch_invoke_right","ketch_set_consent","ketch_set_subscriptions","knowledge_create_document","knowledge_delete_chunk","knowledge_delete_document","knowledge_get_connector","knowledge_get_document","knowledge_list_chunks","knowledge_list_connectors","knowledge_list_documents","knowledge_list_tags","knowledge_search","knowledge_trigger_sync","knowledge_update_chunk","knowledge_upload_chunk","knowledge_upsert_document","langsmith_create_feedback","langsmith_create_run","langsmith_create_runs_batch","langsmith_get_run","langsmith_update_run","latex_compile","latex_get_package","latex_list_fonts","latex_search_packages","launchdarkly_create_flag","launchdarkly_delete_flag","launchdarkly_get_audit_log","launchdarkly_get_flag","launchdarkly_get_flag_status","launchdarkly_list_environments","launchdarkly_list_flags","launchdarkly_list_members","launchdarkly_list_projects","launchdarkly_list_segments","launchdarkly_toggle_flag","launchdarkly_update_flag","leadmagic_company_search","leadmagic_email_to_profile","leadmagic_find_email","leadmagic_find_mobile","leadmagic_get_credits","leadmagic_profile_search","leadmagic_profile_to_email","leadmagic_role_finder","leadmagic_validate_email","lemlist_get_activities","lemlist_get_lead","lemlist_send_email","linear_add_label_to_issue","linear_add_label_to_project","linear_archive_issue","linear_archive_label","linear_archive_project","linear_create_attachment","linear_create_comment","linear_create_customer","linear_create_customer_request","linear_create_customer_status","linear_create_customer_tier","linear_create_cycle","linear_create_favorite","linear_create_issue","linear_create_issue_relation","linear_create_label","linear_create_project","linear_create_project_label","linear_create_project_milestone","linear_create_project_status","linear_create_project_update","linear_create_workflow_state","linear_delete_attachment","linear_delete_comment","linear_delete_customer","linear_delete_customer_status","linear_delete_customer_tier","linear_delete_issue","linear_delete_issue_relation","linear_delete_project","linear_delete_project_label","linear_delete_project_milestone","linear_delete_project_status","linear_get_active_cycle","linear_get_customer","linear_get_cycle","linear_get_issue","linear_get_project","linear_get_viewer","linear_list_attachments","linear_list_comments","linear_list_customer_requests","linear_list_customer_statuses","linear_list_customer_tiers","linear_list_customers","linear_list_cycles","linear_list_favorites","linear_list_issue_relations","linear_list_labels","linear_list_notifications","linear_list_project_labels","linear_list_project_milestones","linear_list_project_statuses","linear_list_project_updates","linear_list_projects","linear_list_teams","linear_list_users","linear_list_workflow_states","linear_merge_customers","linear_read_issues","linear_remove_label_from_issue","linear_remove_label_from_project","linear_search_issues","linear_unarchive_issue","linear_update_attachment","linear_update_comment","linear_update_customer","linear_update_customer_request","linear_update_customer_status","linear_update_customer_tier","linear_update_issue","linear_update_label","linear_update_notification","linear_update_project","linear_update_project_label","linear_update_project_milestone","linear_update_project_status","linear_update_workflow_state","linkedin_get_profile","linkedin_share_post","linkup_search","linq_add_participant","linq_check_imessage","linq_check_rcs","linq_create_attachment","linq_create_chat","linq_create_contact_card","linq_create_webhook_subscription","linq_delete_attachment","linq_delete_message","linq_delete_webhook_subscription","linq_edit_message","linq_get_attachment","linq_get_chat","linq_get_contact_card","linq_get_message","linq_get_webhook_subscription","linq_leave_chat","linq_list_chats","linq_list_messages","linq_list_phone_numbers","linq_list_thread","linq_list_webhook_events","linq_list_webhook_subscriptions","linq_mark_chat_read","linq_react_to_message","linq_remove_participant","linq_send_message","linq_send_voice_memo","linq_share_contact_card","linq_start_typing","linq_stop_typing","linq_update_chat","linq_update_contact_card","linq_update_webhook_subscription","llm_chat","logfire_get_token_info","logfire_get_trace","logfire_query","logfire_search_records","logrocket_create_release","logrocket_get_audit_logs","logrocket_get_highlights","logrocket_identify_user","logrocket_list_exported_sessions","logrocket_request_highlights","logs_get","logs_get_execution","logs_get_run_details","logs_query","logs_query_runs","loops_check_contact_suppression","loops_create_contact","loops_create_contact_property","loops_delete_contact","loops_find_contact","loops_get_transactional_email","loops_list_contact_properties","loops_list_mailing_lists","loops_list_transactional_emails","loops_remove_contact_suppression","loops_send_event","loops_send_transactional_email","loops_update_contact","luma_add_guests","luma_cancel_event","luma_create_event","luma_get_event","luma_get_guest","luma_get_guests","luma_list_events","luma_lookup_event","luma_send_invites","luma_update_event","luma_update_guest_status","mailchimp_add_member","mailchimp_add_member_tags","mailchimp_add_or_update_member","mailchimp_add_segment_member","mailchimp_add_subscriber_to_automation","mailchimp_archive_member","mailchimp_create_audience","mailchimp_create_batch_operation","mailchimp_create_campaign","mailchimp_create_interest","mailchimp_create_interest_category","mailchimp_create_landing_page","mailchimp_create_merge_field","mailchimp_create_segment","mailchimp_create_template","mailchimp_delete_audience","mailchimp_delete_batch_operation","mailchimp_delete_campaign","mailchimp_delete_interest","mailchimp_delete_interest_category","mailchimp_delete_landing_page","mailchimp_delete_member","mailchimp_delete_merge_field","mailchimp_delete_segment","mailchimp_delete_template","mailchimp_get_audience","mailchimp_get_audiences","mailchimp_get_automation","mailchimp_get_automations","mailchimp_get_batch_operation","mailchimp_get_batch_operations","mailchimp_get_campaign","mailchimp_get_campaign_content","mailchimp_get_campaign_report","mailchimp_get_campaign_reports","mailchimp_get_campaigns","mailchimp_get_interest","mailchimp_get_interest_categories","mailchimp_get_interest_category","mailchimp_get_interests","mailchimp_get_landing_page","mailchimp_get_landing_pages","mailchimp_get_member","mailchimp_get_member_tags","mailchimp_get_members","mailchimp_get_merge_field","mailchimp_get_merge_fields","mailchimp_get_segment","mailchimp_get_segment_members","mailchimp_get_segments","mailchimp_get_template","mailchimp_get_templates","mailchimp_pause_automation","mailchimp_publish_landing_page","mailchimp_remove_member_tags","mailchimp_remove_segment_member","mailchimp_replicate_campaign","mailchimp_schedule_campaign","mailchimp_send_campaign","mailchimp_set_campaign_content","mailchimp_start_automation","mailchimp_unarchive_member","mailchimp_unpublish_landing_page","mailchimp_unschedule_campaign","mailchimp_update_audience","mailchimp_update_campaign","mailchimp_update_interest","mailchimp_update_interest_category","mailchimp_update_landing_page","mailchimp_update_member","mailchimp_update_merge_field","mailchimp_update_segment","mailchimp_update_template","mailgun_add_list_member","mailgun_create_mailing_list","mailgun_get_domain","mailgun_get_mailing_list","mailgun_get_message","mailgun_list_domains","mailgun_list_messages","mailgun_send_message","managed_agent_archive_session","managed_agent_create_session","managed_agent_delete_session","managed_agent_get_session","managed_agent_interrupt_session","managed_agent_list_events","managed_agent_respond_custom_tool","managed_agent_respond_tool_confirmation","managed_agent_run_session","managed_agent_send_message","managed_agent_update_session","mem0_add_memories","mem0_get_memories","mem0_search_memories","memory_add","memory_delete","memory_get","memory_get_all","microsoft_ad_add_group_member","microsoft_ad_create_group","microsoft_ad_create_user","microsoft_ad_delete_group","microsoft_ad_delete_user","microsoft_ad_get_group","microsoft_ad_get_user","microsoft_ad_list_group_members","microsoft_ad_list_groups","microsoft_ad_list_users","microsoft_ad_remove_group_member","microsoft_ad_update_group","microsoft_ad_update_user","microsoft_dataverse_associate","microsoft_dataverse_create_multiple","microsoft_dataverse_create_record","microsoft_dataverse_delete_record","microsoft_dataverse_disassociate","microsoft_dataverse_download_file","microsoft_dataverse_execute_action","microsoft_dataverse_execute_function","microsoft_dataverse_fetchxml_query","microsoft_dataverse_get_entity_metadata","microsoft_dataverse_get_record","microsoft_dataverse_list_records","microsoft_dataverse_search","microsoft_dataverse_update_multiple","microsoft_dataverse_update_record","microsoft_dataverse_upload_file","microsoft_dataverse_upsert_record","microsoft_dataverse_whoami","microsoft_excel_clear_range","microsoft_excel_create_table","microsoft_excel_delete_worksheet","microsoft_excel_format_range","microsoft_excel_read","microsoft_excel_read_v2","microsoft_excel_sort_range","microsoft_excel_table_add","microsoft_excel_worksheet_add","microsoft_excel_write","microsoft_excel_write_v2","microsoft_planner_create_bucket","microsoft_planner_create_plan","microsoft_planner_create_task","microsoft_planner_delete_bucket","microsoft_planner_delete_plan","microsoft_planner_delete_task","microsoft_planner_get_plan_details","microsoft_planner_get_task_details","microsoft_planner_list_buckets","microsoft_planner_list_plans","microsoft_planner_read_bucket","microsoft_planner_read_plan","microsoft_planner_read_task","microsoft_planner_update_bucket","microsoft_planner_update_plan","microsoft_planner_update_plan_details","microsoft_planner_update_task","microsoft_planner_update_task_details","microsoft_teams_delete_channel_message","microsoft_teams_delete_chat_message","microsoft_teams_get_message","microsoft_teams_list_channel_members","microsoft_teams_list_channels","microsoft_teams_list_chat_members","microsoft_teams_list_chats","microsoft_teams_list_team_members","microsoft_teams_list_teams","microsoft_teams_read_channel","microsoft_teams_read_chat","microsoft_teams_reply_to_message","microsoft_teams_set_reaction","microsoft_teams_unset_reaction","microsoft_teams_update_channel_message","microsoft_teams_update_chat_message","microsoft_teams_write_channel","microsoft_teams_write_chat","millionverifier_get_credits","millionverifier_verify_email","mintlify_create_agent_job","mintlify_create_assistant_message","mintlify_detect_ai_prose","mintlify_get_agent_job","mintlify_get_assistant_caller_stats","mintlify_get_assistant_conversations","mintlify_get_feedback","mintlify_get_feedback_by_page","mintlify_get_page_content","mintlify_get_searches","mintlify_get_update_status","mintlify_get_views","mintlify_get_visitors","mintlify_search","mintlify_send_agent_message","mintlify_trigger_automation","mintlify_trigger_preview","mintlify_trigger_update","mistral_parser","mistral_parser_v2","mistral_parser_v3","monday_archive_item","monday_change_column_value","monday_create_board","monday_create_column","monday_create_group","monday_create_item","monday_create_subitem","monday_create_update","monday_delete_item","monday_duplicate_item","monday_get_board","monday_get_groups","monday_get_item","monday_get_items","monday_list_boards","monday_move_item_to_group","monday_search_items","monday_update_item","mongodb_delete","mongodb_execute","mongodb_insert","mongodb_introspect","mongodb_query","mongodb_update","mysql_delete","mysql_execute","mysql_insert","mysql_introspect","mysql_query","mysql_update","neo4j_create","neo4j_delete","neo4j_execute","neo4j_introspect","neo4j_merge","neo4j_query","neo4j_update","netsuite_attach_record","netsuite_batch_create_records","netsuite_batch_delete_records","netsuite_batch_get_records","netsuite_batch_update_records","netsuite_batch_upsert_records","netsuite_create_record","netsuite_delete_record","netsuite_detach_record","netsuite_execute_action","netsuite_execute_dataset","netsuite_execute_suiteql","netsuite_get_async_result","netsuite_get_async_status","netsuite_get_governance_limits","netsuite_get_record","netsuite_get_record_form","netsuite_get_record_metadata","netsuite_get_select_options","netsuite_get_server_time","netsuite_get_subresource","netsuite_list_datasets","netsuite_list_record_types","netsuite_list_records","netsuite_transform_record","netsuite_update_record","netsuite_upsert_record","neverbounce_get_credits","neverbounce_verify_email","new_relic_create_deployment_event","new_relic_get_entity","new_relic_nrql_query","new_relic_search_entities","notion_add_database_row","notion_add_database_row_v2","notion_append_blocks","notion_append_blocks_v2","notion_create_comment","notion_create_comment_v2","notion_create_database","notion_create_database_v2","notion_create_page","notion_create_page_v2","notion_delete_block","notion_delete_block_v2","notion_list_comments","notion_list_comments_v2","notion_list_users","notion_list_users_v2","notion_query_database","notion_query_database_v2","notion_read","notion_read_database","notion_read_database_v2","notion_read_v2","notion_retrieve_block","notion_retrieve_block_children","notion_retrieve_block_children_v2","notion_retrieve_block_v2","notion_retrieve_user","notion_retrieve_user_v2","notion_search","notion_search_v2","notion_update_block","notion_update_block_v2","notion_update_page","notion_update_page_v2","notion_write","notion_write_v2","obsidian_append_active","obsidian_append_note","obsidian_append_periodic_note","obsidian_create_note","obsidian_delete_note","obsidian_execute_command","obsidian_get_active","obsidian_get_note","obsidian_get_periodic_note","obsidian_list_commands","obsidian_list_files","obsidian_open_file","obsidian_patch_active","obsidian_patch_note","obsidian_search","okta_activate_group_rule","okta_activate_user","okta_add_user_to_group","okta_assign_group_to_app","okta_assign_user_role","okta_assign_user_to_app","okta_clear_user_sessions","okta_create_group","okta_create_group_rule","okta_create_user","okta_deactivate_group_rule","okta_deactivate_user","okta_delete_group","okta_delete_group_rule","okta_delete_user","okta_enroll_factor","okta_get_app","okta_get_factor","okta_get_group","okta_get_group_rule","okta_get_logs","okta_get_session","okta_get_user","okta_list_app_groups","okta_list_app_users","okta_list_apps","okta_list_factors","okta_list_group_members","okta_list_group_rules","okta_list_groups","okta_list_user_roles","okta_list_users","okta_remove_group_from_app","okta_remove_user_from_app","okta_remove_user_from_group","okta_remove_user_role","okta_reset_all_factors","okta_reset_factor","okta_reset_password","okta_revoke_session","okta_suspend_user","okta_unsuspend_user","okta_update_group","okta_update_user","onedrive_copy","onedrive_create_folder","onedrive_create_share_link","onedrive_delete","onedrive_download","onedrive_get_drive_info","onedrive_get_item","onedrive_list","onedrive_move","onedrive_search","onedrive_upload","onepassword_create_item","onepassword_delete_item","onepassword_get_item","onepassword_get_item_file","onepassword_get_vault","onepassword_list_items","onepassword_list_vaults","onepassword_replace_item","onepassword_resolve_secret","onepassword_update_item","openai_embeddings","openai_image","outlook_calendar_create_event","outlook_calendar_delete_event","outlook_calendar_get_event","outlook_calendar_list_events","outlook_calendar_respond","outlook_calendar_update_event","outlook_copy","outlook_create_folder","outlook_delete","outlook_draft","outlook_forward","outlook_get_attachment","outlook_list_attachments","outlook_list_folders","outlook_mark_read","outlook_mark_unread","outlook_move","outlook_read","outlook_reply","outlook_reply_all","outlook_search","outlook_send","outlook_update_message","pagerduty_add_note","pagerduty_create_incident","pagerduty_get_incident","pagerduty_get_service","pagerduty_list_escalation_policies","pagerduty_list_incident_alerts","pagerduty_list_incidents","pagerduty_list_oncalls","pagerduty_list_schedules","pagerduty_list_services","pagerduty_list_users","pagerduty_merge_incidents","pagerduty_send_event","pagerduty_snooze_incident","pagerduty_update_incident","parallel_deep_research","parallel_extract","parallel_search","pdl_autocomplete","pdl_bulk_company_enrich","pdl_bulk_person_enrich","pdl_clean_company","pdl_clean_location","pdl_clean_school","pdl_company_enrich","pdl_company_search","pdl_person_enrich","pdl_person_identify","pdl_person_search","perplexity_chat","perplexity_search","persona_approve_inquiry","persona_create_account","persona_create_inquiry","persona_create_report","persona_decline_inquiry","persona_expire_inquiry","persona_generate_inquiry_link","persona_get_account","persona_get_case","persona_get_document","persona_get_inquiry","persona_get_report","persona_get_verification","persona_import_accounts","persona_list_accounts","persona_list_cases","persona_list_inquiries","persona_list_inquiry_templates","persona_list_reports","persona_mark_inquiry_for_review","persona_print_inquiry_pdf","persona_redact_account","persona_redact_inquiry","persona_resume_inquiry","persona_update_account","persona_update_inquiry","pinecone_delete_vectors","pinecone_describe_index","pinecone_describe_index_stats","pinecone_fetch","pinecone_generate_embeddings","pinecone_list_indexes","pinecone_list_vector_ids","pinecone_search_text","pinecone_search_vector","pinecone_update_vector","pinecone_upsert_text","pipedrive_create_activity","pipedrive_create_deal","pipedrive_create_lead","pipedrive_create_project","pipedrive_delete_lead","pipedrive_get_activities","pipedrive_get_all_deals","pipedrive_get_deal","pipedrive_get_files","pipedrive_get_leads","pipedrive_get_mail_messages","pipedrive_get_mail_thread","pipedrive_get_pipeline_deals","pipedrive_get_pipelines","pipedrive_get_projects","pipedrive_update_activity","pipedrive_update_deal","pipedrive_update_lead","polymarket_get_activity","polymarket_get_event","polymarket_get_events","polymarket_get_holders","polymarket_get_last_trade_price","polymarket_get_leaderboard","polymarket_get_market","polymarket_get_markets","polymarket_get_midpoint","polymarket_get_orderbook","polymarket_get_positions","polymarket_get_price","polymarket_get_price_history","polymarket_get_series","polymarket_get_series_by_id","polymarket_get_spread","polymarket_get_tags","polymarket_get_tick_size","polymarket_get_trades","polymarket_search","postgresql_delete","postgresql_execute","postgresql_insert","postgresql_introspect","postgresql_query","postgresql_update","posthog_batch_events","posthog_capture_event","posthog_create_annotation","posthog_create_cohort","posthog_create_dashboard","posthog_create_experiment","posthog_create_feature_flag","posthog_create_insight","posthog_create_survey","posthog_delete_feature_flag","posthog_delete_person","posthog_delete_survey","posthog_evaluate_flags","posthog_get_cohort","posthog_get_dashboard","posthog_get_event_definition","posthog_get_experiment","posthog_get_feature_flag","posthog_get_insight","posthog_get_organization","posthog_get_person","posthog_get_project","posthog_get_property_definition","posthog_get_session_recording","posthog_get_survey","posthog_list_actions","posthog_list_annotations","posthog_list_cohorts","posthog_list_dashboards","posthog_list_event_definitions","posthog_list_experiments","posthog_list_feature_flags","posthog_list_insights","posthog_list_organizations","posthog_list_persons","posthog_list_projects","posthog_list_property_definitions","posthog_list_recording_playlists","posthog_list_session_recordings","posthog_list_surveys","posthog_query","posthog_update_cohort","posthog_update_event_definition","posthog_update_experiment","posthog_update_feature_flag","posthog_update_insight","posthog_update_property_definition","posthog_update_survey","profound_bot_logs","profound_bots_report","profound_category_assets","profound_category_personas","profound_category_prompts","profound_category_tags","profound_category_topics","profound_citation_prompts","profound_citations_report","profound_list_assets","profound_list_categories","profound_list_domains","profound_list_models","profound_list_optimizations","profound_list_personas","profound_list_regions","profound_optimization_analysis","profound_prompt_answers","profound_prompt_volume","profound_query_fanouts","profound_raw_logs","profound_referrals_report","profound_sentiment_report","profound_visibility_report","prospeo_account_information","prospeo_bulk_enrich_company","prospeo_bulk_enrich_person","prospeo_enrich_company","prospeo_enrich_person","prospeo_search_company","prospeo_search_person","prospeo_search_suggestions","pulse_parser","pulse_parser_v2","qdrant_fetch_points","qdrant_search_vector","qdrant_upsert_points","quartr_get_audio","quartr_get_company","quartr_get_event","quartr_get_event_summary","quartr_get_report","quartr_get_slide_deck","quartr_get_transcript","quartr_list_audio","quartr_list_companies","quartr_list_document_types","quartr_list_documents","quartr_list_event_types","quartr_list_events","quartr_list_live_events","quartr_list_reports","quartr_list_slide_decks","quartr_list_transcripts","quiver_image_to_svg","quiver_list_models","quiver_text_to_svg","rabbitmq_create_binding","rabbitmq_create_exchange","rabbitmq_create_policy","rabbitmq_create_queue","rabbitmq_delete_binding","rabbitmq_delete_exchange","rabbitmq_delete_policy","rabbitmq_delete_queue","rabbitmq_get_exchange","rabbitmq_get_messages","rabbitmq_get_overview","rabbitmq_get_queue","rabbitmq_health_check","rabbitmq_list_bindings","rabbitmq_list_channels","rabbitmq_list_connections","rabbitmq_list_consumers","rabbitmq_list_exchange_bindings","rabbitmq_list_exchanges","rabbitmq_list_nodes","rabbitmq_list_policies","rabbitmq_list_queues","rabbitmq_list_vhosts","rabbitmq_publish_message","rabbitmq_purge_queue","railway_create_environment","railway_create_project","railway_create_service","railway_delete_environment","railway_delete_project","railway_delete_service","railway_delete_variable","railway_deploy_service","railway_get_deployment","railway_get_deployment_logs","railway_get_project","railway_list_deployments","railway_list_project_members","railway_list_projects","railway_list_variables","railway_restart_deployment","railway_rollback_deployment","railway_transfer_project","railway_update_project","railway_upsert_variable","rb2b_credit_check","rb2b_email_to_activity","rb2b_hem_to_best_linkedin","rb2b_hem_to_business_profile","rb2b_hem_to_linkedin","rb2b_hem_to_maid","rb2b_ip_to_company","rb2b_ip_to_hem","rb2b_ip_to_maid","rb2b_linkedin_slug_search","rb2b_linkedin_to_best_personal_email","rb2b_linkedin_to_business_profile","rb2b_linkedin_to_hashed_emails","rb2b_linkedin_to_mobile_phone","rb2b_linkedin_to_personal_email","rds_delete","rds_execute","rds_insert","rds_introspect","rds_query","rds_update","reddit_delete","reddit_edit","reddit_get_comments","reddit_get_controversial","reddit_get_info","reddit_get_me","reddit_get_messages","reddit_get_posts","reddit_get_saved","reddit_get_subreddit_info","reddit_get_subreddit_rules","reddit_get_user","reddit_get_user_comments","reddit_get_user_posts","reddit_hide","reddit_hot_posts","reddit_list_my_subreddits","reddit_lock","reddit_mark_all_read","reddit_mark_read","reddit_marknsfw","reddit_mod_approve","reddit_mod_distinguish","reddit_mod_remove","reddit_mod_sticky","reddit_reply","reddit_report","reddit_save","reddit_search","reddit_search_subreddits","reddit_send_message","reddit_submit_post","reddit_subscribe","reddit_unhide","reddit_unlock","reddit_unmarknsfw","reddit_unsave","reddit_vote","redis_command","redis_delete","redis_exists","redis_expire","redis_get","redis_hdel","redis_hget","redis_hgetall","redis_hset","redis_incr","redis_incrby","redis_keys","redis_llen","redis_lpop","redis_lpush","redis_lrange","redis_persist","redis_rpop","redis_rpush","redis_set","redis_setnx","redis_ttl","reducto_parser","reducto_parser_v2","resend_cancel_email","resend_create_audience","resend_create_broadcast","resend_create_contact","resend_delete_audience","resend_delete_contact","resend_get_audience","resend_get_broadcast","resend_get_contact","resend_get_email","resend_list_audiences","resend_list_contacts","resend_list_domains","resend_send","resend_send_broadcast","resend_update_contact","revenuecat_create_purchase","revenuecat_defer_google_subscription","revenuecat_delete_customer","revenuecat_get_customer","revenuecat_grant_entitlement","revenuecat_list_offerings","revenuecat_refund_google_subscription","revenuecat_revoke_entitlement","revenuecat_revoke_google_subscription","revenuecat_update_subscriber_attributes","rippling_bulk_create_custom_object_records","rippling_bulk_delete_custom_object_records","rippling_bulk_update_custom_object_records","rippling_create_business_partner","rippling_create_business_partner_group","rippling_create_custom_app","rippling_create_custom_object","rippling_create_custom_object_field","rippling_create_custom_object_record","rippling_create_custom_page","rippling_create_custom_setting","rippling_create_department","rippling_create_draft_hires","rippling_create_object_category","rippling_create_title","rippling_create_work_location","rippling_delete_business_partner","rippling_delete_business_partner_group","rippling_delete_custom_app","rippling_delete_custom_object","rippling_delete_custom_object_field","rippling_delete_custom_object_record","rippling_delete_custom_page","rippling_delete_custom_setting","rippling_delete_object_category","rippling_delete_title","rippling_delete_work_location","rippling_get_business_partner","rippling_get_business_partner_group","rippling_get_current_user","rippling_get_custom_app","rippling_get_custom_object","rippling_get_custom_object_field","rippling_get_custom_object_record","rippling_get_custom_object_record_by_external_id","rippling_get_custom_page","rippling_get_custom_setting","rippling_get_department","rippling_get_employment_type","rippling_get_job_function","rippling_get_object_category","rippling_get_report_run","rippling_get_supergroup","rippling_get_team","rippling_get_title","rippling_get_user","rippling_get_work_location","rippling_get_worker","rippling_list_business_partner_groups","rippling_list_business_partners","rippling_list_companies","rippling_list_custom_apps","rippling_list_custom_fields","rippling_list_custom_object_fields","rippling_list_custom_object_records","rippling_list_custom_objects","rippling_list_custom_pages","rippling_list_custom_settings","rippling_list_departments","rippling_list_employment_types","rippling_list_entitlements","rippling_list_job_functions","rippling_list_object_categories","rippling_list_supergroup_exclusion_members","rippling_list_supergroup_inclusion_members","rippling_list_supergroup_members","rippling_list_supergroups","rippling_list_teams","rippling_list_titles","rippling_list_users","rippling_list_work_locations","rippling_list_workers","rippling_query_custom_object_records","rippling_trigger_report_run","rippling_update_custom_app","rippling_update_custom_object","rippling_update_custom_object_field","rippling_update_custom_object_record","rippling_update_custom_page","rippling_update_custom_setting","rippling_update_department","rippling_update_object_category","rippling_update_supergroup_exclusion_members","rippling_update_supergroup_inclusion_members","rippling_update_title","rippling_update_work_location","rocketlane_add_field_option","rocketlane_add_project_members","rocketlane_add_task_assignees","rocketlane_add_task_dependencies","rocketlane_add_task_followers","rocketlane_archive_project","rocketlane_assign_placeholders","rocketlane_create_field","rocketlane_create_phase","rocketlane_create_project","rocketlane_create_space","rocketlane_create_space_document","rocketlane_create_task","rocketlane_create_time_entry","rocketlane_create_time_off","rocketlane_delete_field","rocketlane_delete_phase","rocketlane_delete_project","rocketlane_delete_space","rocketlane_delete_space_document","rocketlane_delete_task","rocketlane_delete_time_entry","rocketlane_delete_time_off","rocketlane_get_field","rocketlane_get_invoice","rocketlane_get_invoice_line_items","rocketlane_get_invoice_payments","rocketlane_get_phase","rocketlane_get_project","rocketlane_get_space","rocketlane_get_space_document","rocketlane_get_task","rocketlane_get_time_entry","rocketlane_get_time_off","rocketlane_get_user","rocketlane_import_template","rocketlane_list_fields","rocketlane_list_invoices","rocketlane_list_phases","rocketlane_list_placeholders","rocketlane_list_projects","rocketlane_list_resource_allocations","rocketlane_list_space_documents","rocketlane_list_spaces","rocketlane_list_tasks","rocketlane_list_time_entries","rocketlane_list_time_entry_categories","rocketlane_list_time_offs","rocketlane_list_users","rocketlane_move_task_to_phase","rocketlane_remove_project_members","rocketlane_remove_task_assignees","rocketlane_remove_task_dependencies","rocketlane_remove_task_followers","rocketlane_search_time_entries","rocketlane_unassign_placeholders","rocketlane_update_field","rocketlane_update_field_option","rocketlane_update_phase","rocketlane_update_project","rocketlane_update_space","rocketlane_update_space_document","rocketlane_update_task","rocketlane_update_time_entry","rootly_acknowledge_alert","rootly_add_incident_event","rootly_add_subscribers","rootly_assign_incident_role","rootly_create_action_item","rootly_create_alert","rootly_create_incident","rootly_create_status_page_event","rootly_delete_action_item","rootly_delete_incident","rootly_escalate_alert","rootly_get_alert","rootly_get_incident","rootly_list_action_items","rootly_list_alerts","rootly_list_causes","rootly_list_environments","rootly_list_escalation_policies","rootly_list_functionalities","rootly_list_incident_events","rootly_list_incident_roles","rootly_list_incident_types","rootly_list_incidents","rootly_list_on_calls","rootly_list_playbooks","rootly_list_retrospectives","rootly_list_schedules","rootly_list_services","rootly_list_severities","rootly_list_teams","rootly_list_users","rootly_mitigate_incident","rootly_remove_subscribers","rootly_resolve_alert","rootly_resolve_incident","rootly_run_workflow","rootly_snooze_alert","rootly_unassign_incident_role","rootly_update_action_item","rootly_update_alert","rootly_update_incident","s3_copy_object","s3_create_bucket","s3_delete_bucket","s3_delete_object","s3_delete_objects","s3_get_object","s3_head_object","s3_list_buckets","s3_list_objects","s3_presigned_url","s3_put_object","salesforce_create_account","salesforce_create_case","salesforce_create_contact","salesforce_create_custom_field","salesforce_create_custom_object","salesforce_create_lead","salesforce_create_opportunity","salesforce_create_task","salesforce_delete_account","salesforce_delete_case","salesforce_delete_contact","salesforce_delete_custom_field","salesforce_delete_lead","salesforce_delete_opportunity","salesforce_delete_task","salesforce_describe_object","salesforce_get_accounts","salesforce_get_cases","salesforce_get_contacts","salesforce_get_dashboard","salesforce_get_leads","salesforce_get_opportunities","salesforce_get_report","salesforce_get_tasks","salesforce_list_dashboards","salesforce_list_objects","salesforce_list_report_types","salesforce_list_reports","salesforce_query","salesforce_query_more","salesforce_refresh_dashboard","salesforce_run_report","salesforce_tooling_query","salesforce_update_account","salesforce_update_case","salesforce_update_contact","salesforce_update_custom_field","salesforce_update_lead","salesforce_update_opportunity","salesforce_update_task","sap_concur_approve_expense_report","sap_concur_associate_attendees","sap_concur_create_cash_advance","sap_concur_create_expected_expense","sap_concur_create_expense_report","sap_concur_create_list_item","sap_concur_create_purchase_request","sap_concur_create_quick_expense","sap_concur_create_quick_expense_with_image","sap_concur_create_report_comment","sap_concur_create_travel_request","sap_concur_create_user","sap_concur_delete_expected_expense","sap_concur_delete_expense","sap_concur_delete_expense_report","sap_concur_delete_list_item","sap_concur_delete_travel_request","sap_concur_delete_user","sap_concur_get_allocation","sap_concur_get_budget","sap_concur_get_cash_advance","sap_concur_get_expected_expense","sap_concur_get_expense","sap_concur_get_expense_report","sap_concur_get_itemizations","sap_concur_get_itinerary","sap_concur_get_list","sap_concur_get_list_item","sap_concur_get_purchase_request","sap_concur_get_receipt","sap_concur_get_receipt_status","sap_concur_get_request_cash_advance","sap_concur_get_travel_profile","sap_concur_get_travel_request","sap_concur_get_user","sap_concur_issue_cash_advance","sap_concur_list_allocations","sap_concur_list_attendee_associations","sap_concur_list_budget_categories","sap_concur_list_budgets","sap_concur_list_exceptions","sap_concur_list_expected_expenses","sap_concur_list_expense_reports","sap_concur_list_expenses","sap_concur_list_itineraries","sap_concur_list_list_items","sap_concur_list_lists","sap_concur_list_receipts","sap_concur_list_report_comments","sap_concur_list_reports_to_approve","sap_concur_list_travel_profiles_summary","sap_concur_list_travel_request_comments","sap_concur_list_travel_requests","sap_concur_list_users","sap_concur_move_travel_request","sap_concur_recall_expense_report","sap_concur_remove_all_attendees","sap_concur_search_locations","sap_concur_search_users","sap_concur_send_back_expense_report","sap_concur_submit_expense_report","sap_concur_update_allocation","sap_concur_update_expected_expense","sap_concur_update_expense","sap_concur_update_expense_report","sap_concur_update_list_item","sap_concur_update_travel_request","sap_concur_update_user","sap_concur_upload_exchange_rates","sap_concur_upload_receipt_image","sap_s4hana_create_business_partner","sap_s4hana_create_purchase_order","sap_s4hana_create_purchase_requisition","sap_s4hana_create_sales_order","sap_s4hana_delete_sales_order","sap_s4hana_get_billing_document","sap_s4hana_get_business_partner","sap_s4hana_get_customer","sap_s4hana_get_inbound_delivery","sap_s4hana_get_material_document","sap_s4hana_get_outbound_delivery","sap_s4hana_get_product","sap_s4hana_get_purchase_order","sap_s4hana_get_purchase_requisition","sap_s4hana_get_sales_order","sap_s4hana_get_supplier","sap_s4hana_get_supplier_invoice","sap_s4hana_list_billing_documents","sap_s4hana_list_business_partners","sap_s4hana_list_customers","sap_s4hana_list_inbound_deliveries","sap_s4hana_list_material_documents","sap_s4hana_list_material_stock","sap_s4hana_list_outbound_deliveries","sap_s4hana_list_products","sap_s4hana_list_purchase_orders","sap_s4hana_list_purchase_requisitions","sap_s4hana_list_sales_orders","sap_s4hana_list_supplier_invoices","sap_s4hana_list_suppliers","sap_s4hana_odata_query","sap_s4hana_update_business_partner","sap_s4hana_update_customer","sap_s4hana_update_product","sap_s4hana_update_purchase_order","sap_s4hana_update_purchase_requisition","sap_s4hana_update_sales_order","sap_s4hana_update_supplier","search_tool","secrets_manager_create_secret","secrets_manager_delete_secret","secrets_manager_describe_secret","secrets_manager_get_secret","secrets_manager_list_secrets","secrets_manager_restore_secret","secrets_manager_rotate_secret","secrets_manager_tag_resource","secrets_manager_untag_resource","secrets_manager_update_secret","sendblue_evaluate_service","sendblue_get_message","sendblue_send_group_message","sendblue_send_message","sendblue_send_typing_indicator","sendgrid_add_contact","sendgrid_add_contacts_to_list","sendgrid_create_list","sendgrid_create_template","sendgrid_create_template_version","sendgrid_delete_contacts","sendgrid_delete_list","sendgrid_delete_template","sendgrid_get_contact","sendgrid_get_list","sendgrid_get_template","sendgrid_list_all_lists","sendgrid_list_templates","sendgrid_remove_contacts_from_list","sendgrid_search_contacts","sendgrid_send_mail","sentry_events_get","sentry_events_list","sentry_issues_get","sentry_issues_list","sentry_issues_update","sentry_projects_create","sentry_projects_get","sentry_projects_list","sentry_projects_update","sentry_releases_create","sentry_releases_deploy","sentry_releases_list","sentry_teams_list","serper_search","servicenow_aggregate","servicenow_create_record","servicenow_delete_record","servicenow_download_attachment","servicenow_list_attachments","servicenow_read_record","servicenow_update_record","servicenow_upload_attachment","ses_create_configuration_set","ses_create_email_identity","ses_create_template","ses_delete_email_identity","ses_delete_suppressed_destination","ses_delete_template","ses_get_account","ses_get_email_identity","ses_get_suppressed_destination","ses_get_template","ses_list_identities","ses_list_suppressed_destinations","ses_list_templates","ses_put_suppressed_destination","ses_send_bulk_email","ses_send_custom_verification_email","ses_send_email","ses_send_templated_email","ses_update_template","sftp_delete","sftp_download","sftp_list","sftp_mkdir","sftp_upload","sharepoint_add_list_items","sharepoint_create_list","sharepoint_create_page","sharepoint_delete_file","sharepoint_delete_list_item","sharepoint_delete_page","sharepoint_download_file","sharepoint_get_drive_item","sharepoint_get_list","sharepoint_get_list_item","sharepoint_list_sites","sharepoint_publish_page","sharepoint_read_page","sharepoint_update_list","sharepoint_update_page","sharepoint_upload_file","shopify_adjust_inventory","shopify_cancel_order","shopify_create_customer","shopify_create_fulfillment","shopify_create_product","shopify_delete_customer","shopify_delete_product","shopify_get_collection","shopify_get_customer","shopify_get_inventory_level","shopify_get_order","shopify_get_product","shopify_list_collections","shopify_list_customers","shopify_list_inventory_items","shopify_list_locations","shopify_list_orders","shopify_list_products","shopify_update_customer","shopify_update_order","shopify_update_product","similarweb_bounce_rate","similarweb_page_views","similarweb_pages_per_visit","similarweb_traffic_visits","similarweb_visit_duration","similarweb_website_overview","sixtyfour_enrich_company","sixtyfour_enrich_lead","sixtyfour_find_email","sixtyfour_find_phone","slack_add_reaction","slack_archive_conversation","slack_canvas","slack_create_channel_canvas","slack_create_conversation","slack_delete_canvas","slack_delete_message","slack_delete_scheduled_message","slack_download","slack_edit_canvas","slack_ephemeral_message","slack_get_canvas","slack_get_channel_history","slack_get_channel_info","slack_get_message","slack_get_permalink","slack_get_thread","slack_get_thread_replies","slack_get_user","slack_get_user_presence","slack_invite_to_conversation","slack_list_canvases","slack_list_channels","slack_list_members","slack_list_scheduled_messages","slack_list_users","slack_lookup_canvas_sections","slack_message","slack_message_reader","slack_open_view","slack_publish_view","slack_push_view","slack_remove_reaction","slack_rename_conversation","slack_schedule_message","slack_set_conversation_purpose","slack_set_conversation_topic","slack_set_status","slack_set_suggested_prompts","slack_set_title","slack_update_message","slack_update_view","smartlead_add_email_accounts_to_campaign","smartlead_add_leads_to_campaign","smartlead_create_campaign","smartlead_create_lead_list","smartlead_delete_campaign","smartlead_delete_campaign_webhook","smartlead_delete_lead_from_campaign","smartlead_delete_lead_list","smartlead_duplicate_campaign","smartlead_export_campaign_leads","smartlead_get_campaign","smartlead_get_campaign_analytics","smartlead_get_campaign_analytics_by_date","smartlead_get_campaign_lead_statistics","smartlead_get_campaign_mailbox_statistics","smartlead_get_campaign_sequences","smartlead_get_campaign_statistics","smartlead_get_campaign_top_level_analytics_by_date","smartlead_get_campaign_webhook_summary","smartlead_get_lead_by_email","smartlead_get_lead_by_id","smartlead_get_lead_list","smartlead_get_lead_message_history","smartlead_list_campaign_email_accounts","smartlead_list_campaign_leads","smartlead_list_campaign_webhooks","smartlead_list_campaigns","smartlead_list_clients","smartlead_list_email_accounts","smartlead_list_inbox_replies","smartlead_list_lead_activities","smartlead_list_lead_categories","smartlead_list_lead_lists","smartlead_mark_lead_complete","smartlead_pause_lead","smartlead_remove_email_accounts_from_campaign","smartlead_resume_lead","smartlead_save_campaign_sequences","smartlead_unsubscribe_lead_from_campaign","smartlead_unsubscribe_lead_globally","smartlead_update_campaign_schedule","smartlead_update_campaign_settings","smartlead_update_campaign_status","smartlead_update_lead","smartlead_update_lead_category","smartlead_update_lead_list","smartlead_upsert_campaign_webhook","sms_send","smtp_send_mail","snowflake_alter_warehouse","snowflake_call_procedure","snowflake_cancel_statement","snowflake_cancel_task_run","snowflake_delete_rows","snowflake_execute_sql","snowflake_get_statement","snowflake_get_task","snowflake_get_task_run","snowflake_get_task_run_output","snowflake_get_warehouse","snowflake_insert_rows","snowflake_introspect_schema","snowflake_list_copy_history","snowflake_list_databases","snowflake_list_query_history","snowflake_list_schemas","snowflake_list_tables","snowflake_list_task_runs","snowflake_list_tasks","snowflake_list_warehouses","snowflake_load_data","snowflake_resume_task","snowflake_resume_warehouse","snowflake_run_task","snowflake_suspend_task","snowflake_suspend_warehouse","snowflake_unload_data","snowflake_update_rows","snowflake_upsert_rows","splunk_cancel_search_job","splunk_create_search_job","splunk_dispatch_saved_search","splunk_get_fired_alerts","splunk_get_saved_search","splunk_get_search_job","splunk_get_search_results","splunk_list_apps","splunk_list_fired_alerts","splunk_list_indexes","splunk_list_saved_searches","splunk_run_search","sportmonks_core_get_cities","sportmonks_core_get_city","sportmonks_core_get_continent","sportmonks_core_get_continents","sportmonks_core_get_countries","sportmonks_core_get_country","sportmonks_core_get_entity_filters","sportmonks_core_get_my_usage","sportmonks_core_get_region","sportmonks_core_get_regions","sportmonks_core_get_timezones","sportmonks_core_get_type","sportmonks_core_get_type_by_entity","sportmonks_core_get_types","sportmonks_core_search_cities","sportmonks_core_search_countries","sportmonks_core_search_regions","sportmonks_football_expected_by_player","sportmonks_football_expected_by_team","sportmonks_football_get_all_commentaries","sportmonks_football_get_all_fixtures","sportmonks_football_get_all_players","sportmonks_football_get_all_rivals","sportmonks_football_get_all_teams","sportmonks_football_get_all_transfer_rumours","sportmonks_football_get_all_transfers","sportmonks_football_get_brackets_by_season","sportmonks_football_get_coach","sportmonks_football_get_coaches","sportmonks_football_get_coaches_by_country","sportmonks_football_get_commentaries_by_fixture","sportmonks_football_get_current_leagues_by_team","sportmonks_football_get_expected_lineups_by_player","sportmonks_football_get_expected_lineups_by_team","sportmonks_football_get_extended_team_squad","sportmonks_football_get_fixture","sportmonks_football_get_fixtures_by_date","sportmonks_football_get_fixtures_by_date_range","sportmonks_football_get_fixtures_by_date_range_for_team","sportmonks_football_get_fixtures_by_ids","sportmonks_football_get_grouped_standings_by_round","sportmonks_football_get_head_to_head","sportmonks_football_get_inplay_livescores","sportmonks_football_get_latest_coaches","sportmonks_football_get_latest_fixtures","sportmonks_football_get_latest_livescores","sportmonks_football_get_latest_players","sportmonks_football_get_latest_totw","sportmonks_football_get_latest_transfers","sportmonks_football_get_league","sportmonks_football_get_leagues","sportmonks_football_get_leagues_by_country","sportmonks_football_get_leagues_by_date","sportmonks_football_get_leagues_by_team","sportmonks_football_get_live_leagues","sportmonks_football_get_live_probabilities","sportmonks_football_get_live_probabilities_by_fixture","sportmonks_football_get_live_standings_by_league","sportmonks_football_get_livescores","sportmonks_football_get_match_facts","sportmonks_football_get_match_facts_by_date_range","sportmonks_football_get_match_facts_by_fixture","sportmonks_football_get_match_facts_by_league","sportmonks_football_get_past_fixtures_by_tv_station","sportmonks_football_get_player","sportmonks_football_get_players_by_country","sportmonks_football_get_postmatch_news","sportmonks_football_get_postmatch_news_by_season","sportmonks_football_get_predictability_by_league","sportmonks_football_get_prematch_news","sportmonks_football_get_prematch_news_by_season","sportmonks_football_get_prematch_news_upcoming","sportmonks_football_get_probabilities","sportmonks_football_get_probabilities_by_fixture","sportmonks_football_get_referee","sportmonks_football_get_referees","sportmonks_football_get_referees_by_country","sportmonks_football_get_referees_by_season","sportmonks_football_get_rivals_by_team","sportmonks_football_get_round","sportmonks_football_get_round_statistics","sportmonks_football_get_rounds","sportmonks_football_get_rounds_by_season","sportmonks_football_get_schedules_by_season","sportmonks_football_get_schedules_by_season_and_team","sportmonks_football_get_schedules_by_team","sportmonks_football_get_season","sportmonks_football_get_seasons","sportmonks_football_get_seasons_by_team","sportmonks_football_get_stage","sportmonks_football_get_stage_statistics","sportmonks_football_get_stages","sportmonks_football_get_stages_by_season","sportmonks_football_get_standing_corrections_by_season","sportmonks_football_get_standings","sportmonks_football_get_standings_by_round","sportmonks_football_get_standings_by_season","sportmonks_football_get_state","sportmonks_football_get_states","sportmonks_football_get_team","sportmonks_football_get_team_rankings","sportmonks_football_get_team_rankings_by_date","sportmonks_football_get_team_rankings_by_team","sportmonks_football_get_team_squad","sportmonks_football_get_team_squad_by_season","sportmonks_football_get_teams_by_country","sportmonks_football_get_teams_by_season","sportmonks_football_get_topscorers_by_season","sportmonks_football_get_topscorers_by_stage","sportmonks_football_get_totw","sportmonks_football_get_totw_by_round","sportmonks_football_get_transfer","sportmonks_football_get_transfer_rumour","sportmonks_football_get_transfer_rumours_between_dates","sportmonks_football_get_transfer_rumours_by_player","sportmonks_football_get_transfer_rumours_by_team","sportmonks_football_get_transfers_between_dates","sportmonks_football_get_transfers_by_player","sportmonks_football_get_transfers_by_team","sportmonks_football_get_tv_station","sportmonks_football_get_tv_stations","sportmonks_football_get_tv_stations_by_fixture","sportmonks_football_get_upcoming_fixtures_by_market","sportmonks_football_get_upcoming_fixtures_by_tv_station","sportmonks_football_get_value_bets","sportmonks_football_get_value_bets_by_fixture","sportmonks_football_get_venue","sportmonks_football_get_venues","sportmonks_football_get_venues_by_season","sportmonks_football_search_coaches","sportmonks_football_search_fixtures","sportmonks_football_search_leagues","sportmonks_football_search_players","sportmonks_football_search_referees","sportmonks_football_search_rounds","sportmonks_football_search_seasons","sportmonks_football_search_stages","sportmonks_football_search_teams","sportmonks_football_search_venues","sportmonks_motorsport_get_all_fixtures","sportmonks_motorsport_get_current_leagues_by_team","sportmonks_motorsport_get_driver","sportmonks_motorsport_get_driver_standings","sportmonks_motorsport_get_driver_standings_by_season","sportmonks_motorsport_get_drivers","sportmonks_motorsport_get_drivers_by_country","sportmonks_motorsport_get_drivers_by_season","sportmonks_motorsport_get_fixture","sportmonks_motorsport_get_fixtures_by_date","sportmonks_motorsport_get_fixtures_by_date_range","sportmonks_motorsport_get_fixtures_by_ids","sportmonks_motorsport_get_laps_by_fixture","sportmonks_motorsport_get_laps_by_fixture_and_driver","sportmonks_motorsport_get_laps_by_fixture_and_lap","sportmonks_motorsport_get_latest_laps_by_fixture","sportmonks_motorsport_get_latest_pitstops_by_fixture","sportmonks_motorsport_get_latest_stints_by_fixture","sportmonks_motorsport_get_latest_updated_drivers","sportmonks_motorsport_get_latest_updated_fixtures","sportmonks_motorsport_get_league","sportmonks_motorsport_get_leagues","sportmonks_motorsport_get_leagues_by_country","sportmonks_motorsport_get_leagues_by_date","sportmonks_motorsport_get_leagues_by_live","sportmonks_motorsport_get_leagues_by_team","sportmonks_motorsport_get_livescores","sportmonks_motorsport_get_pitstops_by_fixture","sportmonks_motorsport_get_pitstops_by_fixture_and_driver","sportmonks_motorsport_get_pitstops_by_fixture_and_lap","sportmonks_motorsport_get_race_results_by_season_and_driver","sportmonks_motorsport_get_race_results_by_season_and_team","sportmonks_motorsport_get_schedules_by_season","sportmonks_motorsport_get_season","sportmonks_motorsport_get_seasons","sportmonks_motorsport_get_stage","sportmonks_motorsport_get_stages","sportmonks_motorsport_get_stages_by_season","sportmonks_motorsport_get_state","sportmonks_motorsport_get_states","sportmonks_motorsport_get_stints_by_fixture","sportmonks_motorsport_get_stints_by_fixture_and_driver","sportmonks_motorsport_get_stints_by_fixture_and_stint","sportmonks_motorsport_get_team","sportmonks_motorsport_get_team_standings","sportmonks_motorsport_get_team_standings_by_season","sportmonks_motorsport_get_teams","sportmonks_motorsport_get_teams_by_country","sportmonks_motorsport_get_teams_by_season","sportmonks_motorsport_get_venue","sportmonks_motorsport_get_venues","sportmonks_motorsport_get_venues_by_season","sportmonks_motorsport_search_drivers","sportmonks_motorsport_search_leagues","sportmonks_motorsport_search_stages","sportmonks_motorsport_search_teams","sportmonks_motorsport_search_venues","sportmonks_odds_get_all_historical_odds","sportmonks_odds_get_all_inplay_odds","sportmonks_odds_get_all_pre_match_odds","sportmonks_odds_get_all_premium_odds","sportmonks_odds_get_bookmaker","sportmonks_odds_get_bookmaker_event_ids_by_fixture","sportmonks_odds_get_bookmakers","sportmonks_odds_get_bookmakers_by_fixture","sportmonks_odds_get_inplay_odds_by_fixture","sportmonks_odds_get_inplay_odds_by_fixture_and_bookmaker","sportmonks_odds_get_inplay_odds_by_fixture_and_market","sportmonks_odds_get_last_updated_inplay_odds","sportmonks_odds_get_last_updated_pre_match_odds","sportmonks_odds_get_market","sportmonks_odds_get_markets","sportmonks_odds_get_pre_match_odds_by_fixture","sportmonks_odds_get_pre_match_odds_by_fixture_and_bookmaker","sportmonks_odds_get_pre_match_odds_by_fixture_and_market","sportmonks_odds_get_premium_odds_by_fixture","sportmonks_odds_get_premium_odds_by_fixture_and_bookmaker","sportmonks_odds_get_premium_odds_by_fixture_and_market","sportmonks_odds_get_updated_historical_odds_between","sportmonks_odds_get_updated_premium_odds_between","sportmonks_odds_search_bookmakers","sportmonks_odds_search_markets","spotify_add_playlist_cover","spotify_add_to_queue","spotify_add_tracks_to_playlist","spotify_check_following","spotify_check_playlist_followers","spotify_check_saved_albums","spotify_check_saved_audiobooks","spotify_check_saved_episodes","spotify_check_saved_shows","spotify_check_saved_tracks","spotify_create_playlist","spotify_follow_artists","spotify_follow_playlist","spotify_get_album","spotify_get_album_tracks","spotify_get_albums","spotify_get_artist","spotify_get_artist_albums","spotify_get_artist_top_tracks","spotify_get_artists","spotify_get_audiobook","spotify_get_audiobook_chapters","spotify_get_audiobooks","spotify_get_categories","spotify_get_current_user","spotify_get_currently_playing","spotify_get_devices","spotify_get_episode","spotify_get_episodes","spotify_get_followed_artists","spotify_get_markets","spotify_get_new_releases","spotify_get_playback_state","spotify_get_playlist","spotify_get_playlist_cover","spotify_get_playlist_tracks","spotify_get_queue","spotify_get_recently_played","spotify_get_saved_albums","spotify_get_saved_audiobooks","spotify_get_saved_episodes","spotify_get_saved_shows","spotify_get_saved_tracks","spotify_get_show","spotify_get_show_episodes","spotify_get_shows","spotify_get_top_artists","spotify_get_top_tracks","spotify_get_track","spotify_get_tracks","spotify_get_user_playlists","spotify_get_user_profile","spotify_pause","spotify_play","spotify_remove_saved_albums","spotify_remove_saved_audiobooks","spotify_remove_saved_episodes","spotify_remove_saved_shows","spotify_remove_saved_tracks","spotify_remove_tracks_from_playlist","spotify_reorder_playlist_items","spotify_replace_playlist_items","spotify_save_albums","spotify_save_audiobooks","spotify_save_episodes","spotify_save_shows","spotify_save_tracks","spotify_search","spotify_seek","spotify_set_repeat","spotify_set_shuffle","spotify_set_volume","spotify_skip_next","spotify_skip_previous","spotify_transfer_playback","spotify_unfollow_artists","spotify_unfollow_playlist","spotify_update_playlist","sqs_send","square_batch_retrieve_inventory_counts","square_cancel_invoice","square_cancel_payment","square_complete_payment","square_create_catalog_image","square_create_customer","square_create_invoice","square_create_order","square_create_payment","square_delete_catalog_object","square_delete_customer","square_delete_invoice","square_get_catalog_object","square_get_customer","square_get_invoice","square_get_location","square_get_order","square_get_payment","square_get_refund","square_list_catalog","square_list_customers","square_list_invoices","square_list_locations","square_list_payments","square_list_refunds","square_pay_order","square_publish_invoice","square_refund_payment","square_search_catalog_objects","square_search_customers","square_search_invoices","square_search_orders","square_update_customer","square_upsert_catalog_object","ssh_check_command_exists","ssh_check_file_exists","ssh_create_directory","ssh_delete_file","ssh_download_file","ssh_execute_command","ssh_execute_script","ssh_get_system_info","ssh_list_directory","ssh_move_rename","ssh_read_file_content","ssh_upload_file","ssh_write_file_content","stagehand_agent","stagehand_extract","stripe_cancel_payment_intent","stripe_cancel_subscription","stripe_capture_charge","stripe_capture_payment_intent","stripe_confirm_payment_intent","stripe_create_charge","stripe_create_customer","stripe_create_invoice","stripe_create_payment_intent","stripe_create_price","stripe_create_product","stripe_create_subscription","stripe_delete_customer","stripe_delete_invoice","stripe_delete_product","stripe_finalize_invoice","stripe_list_charges","stripe_list_customers","stripe_list_events","stripe_list_invoices","stripe_list_payment_intents","stripe_list_prices","stripe_list_products","stripe_list_subscriptions","stripe_pay_invoice","stripe_resume_subscription","stripe_retrieve_charge","stripe_retrieve_customer","stripe_retrieve_event","stripe_retrieve_invoice","stripe_retrieve_payment_intent","stripe_retrieve_price","stripe_retrieve_product","stripe_retrieve_subscription","stripe_search_charges","stripe_search_customers","stripe_search_invoices","stripe_search_payment_intents","stripe_search_prices","stripe_search_products","stripe_search_subscriptions","stripe_send_invoice","stripe_update_charge","stripe_update_customer","stripe_update_invoice","stripe_update_payment_intent","stripe_update_price","stripe_update_product","stripe_update_subscription","stripe_void_invoice","sts_assume_role","sts_assume_role_with_saml","sts_assume_role_with_web_identity","sts_get_access_key_info","sts_get_caller_identity","sts_get_session_token","stt_assemblyai","stt_assemblyai_v2","stt_deepgram","stt_deepgram_v2","stt_elevenlabs","stt_elevenlabs_v2","stt_gemini","stt_gemini_v2","stt_whisper","stt_whisper_v2","supabase_count","supabase_delete","supabase_get_row","supabase_insert","supabase_introspect","supabase_invoke_function","supabase_query","supabase_rpc","supabase_storage_copy","supabase_storage_create_bucket","supabase_storage_create_signed_upload_url","supabase_storage_create_signed_url","supabase_storage_delete","supabase_storage_delete_bucket","supabase_storage_download","supabase_storage_empty_bucket","supabase_storage_get_public_url","supabase_storage_list","supabase_storage_list_buckets","supabase_storage_move","supabase_storage_update_bucket","supabase_storage_upload","supabase_text_search","supabase_update","supabase_upsert","supabase_vector_search","table_batch_insert_rows","table_create","table_delete_row","table_delete_rows_by_filter","table_get_row","table_get_schema","table_insert_row","table_list","table_query_rows","table_query_rows_v2","table_update_row","table_update_rows_by_filter","table_upsert_row","tailscale_authorize_device","tailscale_create_auth_key","tailscale_delete_auth_key","tailscale_delete_device","tailscale_delete_user","tailscale_expire_device_key","tailscale_get_acl","tailscale_get_auth_key","tailscale_get_device","tailscale_get_device_routes","tailscale_get_dns_preferences","tailscale_get_dns_searchpaths","tailscale_list_auth_keys","tailscale_list_devices","tailscale_list_dns_nameservers","tailscale_list_users","tailscale_set_acl","tailscale_set_device_routes","tailscale_set_device_tags","tailscale_set_dns_nameservers","tailscale_set_dns_preferences","tailscale_set_dns_searchpaths","tailscale_suspend_user","tailscale_update_device_key","tavily_crawl","tavily_extract","tavily_map","tavily_search","telegram_copy_message","telegram_delete_message","telegram_edit_message_text","telegram_forward_message","telegram_get_chat","telegram_get_chat_member","telegram_message","telegram_pin_message","telegram_send_animation","telegram_send_audio","telegram_send_chat_action","telegram_send_contact","telegram_send_document","telegram_send_location","telegram_send_photo","telegram_send_poll","telegram_send_video","telegram_set_message_reaction","telegram_unpin_message","temporal_cancel_workflow","temporal_count_workflows","temporal_create_schedule","temporal_delete_schedule","temporal_describe_schedule","temporal_describe_task_queue","temporal_describe_workflow","temporal_get_workflow_history","temporal_list_schedules","temporal_list_workflows","temporal_pause_schedule","temporal_query_workflow","temporal_reset_workflow","temporal_signal_with_start","temporal_signal_workflow","temporal_start_workflow","temporal_terminate_workflow","temporal_trigger_schedule","temporal_unpause_schedule","temporal_update_workflow","textract_analyze_expense","textract_analyze_id","textract_parser","textract_parser_v2","thinking_tool","thrive_add_audience_managers","thrive_add_audience_members","thrive_add_user_tags","thrive_create_assignment","thrive_create_audience","thrive_create_completion","thrive_create_user","thrive_delete_assignment","thrive_delete_audience","thrive_delete_user","thrive_get_activity","thrive_get_assignment","thrive_get_audience","thrive_get_completion","thrive_get_content","thrive_get_cpd_category","thrive_get_cpd_entry","thrive_get_cpd_requirement","thrive_get_enrolment","thrive_get_skill_levels","thrive_get_tag","thrive_get_user_by_id","thrive_get_user_by_ref","thrive_list_assignments","thrive_list_audience_managers","thrive_list_audience_members","thrive_list_audiences","thrive_list_completions","thrive_list_enrolments","thrive_list_tags","thrive_query_activities","thrive_query_content","thrive_query_cpd_categories","thrive_query_cpd_entries","thrive_query_cpd_requirements","thrive_query_cpd_user_summaries","thrive_remove_audience_manager","thrive_remove_audience_member","thrive_remove_user_tags","thrive_replace_audience_managers","thrive_replace_audience_members","thrive_search_users","thrive_suspend_user","thrive_update_assignment","thrive_update_audience","thrive_update_user","thrive_update_user_skills","tiktok_get_post_status","tiktok_get_user","tiktok_list_videos","tiktok_query_videos","tiktok_upload_video_draft","tinybird_append_datasource","tinybird_delete_datasource_rows","tinybird_events","tinybird_get_job","tinybird_query","tinybird_query_pipe","tinybird_truncate_datasource","trello_add_checklist","trello_add_checklist_item","trello_add_comment","trello_add_label","trello_add_member","trello_create_board","trello_create_card","trello_create_list","trello_delete_card","trello_get_actions","trello_get_board","trello_get_card","trello_list_cards","trello_list_lists","trello_list_members","trello_remove_label","trello_remove_member","trello_search","trello_update_card","trello_update_checklist_item","trello_update_list","trigger_dev_activate_schedule","trigger_dev_add_run_tags","trigger_dev_batch_trigger_task","trigger_dev_cancel_run","trigger_dev_complete_waitpoint_token","trigger_dev_create_env_var","trigger_dev_create_schedule","trigger_dev_create_waitpoint_token","trigger_dev_deactivate_schedule","trigger_dev_delete_env_var","trigger_dev_delete_schedule","trigger_dev_execute_query","trigger_dev_get_batch","trigger_dev_get_batch_results","trigger_dev_get_deployment","trigger_dev_get_env_var","trigger_dev_get_latest_deployment","trigger_dev_get_query_schema","trigger_dev_get_queue","trigger_dev_get_run","trigger_dev_get_run_events","trigger_dev_get_run_result","trigger_dev_get_run_trace","trigger_dev_get_schedule","trigger_dev_get_waitpoint_token","trigger_dev_import_env_vars","trigger_dev_list_deployments","trigger_dev_list_env_vars","trigger_dev_list_queues","trigger_dev_list_runs","trigger_dev_list_schedules","trigger_dev_list_timezones","trigger_dev_list_waitpoint_tokens","trigger_dev_override_queue_concurrency","trigger_dev_pause_queue","trigger_dev_promote_deployment","trigger_dev_replay_run","trigger_dev_reschedule_run","trigger_dev_reset_queue_concurrency","trigger_dev_resume_queue","trigger_dev_trigger_task","trigger_dev_update_env_var","trigger_dev_update_run_metadata","trigger_dev_update_schedule","tts_azure","tts_cartesia","tts_deepgram","tts_elevenlabs","tts_google","tts_openai","tts_playht","twilio_send_sms","twilio_voice_get_recording","twilio_voice_list_calls","twilio_voice_make_call","typeform_create_form","typeform_delete_form","typeform_files","typeform_get_form","typeform_insights","typeform_list_forms","typeform_responses","typeform_update_form","upstash_redis_command","upstash_redis_delete","upstash_redis_exists","upstash_redis_expire","upstash_redis_get","upstash_redis_hget","upstash_redis_hgetall","upstash_redis_hset","upstash_redis_incr","upstash_redis_incrby","upstash_redis_keys","upstash_redis_lpush","upstash_redis_lrange","upstash_redis_set","upstash_redis_setnx","upstash_redis_ttl","uptimerobot_create_alert_contact","uptimerobot_create_maintenance_window","uptimerobot_create_monitor","uptimerobot_create_psp","uptimerobot_delete_alert_contact","uptimerobot_delete_maintenance_window","uptimerobot_delete_monitor","uptimerobot_delete_psp","uptimerobot_get_account","uptimerobot_get_alert_contact","uptimerobot_get_incident","uptimerobot_get_maintenance_window","uptimerobot_get_monitor","uptimerobot_get_psp","uptimerobot_list_alert_contacts","uptimerobot_list_incidents","uptimerobot_list_maintenance_windows","uptimerobot_list_monitors","uptimerobot_list_psps","uptimerobot_pause_monitor","uptimerobot_start_monitor","uptimerobot_update_maintenance_window","uptimerobot_update_monitor","uptimerobot_update_psp","vanta_download_document_file","vanta_get_control","vanta_get_document","vanta_get_framework","vanta_get_person","vanta_get_policy","vanta_get_risk_scenario","vanta_get_test","vanta_get_vendor","vanta_get_vulnerable_asset","vanta_list_control_documents","vanta_list_control_tests","vanta_list_controls","vanta_list_document_uploads","vanta_list_documents","vanta_list_framework_controls","vanta_list_frameworks","vanta_list_monitored_computers","vanta_list_people","vanta_list_policies","vanta_list_risk_scenarios","vanta_list_test_entities","vanta_list_tests","vanta_list_vendors","vanta_list_vulnerabilities","vanta_list_vulnerability_remediations","vanta_list_vulnerable_assets","vanta_submit_document","vanta_upload_document_file","vercel_add_domain","vercel_add_project_domain","vercel_cancel_deployment","vercel_create_alias","vercel_create_check","vercel_create_deployment","vercel_create_dns_record","vercel_create_edge_config","vercel_create_env_var","vercel_create_project","vercel_create_webhook","vercel_delete_alias","vercel_delete_deployment","vercel_delete_dns_record","vercel_delete_domain","vercel_delete_edge_config","vercel_delete_env_var","vercel_delete_project","vercel_delete_webhook","vercel_get_alias","vercel_get_check","vercel_get_deployment","vercel_get_deployment_events","vercel_get_domain","vercel_get_domain_config","vercel_get_edge_config","vercel_get_edge_config_items","vercel_get_env_vars","vercel_get_project","vercel_get_team","vercel_get_user","vercel_get_webhook","vercel_list_aliases","vercel_list_checks","vercel_list_deployment_files","vercel_list_deployments","vercel_list_dns_records","vercel_list_domains","vercel_list_edge_configs","vercel_list_project_domains","vercel_list_projects","vercel_list_team_members","vercel_list_teams","vercel_list_webhooks","vercel_pause_project","vercel_promote_deployment","vercel_remove_project_domain","vercel_rerequest_check","vercel_unpause_project","vercel_update_check","vercel_update_dns_record","vercel_update_edge_config_items","vercel_update_env_var","vercel_update_project","vercel_update_project_domain","vercel_verify_project_domain","video_falai","video_luma","video_minimax","video_runway","video_veo","vision_tool","vision_tool_v2","wealthbox_read_contact","wealthbox_read_note","wealthbox_read_task","wealthbox_write_contact","wealthbox_write_note","wealthbox_write_task","webflow_create_item","webflow_delete_item","webflow_get_item","webflow_list_items","webflow_update_item","webhook_request","whatsapp_get_media","whatsapp_mark_read","whatsapp_send_interactive","whatsapp_send_media","whatsapp_send_message","whatsapp_send_reaction","whatsapp_send_template","whatsapp_upload_media","wikipedia_content","wikipedia_random","wikipedia_search","wikipedia_summary","windchill_check_in_document","windchill_check_in_documents","windchill_check_out_document","windchill_check_out_documents","windchill_create_document","windchill_create_documents","windchill_delete_document","windchill_delete_documents","windchill_download_attachment","windchill_download_primary_content","windchill_get_document","windchill_get_document_structure","windchill_get_primary_content","windchill_get_valid_state_transitions","windchill_list_attachments","windchill_list_documents","windchill_revise_document","windchill_revise_documents","windchill_set_lifecycle_state","windchill_undo_check_out_document","windchill_undo_check_out_documents","windchill_update_common_properties","windchill_update_document","windchill_update_document_security_labels","windchill_update_documents","windchill_upload_attachments","windchill_upload_primary_content","wiza_company_enrichment","wiza_get_credits","wiza_individual_reveal","wiza_prospect_search","wordpress_create_category","wordpress_create_comment","wordpress_create_page","wordpress_create_post","wordpress_create_tag","wordpress_delete_category","wordpress_delete_comment","wordpress_delete_media","wordpress_delete_page","wordpress_delete_post","wordpress_delete_tag","wordpress_get_category","wordpress_get_current_user","wordpress_get_media","wordpress_get_page","wordpress_get_post","wordpress_get_tag","wordpress_get_user","wordpress_list_categories","wordpress_list_comments","wordpress_list_media","wordpress_list_pages","wordpress_list_posts","wordpress_list_tags","wordpress_list_users","wordpress_search_content","wordpress_update_category","wordpress_update_comment","wordpress_update_page","wordpress_update_post","wordpress_update_tag","wordpress_upload_media","workday_assign_onboarding","workday_change_job","workday_create_prehire","workday_get_compensation","workday_get_organizations","workday_get_worker","workday_hire_employee","workday_list_workers","workday_terminate_worker","workday_update_worker","workflow_executor","x_create_bookmark","x_create_tweet","x_delete_bookmark","x_delete_tweet","x_get_blocking","x_get_bookmarks","x_get_followers","x_get_following","x_get_liked_tweets","x_get_liking_users","x_get_me","x_get_personalized_trends","x_get_quote_tweets","x_get_retweeted_by","x_get_trends_by_woeid","x_get_tweets_by_ids","x_get_usage","x_get_user_mentions","x_get_user_timeline","x_get_user_tweets","x_hide_reply","x_manage_block","x_manage_follow","x_manage_like","x_manage_mute","x_manage_retweet","x_read","x_search","x_search_tweets","x_search_users","x_user","x_write","youtube_channel_info","youtube_channel_playlists","youtube_channel_videos","youtube_comments","youtube_playlist_items","youtube_search","youtube_trending","youtube_video_categories","youtube_video_details","zendesk_autocomplete_organizations","zendesk_create_organization","zendesk_create_organizations_bulk","zendesk_create_ticket","zendesk_create_tickets_bulk","zendesk_create_user","zendesk_create_users_bulk","zendesk_delete_organization","zendesk_delete_ticket","zendesk_delete_user","zendesk_get_current_user","zendesk_get_organization","zendesk_get_organizations","zendesk_get_ticket","zendesk_get_tickets","zendesk_get_user","zendesk_get_users","zendesk_merge_tickets","zendesk_search","zendesk_search_count","zendesk_search_users","zendesk_update_organization","zendesk_update_ticket","zendesk_update_tickets_bulk","zendesk_update_user","zendesk_update_users_bulk","zep_add_messages","zep_add_user","zep_create_thread","zep_delete_thread","zep_get_context","zep_get_messages","zep_get_threads","zep_get_user","zep_get_user_threads","zerobounce_get_credits","zerobounce_verify_email","zoho_desk_add_comment","zoho_desk_get_attachment","zoho_desk_get_contact","zoho_desk_get_thread","zoho_desk_get_ticket","zoho_desk_list_comments","zoho_desk_list_organizations","zoho_desk_list_threads","zoho_desk_list_tickets","zoho_desk_update_ticket","zoom_create_meeting","zoom_delete_meeting","zoom_delete_recording","zoom_get_meeting","zoom_get_meeting_invitation","zoom_get_meeting_recordings","zoom_list_meetings","zoom_list_past_participants","zoom_list_recordings","zoom_update_meeting","zoominfo_enrich_companies","zoominfo_enrich_contacts","zoominfo_search_companies","zoominfo_search_contacts","zoominfo_search_intent","zoominfo_search_news"]' ) export default toolIds diff --git a/apps/sim/tools/generated/tool-metadata.ts b/apps/sim/tools/generated/tool-metadata.ts index 97819b145f0..eba37fc3ca3 100644 --- a/apps/sim/tools/generated/tool-metadata.ts +++ b/apps/sim/tools/generated/tool-metadata.ts @@ -3,7 +3,7 @@ /** Serializable metadata for every built-in tool, keyed by tool id. */ const toolMetadata: Record = JSON.parse( - '{"a2a_cancel_task":{"id":"a2a_cancel_task","name":"A2A Cancel Task","description":"Request cancellation of an in-progress A2A task.","version":"1.0.0","params":{"agentUrl":{"type":"string","required":true,"visibility":"user-only","description":"The A2A agent endpoint URL"},"taskId":{"type":"string","required":true,"visibility":"user-or-llm","description":"The task ID to cancel"},"apiKey":{"type":"string","required":false,"visibility":"user-only","description":"API key for authentication (if required)"}}},"a2a_get_agent_card":{"id":"a2a_get_agent_card","name":"A2A Get Agent Card","description":"Fetch the Agent Card (discovery document) for an external A2A agent.","version":"1.0.0","params":{"agentUrl":{"type":"string","required":true,"visibility":"user-only","description":"The A2A agent endpoint URL"},"apiKey":{"type":"string","required":false,"visibility":"user-only","description":"API key for authentication (if required)"}}},"a2a_get_task":{"id":"a2a_get_task","name":"A2A Get Task","description":"Retrieve the current state and result of an A2A task.","version":"1.0.0","params":{"agentUrl":{"type":"string","required":true,"visibility":"user-only","description":"The A2A agent endpoint URL"},"taskId":{"type":"string","required":true,"visibility":"user-or-llm","description":"The task ID to retrieve"},"historyLength":{"type":"number","required":false,"visibility":"user-or-llm","description":"Maximum number of history messages to include"},"apiKey":{"type":"string","required":false,"visibility":"user-only","description":"API key for authentication (if required)"}}},"a2a_send_message":{"id":"a2a_send_message","name":"A2A Send Message","description":"Send a message to an external A2A agent and return its response.","version":"1.0.0","params":{"agentUrl":{"type":"string","required":true,"visibility":"user-only","description":"The A2A agent endpoint URL"},"message":{"type":"string","required":true,"visibility":"user-or-llm","description":"The message text to send"},"data":{"type":"json","required":false,"visibility":"user-or-llm","description":"Optional structured JSON data to attach"},"files":{"type":"json","required":false,"visibility":"user-or-llm","description":"Optional files to attach"},"taskId":{"type":"string","required":false,"visibility":"user-or-llm","description":"Existing task ID to continue"},"contextId":{"type":"string","required":false,"visibility":"user-or-llm","description":"Conversation context ID to continue"},"apiKey":{"type":"string","required":false,"visibility":"user-only","description":"API key for authentication (if required)"}}},"agentmail_create_draft":{"id":"agentmail_create_draft","name":"Create Draft","description":"Create a new email draft in AgentMail","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"AgentMail API key"},"inboxId":{"type":"string","required":true,"visibility":"user-or-llm","description":"ID of the inbox to create the draft in"},"to":{"type":"string","required":false,"visibility":"user-or-llm","description":"Recipient email addresses (comma-separated)"},"subject":{"type":"string","required":false,"visibility":"user-or-llm","description":"Draft subject line"},"text":{"type":"string","required":false,"visibility":"user-or-llm","description":"Plain text draft body"},"html":{"type":"string","required":false,"visibility":"user-or-llm","description":"HTML draft body"},"cc":{"type":"string","required":false,"visibility":"user-or-llm","description":"CC recipient email addresses (comma-separated)"},"bcc":{"type":"string","required":false,"visibility":"user-or-llm","description":"BCC recipient email addresses (comma-separated)"},"inReplyTo":{"type":"string","required":false,"visibility":"user-or-llm","description":"ID of message being replied to"},"sendAt":{"type":"string","required":false,"visibility":"user-or-llm","description":"ISO 8601 timestamp to schedule sending"}}},"agentmail_create_inbox":{"id":"agentmail_create_inbox","name":"Create Inbox","description":"Create a new email inbox with AgentMail","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"AgentMail API key"},"username":{"type":"string","required":false,"visibility":"user-or-llm","description":"Username for the inbox email address"},"domain":{"type":"string","required":false,"visibility":"user-or-llm","description":"Domain for the inbox email address"},"displayName":{"type":"string","required":false,"visibility":"user-or-llm","description":"Display name for the inbox"}}},"agentmail_delete_draft":{"id":"agentmail_delete_draft","name":"Delete Draft","description":"Delete an email draft in AgentMail","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"AgentMail API key"},"inboxId":{"type":"string","required":true,"visibility":"user-or-llm","description":"ID of the inbox containing the draft"},"draftId":{"type":"string","required":true,"visibility":"user-or-llm","description":"ID of the draft to delete"}}},"agentmail_delete_inbox":{"id":"agentmail_delete_inbox","name":"Delete Inbox","description":"Delete an email inbox in AgentMail","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"AgentMail API key"},"inboxId":{"type":"string","required":true,"visibility":"user-or-llm","description":"ID of the inbox to delete"}}},"agentmail_delete_thread":{"id":"agentmail_delete_thread","name":"Delete Thread","description":"Delete an email thread in AgentMail (moves to trash, or permanently deletes if already in trash)","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"AgentMail API key"},"inboxId":{"type":"string","required":true,"visibility":"user-or-llm","description":"ID of the inbox containing the thread"},"threadId":{"type":"string","required":true,"visibility":"user-or-llm","description":"ID of the thread to delete"},"permanent":{"type":"boolean","required":false,"visibility":"user-or-llm","description":"Force permanent deletion instead of moving to trash"}}},"agentmail_forward_message":{"id":"agentmail_forward_message","name":"Forward Message","description":"Forward an email message to new recipients in AgentMail","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"AgentMail API key"},"inboxId":{"type":"string","required":true,"visibility":"user-or-llm","description":"ID of the inbox containing the message"},"messageId":{"type":"string","required":true,"visibility":"user-or-llm","description":"ID of the message to forward"},"to":{"type":"string","required":true,"visibility":"user-or-llm","description":"Recipient email addresses (comma-separated)"},"subject":{"type":"string","required":false,"visibility":"user-or-llm","description":"Override subject line"},"text":{"type":"string","required":false,"visibility":"user-or-llm","description":"Additional plain text to prepend"},"html":{"type":"string","required":false,"visibility":"user-or-llm","description":"Additional HTML to prepend"},"cc":{"type":"string","required":false,"visibility":"user-or-llm","description":"CC recipient email addresses (comma-separated)"},"bcc":{"type":"string","required":false,"visibility":"user-or-llm","description":"BCC recipient email addresses (comma-separated)"}}},"agentmail_get_draft":{"id":"agentmail_get_draft","name":"Get Draft","description":"Get details of a specific email draft in AgentMail","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"AgentMail API key"},"inboxId":{"type":"string","required":true,"visibility":"user-or-llm","description":"ID of the inbox the draft belongs to"},"draftId":{"type":"string","required":true,"visibility":"user-or-llm","description":"ID of the draft to retrieve"}}},"agentmail_get_inbox":{"id":"agentmail_get_inbox","name":"Get Inbox","description":"Get details of a specific email inbox in AgentMail","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"AgentMail API key"},"inboxId":{"type":"string","required":true,"visibility":"user-or-llm","description":"ID of the inbox to retrieve"}}},"agentmail_get_message":{"id":"agentmail_get_message","name":"Get Message","description":"Get details of a specific email message in AgentMail","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"AgentMail API key"},"inboxId":{"type":"string","required":true,"visibility":"user-or-llm","description":"ID of the inbox containing the message"},"messageId":{"type":"string","required":true,"visibility":"user-or-llm","description":"ID of the message to retrieve"}}},"agentmail_get_thread":{"id":"agentmail_get_thread","name":"Get Thread","description":"Get details of a specific email thread including messages in AgentMail","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"AgentMail API key"},"inboxId":{"type":"string","required":true,"visibility":"user-or-llm","description":"ID of the inbox containing the thread"},"threadId":{"type":"string","required":true,"visibility":"user-or-llm","description":"ID of the thread to retrieve"}}},"agentmail_list_drafts":{"id":"agentmail_list_drafts","name":"List Drafts","description":"List email drafts in an inbox in AgentMail","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"AgentMail API key"},"inboxId":{"type":"string","required":true,"visibility":"user-or-llm","description":"ID of the inbox to list drafts from"},"limit":{"type":"number","required":false,"visibility":"user-or-llm","description":"Maximum number of drafts to return"},"pageToken":{"type":"string","required":false,"visibility":"user-or-llm","description":"Pagination token for next page of results"}}},"agentmail_list_inboxes":{"id":"agentmail_list_inboxes","name":"List Inboxes","description":"List all email inboxes in AgentMail","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"AgentMail API key"},"limit":{"type":"number","required":false,"visibility":"user-or-llm","description":"Maximum number of inboxes to return"},"pageToken":{"type":"string","required":false,"visibility":"user-or-llm","description":"Pagination token for next page of results"}}},"agentmail_list_messages":{"id":"agentmail_list_messages","name":"List Messages","description":"List messages in an inbox in AgentMail","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"AgentMail API key"},"inboxId":{"type":"string","required":true,"visibility":"user-or-llm","description":"ID of the inbox to list messages from"},"limit":{"type":"number","required":false,"visibility":"user-or-llm","description":"Maximum number of messages to return"},"pageToken":{"type":"string","required":false,"visibility":"user-or-llm","description":"Pagination token for next page of results"}}},"agentmail_list_threads":{"id":"agentmail_list_threads","name":"List Threads","description":"List email threads in AgentMail","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"AgentMail API key"},"inboxId":{"type":"string","required":true,"visibility":"user-or-llm","description":"ID of the inbox to list threads from"},"limit":{"type":"number","required":false,"visibility":"user-or-llm","description":"Maximum number of threads to return"},"pageToken":{"type":"string","required":false,"visibility":"user-or-llm","description":"Pagination token for next page of results"},"labels":{"type":"string","required":false,"visibility":"user-or-llm","description":"Comma-separated labels to filter threads by"},"before":{"type":"string","required":false,"visibility":"user-or-llm","description":"Filter threads before this ISO 8601 timestamp"},"after":{"type":"string","required":false,"visibility":"user-or-llm","description":"Filter threads after this ISO 8601 timestamp"}}},"agentmail_reply_message":{"id":"agentmail_reply_message","name":"Reply to Message","description":"Reply to an existing email message in AgentMail","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"AgentMail API key"},"inboxId":{"type":"string","required":true,"visibility":"user-or-llm","description":"ID of the inbox to reply from"},"messageId":{"type":"string","required":true,"visibility":"user-or-llm","description":"ID of the message to reply to"},"text":{"type":"string","required":false,"visibility":"user-or-llm","description":"Plain text reply body"},"html":{"type":"string","required":false,"visibility":"user-or-llm","description":"HTML reply body"},"to":{"type":"string","required":false,"visibility":"user-or-llm","description":"Override recipient email addresses (comma-separated)"},"cc":{"type":"string","required":false,"visibility":"user-or-llm","description":"CC email addresses (comma-separated)"},"bcc":{"type":"string","required":false,"visibility":"user-or-llm","description":"BCC email addresses (comma-separated)"},"replyAll":{"type":"boolean","required":false,"visibility":"user-or-llm","description":"Reply to all recipients of the original message"}}},"agentmail_send_draft":{"id":"agentmail_send_draft","name":"Send Draft","description":"Send an existing email draft in AgentMail","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"AgentMail API key"},"inboxId":{"type":"string","required":true,"visibility":"user-or-llm","description":"ID of the inbox containing the draft"},"draftId":{"type":"string","required":true,"visibility":"user-or-llm","description":"ID of the draft to send"}}},"agentmail_send_message":{"id":"agentmail_send_message","name":"Send Message","description":"Send an email message from an AgentMail inbox","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"AgentMail API key"},"inboxId":{"type":"string","required":true,"visibility":"user-or-llm","description":"ID of the inbox to send from"},"to":{"type":"string","required":true,"visibility":"user-or-llm","description":"Recipient email address (comma-separated for multiple)"},"subject":{"type":"string","required":true,"visibility":"user-or-llm","description":"Email subject line"},"text":{"type":"string","required":false,"visibility":"user-or-llm","description":"Plain text email body"},"html":{"type":"string","required":false,"visibility":"user-or-llm","description":"HTML email body"},"cc":{"type":"string","required":false,"visibility":"user-or-llm","description":"CC recipient email addresses (comma-separated)"},"bcc":{"type":"string","required":false,"visibility":"user-or-llm","description":"BCC recipient email addresses (comma-separated)"}}},"agentmail_update_draft":{"id":"agentmail_update_draft","name":"Update Draft","description":"Update an existing email draft in AgentMail","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"AgentMail API key"},"inboxId":{"type":"string","required":true,"visibility":"user-or-llm","description":"ID of the inbox containing the draft"},"draftId":{"type":"string","required":true,"visibility":"user-or-llm","description":"ID of the draft to update"},"to":{"type":"string","required":false,"visibility":"user-or-llm","description":"Recipient email addresses (comma-separated)"},"subject":{"type":"string","required":false,"visibility":"user-or-llm","description":"Draft subject line"},"text":{"type":"string","required":false,"visibility":"user-or-llm","description":"Plain text draft body"},"html":{"type":"string","required":false,"visibility":"user-or-llm","description":"HTML draft body"},"cc":{"type":"string","required":false,"visibility":"user-or-llm","description":"CC recipient email addresses (comma-separated)"},"bcc":{"type":"string","required":false,"visibility":"user-or-llm","description":"BCC recipient email addresses (comma-separated)"},"sendAt":{"type":"string","required":false,"visibility":"user-or-llm","description":"ISO 8601 timestamp to schedule sending"}}},"agentmail_update_inbox":{"id":"agentmail_update_inbox","name":"Update Inbox","description":"Update the display name of an email inbox in AgentMail","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"AgentMail API key"},"inboxId":{"type":"string","required":true,"visibility":"user-or-llm","description":"ID of the inbox to update"},"displayName":{"type":"string","required":true,"visibility":"user-or-llm","description":"New display name for the inbox"}}},"agentmail_update_message":{"id":"agentmail_update_message","name":"Update Message","description":"Add or remove labels on an email message in AgentMail","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"AgentMail API key"},"inboxId":{"type":"string","required":true,"visibility":"user-or-llm","description":"ID of the inbox containing the message"},"messageId":{"type":"string","required":true,"visibility":"user-or-llm","description":"ID of the message to update"},"addLabels":{"type":"string","required":false,"visibility":"user-or-llm","description":"Comma-separated labels to add to the message"},"removeLabels":{"type":"string","required":false,"visibility":"user-or-llm","description":"Comma-separated labels to remove from the message"}}},"agentmail_update_thread":{"id":"agentmail_update_thread","name":"Update Thread Labels","description":"Add or remove labels on an email thread in AgentMail","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"AgentMail API key"},"inboxId":{"type":"string","required":true,"visibility":"user-or-llm","description":"ID of the inbox containing the thread"},"threadId":{"type":"string","required":true,"visibility":"user-or-llm","description":"ID of the thread to update"},"addLabels":{"type":"string","required":false,"visibility":"user-or-llm","description":"Comma-separated labels to add to the thread"},"removeLabels":{"type":"string","required":false,"visibility":"user-or-llm","description":"Comma-separated labels to remove from the thread"}}},"agentphone_create_call":{"id":"agentphone_create_call","name":"Create Outbound Call","description":"Initiate an outbound voice call from an AgentPhone agent","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"AgentPhone API key"},"agentId":{"type":"string","required":true,"visibility":"user-or-llm","description":"Agent that will handle the call"},"toNumber":{"type":"string","required":true,"visibility":"user-or-llm","description":"Phone number to call in E.164 format (e.g. +14155551234)"},"fromNumberId":{"type":"string","required":false,"visibility":"user-or-llm","description":"Phone number ID to use as caller ID. Must belong to the agent. If omitted, the agent\'s first assigned number is used."},"initialGreeting":{"type":"string","required":false,"visibility":"user-or-llm","description":"Optional greeting spoken when the recipient answers"},"voice":{"type":"string","required":false,"visibility":"user-or-llm","description":"Voice ID override for this call (defaults to the agent\'s configured voice)"},"systemPrompt":{"type":"string","required":false,"visibility":"user-or-llm","description":"When provided, uses a built-in LLM for the conversation instead of forwarding to your webhook"}}},"agentphone_create_contact":{"id":"agentphone_create_contact","name":"Create Contact","description":"Create a new contact in AgentPhone","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"AgentPhone API key"},"phoneNumber":{"type":"string","required":true,"visibility":"user-or-llm","description":"Phone number in E.164 format (e.g. +14155551234)"},"name":{"type":"string","required":true,"visibility":"user-or-llm","description":"Contact\'s full name"},"email":{"type":"string","required":false,"visibility":"user-or-llm","description":"Contact\'s email address"},"notes":{"type":"string","required":false,"visibility":"user-or-llm","description":"Freeform notes stored on the contact"}}},"agentphone_create_number":{"id":"agentphone_create_number","name":"Create Phone Number","description":"Provision a new SMS- and voice-enabled phone number","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"AgentPhone API key"},"country":{"type":"string","required":false,"visibility":"user-or-llm","description":"Two-letter country code (e.g. US, CA). Defaults to US."},"areaCode":{"type":"string","required":false,"visibility":"user-or-llm","description":"Preferred area code (US/CA only, e.g. \\"415\\"). Best-effort — may be ignored if unavailable."},"agentId":{"type":"string","required":false,"visibility":"user-or-llm","description":"Optionally attach the number to an agent immediately"}}},"agentphone_delete_contact":{"id":"agentphone_delete_contact","name":"Delete Contact","description":"Delete a contact by ID","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"AgentPhone API key"},"contactId":{"type":"string","required":true,"visibility":"user-or-llm","description":"Contact ID"}}},"agentphone_get_call":{"id":"agentphone_get_call","name":"Get Call","description":"Fetch a call and its full transcript","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"AgentPhone API key"},"callId":{"type":"string","required":true,"visibility":"user-or-llm","description":"ID of the call to retrieve"}}},"agentphone_get_call_transcript":{"id":"agentphone_get_call_transcript","name":"Get Call Transcript","description":"Get the full ordered transcript for a call","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"AgentPhone API key"},"callId":{"type":"string","required":true,"visibility":"user-or-llm","description":"ID of the call to retrieve the transcript for"}}},"agentphone_get_contact":{"id":"agentphone_get_contact","name":"Get Contact","description":"Fetch a single contact by ID","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"AgentPhone API key"},"contactId":{"type":"string","required":true,"visibility":"user-or-llm","description":"Contact ID"}}},"agentphone_get_conversation":{"id":"agentphone_get_conversation","name":"Get Conversation","description":"Get a conversation along with its recent messages","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"AgentPhone API key"},"conversationId":{"type":"string","required":true,"visibility":"user-or-llm","description":"Conversation ID"},"messageLimit":{"type":"number","required":false,"visibility":"user-or-llm","description":"Number of recent messages to include (default 50, max 100)"}}},"agentphone_get_conversation_messages":{"id":"agentphone_get_conversation_messages","name":"Get Conversation Messages","description":"Get paginated messages for a conversation","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"AgentPhone API key"},"conversationId":{"type":"string","required":true,"visibility":"user-or-llm","description":"Conversation ID"},"limit":{"type":"number","required":false,"visibility":"user-or-llm","description":"Number of messages to return (default 50, max 200)"},"before":{"type":"string","required":false,"visibility":"user-or-llm","description":"Return messages received before this ISO 8601 timestamp"},"after":{"type":"string","required":false,"visibility":"user-or-llm","description":"Return messages received after this ISO 8601 timestamp"}}},"agentphone_get_number_messages":{"id":"agentphone_get_number_messages","name":"Get Phone Number Messages","description":"Fetch messages received on a specific phone number","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"AgentPhone API key"},"numberId":{"type":"string","required":true,"visibility":"user-or-llm","description":"ID of the phone number"},"limit":{"type":"number","required":false,"visibility":"user-or-llm","description":"Number of messages to return (default 50, max 200)"},"before":{"type":"string","required":false,"visibility":"user-or-llm","description":"Return messages received before this ISO 8601 timestamp"},"after":{"type":"string","required":false,"visibility":"user-or-llm","description":"Return messages received after this ISO 8601 timestamp"}}},"agentphone_get_usage":{"id":"agentphone_get_usage","name":"Get Usage","description":"Retrieve current usage statistics for the AgentPhone account","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"AgentPhone API key"}}},"agentphone_get_usage_daily":{"id":"agentphone_get_usage_daily","name":"Get Daily Usage","description":"Get a daily breakdown of usage (messages, calls, webhooks) for the last N days","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"AgentPhone API key"},"days":{"type":"number","required":false,"visibility":"user-or-llm","description":"Number of days to return (1-365, default 30)"}}},"agentphone_get_usage_monthly":{"id":"agentphone_get_usage_monthly","name":"Get Monthly Usage","description":"Get monthly usage aggregation (messages, calls, webhooks) for the last N months","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"AgentPhone API key"},"months":{"type":"number","required":false,"visibility":"user-or-llm","description":"Number of months to return (1-24, default 6)"}}},"agentphone_list_calls":{"id":"agentphone_list_calls","name":"List Calls","description":"List voice calls for this AgentPhone account","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"AgentPhone API key"},"limit":{"type":"number","required":false,"visibility":"user-or-llm","description":"Number of results to return (default 20, max 100)"},"offset":{"type":"number","required":false,"visibility":"user-or-llm","description":"Number of results to skip (min 0)"},"status":{"type":"string","required":false,"visibility":"user-or-llm","description":"Filter by status (completed, in-progress, failed)"},"direction":{"type":"string","required":false,"visibility":"user-or-llm","description":"Filter by direction (inbound, outbound)"},"type":{"type":"string","required":false,"visibility":"user-or-llm","description":"Filter by call type (pstn, web)"},"search":{"type":"string","required":false,"visibility":"user-or-llm","description":"Search by phone number (matches fromNumber or toNumber)"}}},"agentphone_list_contacts":{"id":"agentphone_list_contacts","name":"List Contacts","description":"List contacts for this AgentPhone account","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"AgentPhone API key"},"search":{"type":"string","required":false,"visibility":"user-or-llm","description":"Filter by name or phone number (case-insensitive contains)"},"limit":{"type":"number","required":false,"visibility":"user-or-llm","description":"Number of results to return (default 50, max 200)"},"offset":{"type":"number","required":false,"visibility":"user-or-llm","description":"Number of results to skip (min 0)"}}},"agentphone_list_conversations":{"id":"agentphone_list_conversations","name":"List Conversations","description":"List conversations (message threads) for this AgentPhone account","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"AgentPhone API key"},"limit":{"type":"number","required":false,"visibility":"user-or-llm","description":"Number of results to return (default 20, max 100)"},"offset":{"type":"number","required":false,"visibility":"user-or-llm","description":"Number of results to skip (min 0)"}}},"agentphone_list_numbers":{"id":"agentphone_list_numbers","name":"List Phone Numbers","description":"List all phone numbers provisioned for this AgentPhone account","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"AgentPhone API key"},"limit":{"type":"number","required":false,"visibility":"user-or-llm","description":"Number of results to return (default 20, max 100)"},"offset":{"type":"number","required":false,"visibility":"user-or-llm","description":"Number of results to skip (min 0)"}}},"agentphone_react_to_message":{"id":"agentphone_react_to_message","name":"React to Message","description":"Send an iMessage tapback reaction to a message (iMessage only)","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"AgentPhone API key"},"messageId":{"type":"string","required":true,"visibility":"user-or-llm","description":"ID of the message to react to"},"reaction":{"type":"string","required":true,"visibility":"user-or-llm","description":"Reaction type: love, like, dislike, laugh, emphasize, or question"}}},"agentphone_release_number":{"id":"agentphone_release_number","name":"Release Phone Number","description":"Release (delete) a phone number. This action is irreversible.","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"AgentPhone API key"},"numberId":{"type":"string","required":true,"visibility":"user-or-llm","description":"ID of the phone number to release"}}},"agentphone_send_message":{"id":"agentphone_send_message","name":"Send Message","description":"Send an outbound SMS or iMessage from an AgentPhone agent","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"AgentPhone API key"},"agentId":{"type":"string","required":true,"visibility":"user-or-llm","description":"Agent sending the message"},"toNumber":{"type":"string","required":true,"visibility":"user-or-llm","description":"Recipient phone number in E.164 format (e.g. +14155551234)"},"body":{"type":"string","required":true,"visibility":"user-or-llm","description":"Message text to send"},"mediaUrl":{"type":"string","required":false,"visibility":"user-or-llm","description":"Optional URL of an image, video, or file to attach"},"numberId":{"type":"string","required":false,"visibility":"user-or-llm","description":"Phone number ID to send from. If omitted, the agent\'s first assigned number is used."}}},"agentphone_update_contact":{"id":"agentphone_update_contact","name":"Update Contact","description":"Update a contact\'s fields","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"AgentPhone API key"},"contactId":{"type":"string","required":true,"visibility":"user-or-llm","description":"Contact ID"},"phoneNumber":{"type":"string","required":false,"visibility":"user-or-llm","description":"New phone number in E.164 format"},"name":{"type":"string","required":false,"visibility":"user-or-llm","description":"New contact name"},"email":{"type":"string","required":false,"visibility":"user-or-llm","description":"New email address"},"notes":{"type":"string","required":false,"visibility":"user-or-llm","description":"New freeform notes"}}},"agentphone_update_conversation":{"id":"agentphone_update_conversation","name":"Update Conversation","description":"Update conversation metadata (stored state). Pass null to clear existing metadata.","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"AgentPhone API key"},"conversationId":{"type":"string","required":true,"visibility":"user-or-llm","description":"Conversation ID"},"metadata":{"type":"json","required":false,"visibility":"user-or-llm","description":"Custom key-value metadata to store on the conversation. Pass null to clear existing metadata."}}},"agiloft_async_status":{"id":"agiloft_async_status","name":"Agiloft Async Status","description":"Check whether an asynchronous Agiloft call, such as a run action button, has completed.","version":"1.0.0","params":{"instanceUrl":{"type":"string","required":true,"visibility":"user-only","description":"Agiloft instance URL (e.g., https://mycompany.agiloft.com)"},"knowledgeBase":{"type":"string","required":true,"visibility":"user-only","description":"Knowledge base name"},"login":{"type":"string","required":true,"visibility":"user-only","description":"Agiloft username"},"password":{"type":"string","required":true,"visibility":"user-only","description":"Agiloft password"},"table":{"type":"string","required":true,"visibility":"user-or-llm","description":"Table the asynchronous call was made against"},"callbackId":{"type":"string","required":true,"visibility":"user-or-llm","description":"Callback ID returned by the asynchronous call, e.g. from Run Action Button"}}},"agiloft_attach_file":{"id":"agiloft_attach_file","name":"Agiloft Attach File","description":"Attach a file to a field in an Agiloft record.","version":"1.0.0","params":{"instanceUrl":{"type":"string","required":true,"visibility":"user-only","description":"Agiloft instance URL (e.g., https://mycompany.agiloft.com)"},"knowledgeBase":{"type":"string","required":true,"visibility":"user-only","description":"Knowledge base name"},"login":{"type":"string","required":true,"visibility":"user-only","description":"Agiloft username"},"password":{"type":"string","required":true,"visibility":"user-only","description":"Agiloft password"},"table":{"type":"string","required":true,"visibility":"user-or-llm","description":"Table name (e.g., \\"contracts\\")"},"recordId":{"type":"string","required":true,"visibility":"user-or-llm","description":"ID of the record to attach the file to"},"fieldName":{"type":"string","required":true,"visibility":"user-or-llm","description":"Name of the attachment field"},"file":{"type":"file","required":true,"visibility":"user-or-llm","description":"File to attach"},"fileName":{"type":"string","required":false,"visibility":"user-or-llm","description":"Name to assign to the file (defaults to original file name)"},"overwrite":{"type":"boolean","required":false,"visibility":"user-or-llm","description":"Replace the contents of the field instead of adding another file to it"}}},"agiloft_attachment_info":{"id":"agiloft_attachment_info","name":"Agiloft Attachment Info","description":"Get information about file attachments on a record field.","version":"1.0.0","params":{"instanceUrl":{"type":"string","required":true,"visibility":"user-only","description":"Agiloft instance URL (e.g., https://mycompany.agiloft.com)"},"knowledgeBase":{"type":"string","required":true,"visibility":"user-only","description":"Knowledge base name"},"login":{"type":"string","required":true,"visibility":"user-only","description":"Agiloft username"},"password":{"type":"string","required":true,"visibility":"user-only","description":"Agiloft password"},"table":{"type":"string","required":true,"visibility":"user-or-llm","description":"Table name (e.g., \\"contracts\\")"},"recordId":{"type":"string","required":true,"visibility":"user-or-llm","description":"ID of the record to check attachments on"},"fieldName":{"type":"string","required":true,"visibility":"user-or-llm","description":"Name of the attachment field to inspect"}}},"agiloft_create_record":{"id":"agiloft_create_record","name":"Agiloft Create Record","description":"Create a new record in an Agiloft table.","version":"1.0.0","params":{"instanceUrl":{"type":"string","required":true,"visibility":"user-only","description":"Agiloft instance URL (e.g., https://mycompany.agiloft.com)"},"knowledgeBase":{"type":"string","required":true,"visibility":"user-only","description":"Knowledge base name"},"login":{"type":"string","required":true,"visibility":"user-only","description":"Agiloft username"},"password":{"type":"string","required":true,"visibility":"user-only","description":"Agiloft password"},"table":{"type":"string","required":true,"visibility":"user-or-llm","description":"Table name (e.g., \\"contracts\\", \\"contacts.employees\\")"},"data":{"type":"string","required":true,"visibility":"user-or-llm","description":"Record field values as a JSON object (e.g., {\\"first_name\\": \\"John\\", \\"status\\": \\"Active\\"})"}}},"agiloft_delete_record":{"id":"agiloft_delete_record","name":"Agiloft Delete Record","description":"Delete a record from an Agiloft table.","version":"1.0.0","params":{"instanceUrl":{"type":"string","required":true,"visibility":"user-only","description":"Agiloft instance URL (e.g., https://mycompany.agiloft.com)"},"knowledgeBase":{"type":"string","required":true,"visibility":"user-only","description":"Knowledge base name"},"login":{"type":"string","required":true,"visibility":"user-only","description":"Agiloft username"},"password":{"type":"string","required":true,"visibility":"user-only","description":"Agiloft password"},"table":{"type":"string","required":true,"visibility":"user-or-llm","description":"Table name (e.g., \\"contracts\\", \\"contacts.employees\\")"},"recordId":{"type":"string","required":true,"visibility":"user-or-llm","description":"ID of the record to delete"},"substituteIds":{"type":"string","required":false,"visibility":"user-or-llm","description":"Comma-separated IDs of records that adopt the dependants of the deleted record. Read only when the delete rule is REPLACE_WITH_ANOTHER."},"deleteRule":{"type":"string","required":false,"visibility":"user-or-llm","description":"How to treat records that depend on this one: ERROR_IF_DEPENDANTS (default — fails rather than cascading), APPLY_DELETE_WHERE_POSSIBLE, DELETE_WHERE_POSSIBLE_OTHERWISE_UNLINK, APPLY_UNLINK, UNLINK_WHERE_POSSIBLE_OTHERWISE_DELETE, or REPLACE_WITH_ANOTHER"}}},"agiloft_get_choice_line_id":{"id":"agiloft_get_choice_line_id","name":"Agiloft Get Choice Line ID","description":"Resolve the internal numeric ID of a choice-list value, for use in EWSelect WHERE clauses against choice fields.","version":"1.0.0","params":{"instanceUrl":{"type":"string","required":true,"visibility":"user-only","description":"Agiloft instance URL (e.g., https://mycompany.agiloft.com)"},"knowledgeBase":{"type":"string","required":true,"visibility":"user-only","description":"Knowledge base name"},"login":{"type":"string","required":true,"visibility":"user-only","description":"Agiloft username"},"password":{"type":"string","required":true,"visibility":"user-only","description":"Agiloft password"},"table":{"type":"string","required":true,"visibility":"user-or-llm","description":"Table name (e.g., \\"case\\", \\"contracts\\")"},"fieldName":{"type":"string","required":true,"visibility":"user-or-llm","description":"Choice field name (e.g., \\"priority\\", \\"status\\")"},"value":{"type":"string","required":true,"visibility":"user-or-llm","description":"Choice display value to resolve (e.g., \\"High\\", \\"Active\\")"}}},"agiloft_list_tables":{"id":"agiloft_list_tables","name":"Agiloft List Tables","description":"List the tables and fields in an Agiloft knowledge base, to discover the logical names other operations need.","version":"1.0.0","params":{"instanceUrl":{"type":"string","required":true,"visibility":"user-only","description":"Agiloft instance URL (e.g., https://mycompany.agiloft.com)"},"knowledgeBase":{"type":"string","required":true,"visibility":"user-only","description":"Knowledge base name"},"login":{"type":"string","required":true,"visibility":"user-only","description":"Agiloft username"},"password":{"type":"string","required":true,"visibility":"user-only","description":"Agiloft password"},"table":{"type":"string","required":false,"visibility":"user-or-llm","description":"Logical name of a single table to describe (e.g., \\"contacts\\"). Leave empty to list every table in the knowledge base."},"includeLinkedInfo":{"type":"boolean","required":false,"visibility":"user-or-llm","description":"Include the source table and column behind each linked field"},"skipColumnsInfo":{"type":"boolean","required":false,"visibility":"user-or-llm","description":"Return table names only, omitting field details, for a much smaller response"}}},"agiloft_lock_record":{"id":"agiloft_lock_record","name":"Agiloft Lock Record","description":"Lock, unlock, or check the lock status of an Agiloft record.","version":"1.0.0","params":{"instanceUrl":{"type":"string","required":true,"visibility":"user-only","description":"Agiloft instance URL (e.g., https://mycompany.agiloft.com)"},"knowledgeBase":{"type":"string","required":true,"visibility":"user-only","description":"Knowledge base name"},"login":{"type":"string","required":true,"visibility":"user-only","description":"Agiloft username"},"password":{"type":"string","required":true,"visibility":"user-only","description":"Agiloft password"},"table":{"type":"string","required":true,"visibility":"user-or-llm","description":"Table name (e.g., \\"contracts\\")"},"recordId":{"type":"string","required":true,"visibility":"user-or-llm","description":"ID of the record to lock, unlock, or check"},"lockAction":{"type":"string","required":true,"visibility":"user-or-llm","description":"Action to perform: \\"lock\\", \\"unlock\\", or \\"check\\""},"force":{"type":"boolean","required":false,"visibility":"user-or-llm","description":"Unlock only: release a lock held by another user."}}},"agiloft_nlp_search":{"id":"agiloft_nlp_search","name":"Agiloft Natural Language Search","description":"Search Agiloft records by describing what you want in plain language, such as \\"active NDAs submitted last month\\".","version":"1.0.0","params":{"instanceUrl":{"type":"string","required":true,"visibility":"user-only","description":"Agiloft instance URL (e.g., https://mycompany.agiloft.com)"},"knowledgeBase":{"type":"string","required":true,"visibility":"user-only","description":"Knowledge base name"},"login":{"type":"string","required":true,"visibility":"user-only","description":"Agiloft username"},"password":{"type":"string","required":true,"visibility":"user-only","description":"Agiloft password"},"nlpQuery":{"type":"string","required":true,"visibility":"user-or-llm","description":"The request in plain language, e.g. \\"Show me open, high-priority contracts\\". Structured field filters are not accepted — use Search Records for those."},"fields":{"type":"string","required":true,"visibility":"user-or-llm","description":"Comma-separated field names to return, e.g. \\"id, contract_title1, company_name\\""},"page":{"type":"string","required":false,"visibility":"user-or-llm","description":"Page number, starting from 0"},"limit":{"type":"string","required":false,"visibility":"user-or-llm","description":"Records per page"}}},"agiloft_read_record":{"id":"agiloft_read_record","name":"Agiloft Read Record","description":"Read a record by ID from an Agiloft table.","version":"1.0.0","params":{"instanceUrl":{"type":"string","required":true,"visibility":"user-only","description":"Agiloft instance URL (e.g., https://mycompany.agiloft.com)"},"knowledgeBase":{"type":"string","required":true,"visibility":"user-only","description":"Knowledge base name"},"login":{"type":"string","required":true,"visibility":"user-only","description":"Agiloft username"},"password":{"type":"string","required":true,"visibility":"user-only","description":"Agiloft password"},"table":{"type":"string","required":true,"visibility":"user-or-llm","description":"Table name (e.g., \\"contracts\\", \\"contacts.employees\\")"},"recordId":{"type":"string","required":true,"visibility":"user-or-llm","description":"ID of the record to read"},"fields":{"type":"string","required":false,"visibility":"user-or-llm","description":"Comma-separated list of field names to include in the response"}}},"agiloft_remove_attachment":{"id":"agiloft_remove_attachment","name":"Agiloft Remove Attachment","description":"Remove an attached file from a field in an Agiloft record.","version":"1.0.0","params":{"instanceUrl":{"type":"string","required":true,"visibility":"user-only","description":"Agiloft instance URL (e.g., https://mycompany.agiloft.com)"},"knowledgeBase":{"type":"string","required":true,"visibility":"user-only","description":"Knowledge base name"},"login":{"type":"string","required":true,"visibility":"user-only","description":"Agiloft username"},"password":{"type":"string","required":true,"visibility":"user-only","description":"Agiloft password"},"table":{"type":"string","required":true,"visibility":"user-or-llm","description":"Table name (e.g., \\"contracts\\")"},"recordId":{"type":"string","required":true,"visibility":"user-or-llm","description":"ID of the record containing the attachment"},"fieldName":{"type":"string","required":true,"visibility":"user-or-llm","description":"Name of the attachment field"},"position":{"type":"string","required":true,"visibility":"user-or-llm","description":"Position index of the file to remove (starting from 0)"}}},"agiloft_retrieve_attachment":{"id":"agiloft_retrieve_attachment","name":"Agiloft Retrieve Attachment","description":"Download an attached file from an Agiloft record field.","version":"1.0.0","params":{"instanceUrl":{"type":"string","required":true,"visibility":"user-only","description":"Agiloft instance URL (e.g., https://mycompany.agiloft.com)"},"knowledgeBase":{"type":"string","required":true,"visibility":"user-only","description":"Knowledge base name"},"login":{"type":"string","required":true,"visibility":"user-only","description":"Agiloft username"},"password":{"type":"string","required":true,"visibility":"user-only","description":"Agiloft password"},"table":{"type":"string","required":true,"visibility":"user-or-llm","description":"Table name (e.g., \\"contracts\\")"},"recordId":{"type":"string","required":true,"visibility":"user-or-llm","description":"ID of the record containing the attachment"},"fieldName":{"type":"string","required":true,"visibility":"user-or-llm","description":"Name of the attachment field"},"position":{"type":"string","required":true,"visibility":"user-or-llm","description":"Position index of the file in the field (starting from 0)"}}},"agiloft_run_action_button":{"id":"agiloft_run_action_button","name":"Agiloft Run Action Button","description":"Run an action button on an Agiloft record, such as an approval or send-for-signature step.","version":"1.0.0","params":{"instanceUrl":{"type":"string","required":true,"visibility":"user-only","description":"Agiloft instance URL (e.g., https://mycompany.agiloft.com)"},"knowledgeBase":{"type":"string","required":true,"visibility":"user-only","description":"Knowledge base name"},"login":{"type":"string","required":true,"visibility":"user-only","description":"Agiloft username"},"password":{"type":"string","required":true,"visibility":"user-only","description":"Agiloft password"},"table":{"type":"string","required":true,"visibility":"user-or-llm","description":"Table name (e.g., \\"contracts\\", \\"case\\")"},"recordId":{"type":"string","required":true,"visibility":"user-or-llm","description":"ID of the record to run the action button on"},"actionButtonField":{"type":"string","required":true,"visibility":"user-or-llm","description":"Logical name of the field holding the action button (e.g., \\"ab_field\\")"}}},"agiloft_saved_search":{"id":"agiloft_saved_search","name":"Agiloft Saved Search","description":"List the saved searches defined for an Agiloft table.","version":"1.0.0","params":{"instanceUrl":{"type":"string","required":true,"visibility":"user-only","description":"Agiloft instance URL (e.g., https://mycompany.agiloft.com)"},"knowledgeBase":{"type":"string","required":true,"visibility":"user-only","description":"Knowledge base name"},"login":{"type":"string","required":true,"visibility":"user-only","description":"Agiloft username"},"password":{"type":"string","required":true,"visibility":"user-only","description":"Agiloft password"},"table":{"type":"string","required":true,"visibility":"user-or-llm","description":"Logical table name to list saved searches for (e.g., \\"contract\\")"}}},"agiloft_search_records":{"id":"agiloft_search_records","name":"Agiloft Search Records","description":"Search for records in an Agiloft table using a query.","version":"1.0.0","params":{"instanceUrl":{"type":"string","required":true,"visibility":"user-only","description":"Agiloft instance URL (e.g., https://mycompany.agiloft.com)"},"knowledgeBase":{"type":"string","required":true,"visibility":"user-only","description":"Knowledge base name"},"login":{"type":"string","required":true,"visibility":"user-only","description":"Agiloft username"},"password":{"type":"string","required":true,"visibility":"user-only","description":"Agiloft password"},"table":{"type":"string","required":true,"visibility":"user-or-llm","description":"Table name to search in (e.g., \\"contracts\\", \\"contacts.employees\\")"},"query":{"type":"string","required":false,"visibility":"user-or-llm","description":"Ad hoc EWSearch query. Combine conditions with && (and) or || (or) and quote every value — e.g. \\"summary~=\'test\'&&priority=\'High\'\\". Required unless a saved search is given."},"search":{"type":"string","required":false,"visibility":"user-or-llm","description":"Label of a saved search defined on the table (e.g., \\"C: Status is Closed\\"). Can be combined with a query to narrow it further."},"fields":{"type":"string","required":false,"visibility":"user-or-llm","description":"Comma-separated list of field names to include in the results"},"page":{"type":"string","required":false,"visibility":"user-or-llm","description":"Page number for paginated results (starting from 0)"},"limit":{"type":"string","required":false,"visibility":"user-or-llm","description":"Maximum number of records to return per page. Agiloft treats 0 as \\"all records\\", so leave it unset or use a positive value to keep result sizes bounded."}}},"agiloft_select_records":{"id":"agiloft_select_records","name":"Agiloft Select Records","description":"Select record IDs matching a SQL WHERE clause from an Agiloft table.","version":"1.0.0","params":{"instanceUrl":{"type":"string","required":true,"visibility":"user-only","description":"Agiloft instance URL (e.g., https://mycompany.agiloft.com)"},"knowledgeBase":{"type":"string","required":true,"visibility":"user-only","description":"Knowledge base name"},"login":{"type":"string","required":true,"visibility":"user-only","description":"Agiloft username"},"password":{"type":"string","required":true,"visibility":"user-only","description":"Agiloft password"},"table":{"type":"string","required":true,"visibility":"user-or-llm","description":"Table name (e.g., \\"contracts\\", \\"contacts.employees\\")"},"where":{"type":"string","required":true,"visibility":"user-or-llm","description":"SQL WHERE clause using database column names (e.g., \\"summary like \'%new%\'\\" or \\"assigned_person=\'John Doe\'\\"). EWSelect has no page size and returns every matching ID, so append a database limit such as \\"limit 0,200\\" to bound the result."}}},"agiloft_update_record":{"id":"agiloft_update_record","name":"Agiloft Update Record","description":"Update an existing record in an Agiloft table.","version":"1.0.0","params":{"instanceUrl":{"type":"string","required":true,"visibility":"user-only","description":"Agiloft instance URL (e.g., https://mycompany.agiloft.com)"},"knowledgeBase":{"type":"string","required":true,"visibility":"user-only","description":"Knowledge base name"},"login":{"type":"string","required":true,"visibility":"user-only","description":"Agiloft username"},"password":{"type":"string","required":true,"visibility":"user-only","description":"Agiloft password"},"table":{"type":"string","required":true,"visibility":"user-or-llm","description":"Table name (e.g., \\"contracts\\", \\"contacts.employees\\")"},"recordId":{"type":"string","required":true,"visibility":"user-or-llm","description":"ID of the record to update"},"data":{"type":"string","required":true,"visibility":"user-or-llm","description":"Updated field values as a JSON object (e.g., {\\"status\\": \\"Active\\", \\"priority\\": \\"High\\"})"}}},"agiloft_upsert_record":{"id":"agiloft_upsert_record","name":"Agiloft Upsert Record","description":"Create an Agiloft record, or update it when a record already matches the given fields.","version":"1.0.0","params":{"instanceUrl":{"type":"string","required":true,"visibility":"user-only","description":"Agiloft instance URL (e.g., https://mycompany.agiloft.com)"},"knowledgeBase":{"type":"string","required":true,"visibility":"user-only","description":"Knowledge base name"},"login":{"type":"string","required":true,"visibility":"user-only","description":"Agiloft username"},"password":{"type":"string","required":true,"visibility":"user-only","description":"Agiloft password"},"table":{"type":"string","required":true,"visibility":"user-or-llm","description":"Table name (e.g., \\"contracts\\", \\"contacts.employees\\")"},"match":{"type":"string","required":true,"visibility":"user-or-llm","description":"Field used to find an existing record (e.g., \\"ext_id\\"). Pick something that identifies a record uniquely — if more than one record matches, Agiloft writes nothing and returns a conflict."},"async":{"type":"boolean","required":false,"visibility":"user-or-llm","description":"Queue the write instead of waiting for it. Returns a callback ID instead of a record ID; pass that to Async Status to poll the result."},"data":{"type":"string","required":true,"visibility":"user-or-llm","description":"Field values as a JSON object. On create these populate the new record; on update only the supplied fields change."}}},"ahrefs_anchors":{"id":"ahrefs_anchors","name":"Ahrefs Anchors","description":"Get the anchor text distribution for a target domain or URL\'s backlinks, showing how many links and referring domains use each anchor text.","version":"1.0.0","params":{"target":{"type":"string","required":true,"visibility":"user-or-llm","description":"The target domain or URL to analyze. Example: \\"example.com\\" or \\"https://example.com/page\\""},"mode":{"type":"string","required":false,"visibility":"user-or-llm","description":"Analysis mode: domain (entire domain), prefix (URL prefix), subdomains (include all subdomains, default), exact (exact URL match)"},"history":{"type":"string","required":false,"visibility":"user-or-llm","description":"Historical scope: \\"live\\" (currently live), \\"all_time\\" (default, includes lost backlinks), or \\"since:YYYY-MM-DD\\" (backlinks found since a date)"},"limit":{"type":"number","required":false,"visibility":"user-or-llm","description":"Maximum number of results to return. Example: 50 (default: 1000)"},"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Ahrefs API Key"}}},"ahrefs_backlinks":{"id":"ahrefs_backlinks","name":"Ahrefs Backlinks","description":"Get a list of backlinks pointing to a target domain or URL. Returns details about each backlink including source URL, anchor text, and domain rating.","version":"1.0.0","params":{"target":{"type":"string","required":true,"visibility":"user-or-llm","description":"The target domain or URL to analyze. Example: \\"example.com\\" or \\"https://example.com/page\\""},"mode":{"type":"string","required":false,"visibility":"user-or-llm","description":"Analysis mode: domain (entire domain), prefix (URL prefix), subdomains (include all subdomains, default), exact (exact URL match). Example: \\"domain\\""},"history":{"type":"string","required":false,"visibility":"user-or-llm","description":"Historical scope: \\"live\\" (currently live backlinks), \\"all_time\\" (default, includes lost backlinks), or \\"since:YYYY-MM-DD\\" (backlinks found since a date)."},"limit":{"type":"number","required":false,"visibility":"user-or-llm","description":"Maximum number of results to return. Example: 50 (default: 1000)"},"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Ahrefs API Key"}}},"ahrefs_backlinks_stats":{"id":"ahrefs_backlinks_stats","name":"Ahrefs Backlinks Stats","description":"Get backlink and referring domain totals for a target domain or URL, both currently live and across all time.","version":"1.0.0","params":{"target":{"type":"string","required":true,"visibility":"user-or-llm","description":"The target domain or URL to analyze. Example: \\"example.com\\" or \\"https://example.com/page\\""},"mode":{"type":"string","required":false,"visibility":"user-or-llm","description":"Analysis mode: domain (entire domain), prefix (URL prefix), subdomains (include all subdomains, default), exact (exact URL match). Example: \\"domain\\""},"date":{"type":"string","required":false,"visibility":"user-only","description":"Date to report metrics on, in YYYY-MM-DD format (defaults to today)"},"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Ahrefs API Key"}}},"ahrefs_batch_analysis":{"id":"ahrefs_batch_analysis","name":"Ahrefs Batch Analysis","description":"Get bulk SEO metrics (Domain Rating, backlinks, referring domains, organic traffic, and more) for multiple domains or URLs in a single request. Useful for comparing many competitors at once.","version":"1.0.0","params":{"targets":{"type":"string","required":true,"visibility":"user-or-llm","description":"Comma-separated list of domains or URLs to analyze. Example: \\"example.com,competitor.com\\""},"mode":{"type":"string","required":false,"visibility":"user-or-llm","description":"Analysis mode applied to every target: domain (entire domain), prefix (URL prefix), subdomains (include all subdomains, default), exact (exact URL match)"},"protocol":{"type":"string","required":false,"visibility":"user-or-llm","description":"Protocol applied to every target: \\"both\\" (default), \\"http\\", or \\"https\\""},"country":{"type":"string","required":false,"visibility":"user-or-llm","description":"Country code for traffic data. Example: \\"us\\", \\"gb\\", \\"de\\" (default: \\"us\\")"},"volumeMode":{"type":"string","required":false,"visibility":"user-or-llm","description":"Search volume calculation: \\"monthly\\" or \\"average\\" (default: \\"monthly\\")"},"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Ahrefs API Key"}}},"ahrefs_broken_backlinks":{"id":"ahrefs_broken_backlinks","name":"Ahrefs Broken Backlinks","description":"Get a list of broken backlinks pointing to a target domain or URL. Useful for identifying link reclamation opportunities.","version":"1.0.0","params":{"target":{"type":"string","required":true,"visibility":"user-or-llm","description":"The target domain or URL to analyze. Example: \\"example.com\\" or \\"https://example.com/page\\""},"mode":{"type":"string","required":false,"visibility":"user-or-llm","description":"Analysis mode: domain (entire domain), prefix (URL prefix), subdomains (include all subdomains, default), exact (exact URL match). Example: \\"domain\\""},"limit":{"type":"number","required":false,"visibility":"user-or-llm","description":"Maximum number of results to return. Example: 50 (default: 1000)"},"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Ahrefs API Key"}}},"ahrefs_domain_rating":{"id":"ahrefs_domain_rating","name":"Ahrefs Domain Rating","description":"Get the Domain Rating (DR) and Ahrefs Rank for a target domain. Domain Rating shows the strength of a website\'s backlink profile on a scale from 0 to 100.","version":"1.0.0","params":{"target":{"type":"string","required":true,"visibility":"user-or-llm","description":"The target domain to analyze (e.g., example.com)"},"date":{"type":"string","required":false,"visibility":"user-only","description":"Date for historical data in YYYY-MM-DD format (defaults to today)"},"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Ahrefs API Key"}}},"ahrefs_domain_rating_history":{"id":"ahrefs_domain_rating_history","name":"Ahrefs Domain Rating History","description":"Get the historical Domain Rating (DR) trend for a target domain or URL over a date range, grouped daily, weekly, or monthly.","version":"1.0.0","params":{"target":{"type":"string","required":true,"visibility":"user-or-llm","description":"The target domain or URL to analyze. Example: \\"example.com\\""},"dateFrom":{"type":"string","required":true,"visibility":"user-only","description":"Start date of the historical period, in YYYY-MM-DD format"},"dateTo":{"type":"string","required":false,"visibility":"user-only","description":"End date of the historical period, in YYYY-MM-DD format (defaults to today)"},"historyGrouping":{"type":"string","required":false,"visibility":"user-or-llm","description":"Time interval for grouping data points: \\"daily\\", \\"weekly\\", or \\"monthly\\" (default: \\"monthly\\")"},"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Ahrefs API Key"}}},"ahrefs_keyword_overview":{"id":"ahrefs_keyword_overview","name":"Ahrefs Keyword Overview","description":"Get detailed metrics for a keyword including search volume, keyword difficulty, CPC, clicks, and traffic potential.","version":"1.0.0","params":{"keyword":{"type":"string","required":true,"visibility":"user-or-llm","description":"The keyword to analyze"},"country":{"type":"string","required":false,"visibility":"user-or-llm","description":"Country code for keyword data. Example: \\"us\\", \\"gb\\", \\"de\\" (default: \\"us\\")"},"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Ahrefs API Key"}}},"ahrefs_keywords_history":{"id":"ahrefs_keywords_history","name":"Ahrefs Keywords History","description":"Get the historical organic keyword ranking distribution for a target domain or URL over a date range: how many keywords rank in each position bucket at each point in time.","version":"1.0.0","params":{"target":{"type":"string","required":true,"visibility":"user-or-llm","description":"The target domain or URL to analyze. Example: \\"example.com\\""},"dateFrom":{"type":"string","required":true,"visibility":"user-only","description":"Start date of the historical period, in YYYY-MM-DD format"},"dateTo":{"type":"string","required":false,"visibility":"user-only","description":"End date of the historical period, in YYYY-MM-DD format (defaults to today)"},"historyGrouping":{"type":"string","required":false,"visibility":"user-or-llm","description":"Time interval for grouping data points: \\"daily\\", \\"weekly\\", or \\"monthly\\" (default: \\"monthly\\")"},"country":{"type":"string","required":false,"visibility":"user-or-llm","description":"Country code for search results. Example: \\"us\\", \\"gb\\", \\"de\\" (default: \\"us\\")"},"mode":{"type":"string","required":false,"visibility":"user-or-llm","description":"Analysis mode: domain (entire domain), prefix (URL prefix), subdomains (include all subdomains, default), exact (exact URL match)"},"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Ahrefs API Key"}}},"ahrefs_metrics":{"id":"ahrefs_metrics","name":"Ahrefs Metrics","description":"Get a one-call organic and paid search overview for a target domain or URL: organic traffic, organic keywords, paid traffic, paid keywords, and estimated traffic cost.","version":"1.0.0","params":{"target":{"type":"string","required":true,"visibility":"user-or-llm","description":"The target domain or URL to analyze. Example: \\"example.com\\""},"country":{"type":"string","required":false,"visibility":"user-or-llm","description":"Country code for traffic data. Example: \\"us\\", \\"gb\\", \\"de\\""},"mode":{"type":"string","required":false,"visibility":"user-or-llm","description":"Analysis mode: domain (entire domain), prefix (URL prefix), subdomains (include all subdomains, default), exact (exact URL match). Example: \\"domain\\""},"date":{"type":"string","required":false,"visibility":"user-only","description":"Date to report metrics on, in YYYY-MM-DD format (defaults to today)"},"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Ahrefs API Key"}}},"ahrefs_metrics_history":{"id":"ahrefs_metrics_history","name":"Ahrefs Metrics History","description":"Get the historical organic and paid traffic trend for a target domain or URL over a date range: organic traffic/cost and paid traffic/cost at each point in time.","version":"1.0.0","params":{"target":{"type":"string","required":true,"visibility":"user-or-llm","description":"The target domain or URL to analyze. Example: \\"example.com\\""},"dateFrom":{"type":"string","required":true,"visibility":"user-only","description":"Start date of the historical period, in YYYY-MM-DD format"},"dateTo":{"type":"string","required":false,"visibility":"user-only","description":"End date of the historical period, in YYYY-MM-DD format (defaults to today)"},"volumeMode":{"type":"string","required":false,"visibility":"user-or-llm","description":"Search volume calculation: \\"monthly\\" or \\"average\\" (default: \\"monthly\\")"},"historyGrouping":{"type":"string","required":false,"visibility":"user-or-llm","description":"Time interval for grouping data points: \\"daily\\", \\"weekly\\", or \\"monthly\\" (default: \\"monthly\\")"},"country":{"type":"string","required":false,"visibility":"user-or-llm","description":"Country code for traffic data. Example: \\"us\\", \\"gb\\", \\"de\\" (default: \\"us\\")"},"mode":{"type":"string","required":false,"visibility":"user-or-llm","description":"Analysis mode: domain (entire domain), prefix (URL prefix), subdomains (include all subdomains, default), exact (exact URL match)"},"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Ahrefs API Key"}}},"ahrefs_organic_competitors":{"id":"ahrefs_organic_competitors","name":"Ahrefs Organic Competitors","description":"Get domains that compete with a target domain or URL for the same organic keywords, ranked by keyword overlap.","version":"1.0.0","params":{"target":{"type":"string","required":true,"visibility":"user-or-llm","description":"The target domain or URL to analyze. Example: \\"example.com\\""},"country":{"type":"string","required":false,"visibility":"user-or-llm","description":"Country code for search results. Example: \\"us\\", \\"gb\\", \\"de\\" (default: \\"us\\")"},"mode":{"type":"string","required":false,"visibility":"user-or-llm","description":"Analysis mode: domain (entire domain), prefix (URL prefix), subdomains (include all subdomains, default), exact (exact URL match). Example: \\"domain\\""},"date":{"type":"string","required":false,"visibility":"user-only","description":"Date to report metrics on, in YYYY-MM-DD format (defaults to today)"},"limit":{"type":"number","required":false,"visibility":"user-or-llm","description":"Maximum number of results to return. Example: 50 (default: 1000)"},"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Ahrefs API Key"}}},"ahrefs_organic_keywords":{"id":"ahrefs_organic_keywords","name":"Ahrefs Organic Keywords","description":"Get organic keywords that a target domain or URL ranks for in Google search results. Returns keyword details including search volume, ranking position, and estimated traffic.","version":"1.0.0","params":{"target":{"type":"string","required":true,"visibility":"user-or-llm","description":"The target domain or URL to analyze. Example: \\"example.com\\" or \\"https://example.com/page\\""},"country":{"type":"string","required":false,"visibility":"user-or-llm","description":"Country code for search results. Example: \\"us\\", \\"gb\\", \\"de\\" (default: \\"us\\")"},"mode":{"type":"string","required":false,"visibility":"user-or-llm","description":"Analysis mode: domain (entire domain), prefix (URL prefix), subdomains (include all subdomains, default), exact (exact URL match). Example: \\"domain\\""},"date":{"type":"string","required":false,"visibility":"user-only","description":"Date to report metrics on, in YYYY-MM-DD format (defaults to today)"},"limit":{"type":"number","required":false,"visibility":"user-or-llm","description":"Maximum number of results to return. Example: 50 (default: 1000)"},"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Ahrefs API Key"}}},"ahrefs_paid_pages":{"id":"ahrefs_paid_pages","name":"Ahrefs Paid Pages","description":"Get a target domain\'s pages that receive paid search traffic, sorted by estimated paid traffic. Returns page URLs with their paid traffic, keyword counts, and estimated spend.","version":"1.0.0","params":{"target":{"type":"string","required":true,"visibility":"user-or-llm","description":"The target domain or URL to analyze. Example: \\"example.com\\""},"country":{"type":"string","required":false,"visibility":"user-or-llm","description":"Country code for traffic data. Example: \\"us\\", \\"gb\\", \\"de\\" (default: \\"us\\")"},"mode":{"type":"string","required":false,"visibility":"user-or-llm","description":"Analysis mode: domain (entire domain), prefix (URL prefix), subdomains (include all subdomains, default), exact (exact URL match)"},"date":{"type":"string","required":false,"visibility":"user-only","description":"Date to report metrics on, in YYYY-MM-DD format (defaults to today)"},"limit":{"type":"number","required":false,"visibility":"user-or-llm","description":"Maximum number of results to return. Example: 50 (default: 1000)"},"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Ahrefs API Key"}}},"ahrefs_rank_tracker_competitors_overview":{"id":"ahrefs_rank_tracker_competitors_overview","name":"Ahrefs Rank Tracker Competitors Overview","description":"Get competitor rankings for the keywords tracked in an Ahrefs Rank Tracker project: each tracked keyword\'s volume and difficulty alongside every competitor\'s position, traffic, and traffic value. This endpoint is free and does not consume API units.","version":"1.0.0","params":{"projectId":{"type":"number","required":true,"visibility":"user-or-llm","description":"The Rank Tracker project ID (found in the project URL in Ahrefs)"},"date":{"type":"string","required":true,"visibility":"user-only","description":"Date to report rankings for, in YYYY-MM-DD format"},"device":{"type":"string","required":true,"visibility":"user-or-llm","description":"Rankings device type: \\"desktop\\" or \\"mobile\\""},"dateCompared":{"type":"string","required":false,"visibility":"user-only","description":"Comparison date in YYYY-MM-DD format, to compute position/traffic deltas"},"volumeMode":{"type":"string","required":false,"visibility":"user-or-llm","description":"Search volume calculation: \\"monthly\\" or \\"average\\" (default: \\"monthly\\")"},"limit":{"type":"number","required":false,"visibility":"user-or-llm","description":"Maximum number of results to return. Example: 50 (default: 1000)"},"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Ahrefs API Key"}}},"ahrefs_rank_tracker_competitors_stats":{"id":"ahrefs_rank_tracker_competitors_stats","name":"Ahrefs Rank Tracker Competitors Stats","description":"Get aggregate competitor stats for an Ahrefs Rank Tracker project: each competitor\'s traffic, traffic value, average position, and share of voice across all tracked keywords. This endpoint is free and does not consume API units.","version":"1.0.0","params":{"projectId":{"type":"number","required":true,"visibility":"user-or-llm","description":"The Rank Tracker project ID (found in the project URL in Ahrefs)"},"date":{"type":"string","required":true,"visibility":"user-only","description":"Date to report metrics for, in YYYY-MM-DD format"},"device":{"type":"string","required":true,"visibility":"user-or-llm","description":"Rankings device type: \\"desktop\\" or \\"mobile\\""},"volumeMode":{"type":"string","required":false,"visibility":"user-or-llm","description":"Search volume calculation: \\"monthly\\" or \\"average\\" (default: \\"monthly\\")"},"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Ahrefs API Key"}}},"ahrefs_rank_tracker_overview":{"id":"ahrefs_rank_tracker_overview","name":"Ahrefs Rank Tracker Overview","description":"Get ranking overview metrics for the keywords tracked in an Ahrefs Rank Tracker project: position, search volume, keyword difficulty, and estimated traffic. This endpoint is free and does not consume API units.","version":"1.0.0","params":{"projectId":{"type":"number","required":true,"visibility":"user-or-llm","description":"The Rank Tracker project ID (found in the project URL in Ahrefs)"},"date":{"type":"string","required":true,"visibility":"user-only","description":"Date to report rankings for, in YYYY-MM-DD format"},"device":{"type":"string","required":true,"visibility":"user-or-llm","description":"Rankings device type: \\"desktop\\" or \\"mobile\\""},"dateCompared":{"type":"string","required":false,"visibility":"user-only","description":"Comparison date in YYYY-MM-DD format, to compute position/traffic deltas"},"volumeMode":{"type":"string","required":false,"visibility":"user-or-llm","description":"Search volume calculation: \\"monthly\\" or \\"average\\" (default: \\"monthly\\")"},"limit":{"type":"number","required":false,"visibility":"user-or-llm","description":"Maximum number of results to return. Example: 50 (default: 1000)"},"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Ahrefs API Key"}}},"ahrefs_rank_tracker_serp_overview":{"id":"ahrefs_rank_tracker_serp_overview","name":"Ahrefs Rank Tracker SERP Overview","description":"Get the full SERP (search engine results page) for a keyword tracked in an Ahrefs Rank Tracker project, including every ranking URL with its position, title, and authority metrics. This endpoint is free and does not consume API units.","version":"1.0.0","params":{"projectId":{"type":"number","required":true,"visibility":"user-or-llm","description":"The Rank Tracker project ID (found in the project URL in Ahrefs)"},"keyword":{"type":"string","required":true,"visibility":"user-or-llm","description":"The tracked keyword to retrieve SERP data for"},"country":{"type":"string","required":true,"visibility":"user-or-llm","description":"Country code for the tracked keyword. Example: \\"us\\", \\"gb\\", \\"de\\""},"device":{"type":"string","required":true,"visibility":"user-or-llm","description":"Rankings device type: \\"desktop\\" or \\"mobile\\""},"topPositions":{"type":"number","required":false,"visibility":"user-or-llm","description":"Number of top organic positions to return (defaults to all available)"},"date":{"type":"string","required":false,"visibility":"user-only","description":"Timestamp to return the last available SERP Overview at, in YYYY-MM-DDThh:mm:ss format"},"locationId":{"type":"number","required":false,"visibility":"user-or-llm","description":"Location ID of the tracked keyword, if tracked at a specific location"},"languageCode":{"type":"string","required":false,"visibility":"user-or-llm","description":"Language code of the tracked keyword"},"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Ahrefs API Key"}}},"ahrefs_refdomains_history":{"id":"ahrefs_refdomains_history","name":"Ahrefs Referring Domains History","description":"Get the historical referring domains trend for a target domain or URL over a date range, grouped daily, weekly, or monthly.","version":"1.0.0","params":{"target":{"type":"string","required":true,"visibility":"user-or-llm","description":"The target domain or URL to analyze. Example: \\"example.com\\""},"dateFrom":{"type":"string","required":true,"visibility":"user-only","description":"Start date of the historical period, in YYYY-MM-DD format"},"dateTo":{"type":"string","required":false,"visibility":"user-only","description":"End date of the historical period, in YYYY-MM-DD format (defaults to today)"},"historyGrouping":{"type":"string","required":false,"visibility":"user-or-llm","description":"Time interval for grouping data points: \\"daily\\", \\"weekly\\", or \\"monthly\\" (default: \\"monthly\\")"},"mode":{"type":"string","required":false,"visibility":"user-or-llm","description":"Analysis mode: domain (entire domain), prefix (URL prefix), subdomains (include all subdomains, default), exact (exact URL match)"},"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Ahrefs API Key"}}},"ahrefs_referring_domains":{"id":"ahrefs_referring_domains","name":"Ahrefs Referring Domains","description":"Get a list of domains that link to a target domain or URL. Returns unique referring domains with their domain rating, backlink counts, and discovery dates.","version":"1.0.0","params":{"target":{"type":"string","required":true,"visibility":"user-or-llm","description":"The target domain or URL to analyze. Example: \\"example.com\\" or \\"https://example.com/page\\""},"mode":{"type":"string","required":false,"visibility":"user-or-llm","description":"Analysis mode: domain (entire domain), prefix (URL prefix), subdomains (include all subdomains, default), exact (exact URL match). Example: \\"domain\\""},"history":{"type":"string","required":false,"visibility":"user-or-llm","description":"Historical scope: \\"live\\" (currently live), \\"all_time\\" (default, includes lost domains), or \\"since:YYYY-MM-DD\\" (domains found since a date)."},"limit":{"type":"number","required":false,"visibility":"user-or-llm","description":"Maximum number of results to return. Example: 50 (default: 1000)"},"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Ahrefs API Key"}}},"ahrefs_related_terms":{"id":"ahrefs_related_terms","name":"Ahrefs Related Terms","description":"Get keyword ideas related to a seed keyword: terms the same top-ranking pages also rank for (\\"also rank for\\") or also discuss (\\"also talk about\\"), with volume, difficulty, and CPC.","version":"1.0.0","params":{"keyword":{"type":"string","required":true,"visibility":"user-or-llm","description":"The seed keyword to find related terms for"},"country":{"type":"string","required":false,"visibility":"user-or-llm","description":"Country code for keyword data. Example: \\"us\\", \\"gb\\", \\"de\\" (default: \\"us\\")"},"terms":{"type":"string","required":false,"visibility":"user-or-llm","description":"Type of related keywords to return: \\"also_rank_for\\", \\"also_talk_about\\", or \\"all\\" (default: \\"all\\")"},"viewFor":{"type":"string","required":false,"visibility":"user-or-llm","description":"Whether to derive related terms from the top 10 or top 100 ranking pages (default: \\"top_10\\")"},"limit":{"type":"number","required":false,"visibility":"user-or-llm","description":"Maximum number of results to return. Example: 50 (default: 1000)"},"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Ahrefs API Key"}}},"ahrefs_site_audit_page_explorer":{"id":"ahrefs_site_audit_page_explorer","name":"Ahrefs Site Audit Page Explorer","description":"Get crawled pages from an Ahrefs Site Audit project with health and SEO metrics: HTTP status, title, link counts, backlinks, indexability, and traffic. Optionally filter to pages affected by a specific issue.","version":"1.0.0","params":{"projectId":{"type":"number","required":true,"visibility":"user-or-llm","description":"The Site Audit project ID (found in the project URL in Ahrefs)"},"date":{"type":"string","required":false,"visibility":"user-only","description":"Crawl date in YYYY-MM-DDThh:mm:ss format (defaults to the most recent crawl)"},"limit":{"type":"number","required":false,"visibility":"user-or-llm","description":"Maximum number of results to return. Example: 50 (default: 1000)"},"offset":{"type":"number","required":false,"visibility":"user-or-llm","description":"Number of results to skip, for pagination"},"issueId":{"type":"string","required":false,"visibility":"user-or-llm","description":"Only return pages affected by this issue ID"},"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Ahrefs API Key"}}},"ahrefs_top_pages":{"id":"ahrefs_top_pages","name":"Ahrefs Top Pages","description":"Get the top pages of a target domain sorted by organic traffic. Returns page URLs with their traffic, keyword counts, and estimated traffic value.","version":"1.0.0","params":{"target":{"type":"string","required":true,"visibility":"user-or-llm","description":"The target domain to analyze. Example: \\"example.com\\""},"country":{"type":"string","required":false,"visibility":"user-or-llm","description":"Country code for traffic data. Example: \\"us\\", \\"gb\\", \\"de\\" (default: \\"us\\")"},"mode":{"type":"string","required":false,"visibility":"user-or-llm","description":"Analysis mode: domain (entire domain), prefix (URL prefix), subdomains (include all subdomains, default), exact (exact URL match). Example: \\"domain\\""},"date":{"type":"string","required":false,"visibility":"user-only","description":"Date to report metrics on, in YYYY-MM-DD format (defaults to today)"},"limit":{"type":"number","required":false,"visibility":"user-or-llm","description":"Maximum number of results to return. Example: 50 (default: 1000)"},"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Ahrefs API Key"}}},"airtable_create_records":{"id":"airtable_create_records","name":"Airtable Create Records","description":"Write new records to an Airtable table","version":"1.0.0","params":{"accessToken":{"type":"string","required":true,"visibility":"hidden","description":"OAuth access token"},"baseId":{"type":"string","required":true,"visibility":"user-or-llm","description":"Airtable base ID (starts with \\"app\\", e.g., \\"appXXXXXXXXXXXXXX\\")"},"tableId":{"type":"string","required":true,"visibility":"user-or-llm","description":"Table ID (starts with \\"tbl\\") or table name"},"records":{"type":"json","required":true,"visibility":"user-or-llm","description":"Array of records to create, each with a `fields` object"},"typecast":{"type":"boolean","required":false,"visibility":"user-or-llm","description":"When true, Airtable automatically converts string values to the field type"}},"oauth":{"required":true,"provider":"airtable"}},"airtable_delete_records":{"id":"airtable_delete_records","name":"Airtable Delete Records","description":"Delete one or more records from an Airtable table by ID","version":"1.0.0","params":{"accessToken":{"type":"string","required":true,"visibility":"hidden","description":"OAuth access token"},"baseId":{"type":"string","required":true,"visibility":"user-or-llm","description":"Airtable base ID (starts with \\"app\\", e.g., \\"appXXXXXXXXXXXXXX\\")"},"tableId":{"type":"string","required":true,"visibility":"user-or-llm","description":"Table ID (starts with \\"tbl\\") or table name"},"recordIds":{"type":"json","required":true,"visibility":"user-or-llm","description":"Array of record IDs to delete (each starts with \\"rec\\", e.g., [\\"recXXXXXXXXXXXXXX\\"]). Pass a single-element array to delete one record."}},"oauth":{"required":true,"provider":"airtable"}},"airtable_get_base_schema":{"id":"airtable_get_base_schema","name":"Airtable Get Base Schema","description":"Get the schema of all tables, fields, and views in an Airtable base","version":"1.0.0","params":{"accessToken":{"type":"string","required":true,"visibility":"hidden","description":"OAuth access token"},"baseId":{"type":"string","required":true,"visibility":"user-or-llm","description":"Airtable base ID (starts with \\"app\\", e.g., \\"appXXXXXXXXXXXXXX\\")"}},"oauth":{"required":true,"provider":"airtable"}},"airtable_get_record":{"id":"airtable_get_record","name":"Airtable Get Record","description":"Retrieve a single record from an Airtable table by its ID","version":"1.0.0","params":{"accessToken":{"type":"string","required":true,"visibility":"hidden","description":"OAuth access token"},"baseId":{"type":"string","required":true,"visibility":"user-or-llm","description":"Airtable base ID (starts with \\"app\\", e.g., \\"appXXXXXXXXXXXXXX\\")"},"tableId":{"type":"string","required":true,"visibility":"user-or-llm","description":"Table ID (starts with \\"tbl\\") or table name"},"recordId":{"type":"string","required":true,"visibility":"user-or-llm","description":"Record ID to retrieve (starts with \\"rec\\", e.g., \\"recXXXXXXXXXXXXXX\\")"}},"oauth":{"required":true,"provider":"airtable"}},"airtable_list_bases":{"id":"airtable_list_bases","name":"Airtable List Bases","description":"List all bases the authenticated user has access to","version":"1.0.0","params":{"accessToken":{"type":"string","required":true,"visibility":"hidden","description":"OAuth access token"},"offset":{"type":"string","required":false,"visibility":"user-or-llm","description":"Pagination offset for retrieving additional bases"}},"oauth":{"required":true,"provider":"airtable"}},"airtable_list_records":{"id":"airtable_list_records","name":"Airtable List Records","description":"Read records from an Airtable table","version":"1.0.0","params":{"accessToken":{"type":"string","required":true,"visibility":"hidden","description":"OAuth access token"},"baseId":{"type":"string","required":true,"visibility":"user-or-llm","description":"Airtable base ID (starts with \\"app\\", e.g., \\"appXXXXXXXXXXXXXX\\")"},"tableId":{"type":"string","required":true,"visibility":"user-or-llm","description":"Table ID (starts with \\"tbl\\") or table name"},"maxRecords":{"type":"number","required":false,"visibility":"user-or-llm","description":"Maximum number of records to return (default: all records)"},"filterFormula":{"type":"string","required":false,"visibility":"user-or-llm","description":"Formula to filter records (e.g., \\"({Field Name} = \'Value\')\\")"}},"oauth":{"required":true,"provider":"airtable"}},"airtable_list_tables":{"id":"airtable_list_tables","name":"Airtable List Tables","description":"List all tables and their schema in an Airtable base","version":"1.0.0","params":{"accessToken":{"type":"string","required":true,"visibility":"hidden","description":"OAuth access token"},"baseId":{"type":"string","required":true,"visibility":"user-or-llm","description":"Airtable base ID (starts with \\"app\\", e.g., \\"appXXXXXXXXXXXXXX\\")"}},"oauth":{"required":true,"provider":"airtable"}},"airtable_update_multiple_records":{"id":"airtable_update_multiple_records","name":"Airtable Update Multiple Records","description":"Update multiple existing records in an Airtable table","version":"1.0.0","params":{"accessToken":{"type":"string","required":true,"visibility":"hidden","description":"OAuth access token"},"baseId":{"type":"string","required":true,"visibility":"user-or-llm","description":"Airtable base ID (starts with \\"app\\", e.g., \\"appXXXXXXXXXXXXXX\\")"},"tableId":{"type":"string","required":true,"visibility":"user-or-llm","description":"Table ID (starts with \\"tbl\\") or table name"},"records":{"type":"json","required":true,"visibility":"user-or-llm","description":"Array of records to update, each with an `id` and a `fields` object"},"typecast":{"type":"boolean","required":false,"visibility":"user-or-llm","description":"When true, Airtable automatically converts string values to the field type"}},"oauth":{"required":true,"provider":"airtable"}},"airtable_update_record":{"id":"airtable_update_record","name":"Airtable Update Record","description":"Update an existing record in an Airtable table by ID","version":"1.0.0","params":{"accessToken":{"type":"string","required":true,"visibility":"hidden","description":"OAuth access token"},"baseId":{"type":"string","required":true,"visibility":"user-or-llm","description":"Airtable base ID (starts with \\"app\\", e.g., \\"appXXXXXXXXXXXXXX\\")"},"tableId":{"type":"string","required":true,"visibility":"user-or-llm","description":"Table ID (starts with \\"tbl\\") or table name"},"recordId":{"type":"string","required":true,"visibility":"user-or-llm","description":"Record ID to update (starts with \\"rec\\", e.g., \\"recXXXXXXXXXXXXXX\\")"},"fields":{"type":"json","required":true,"visibility":"user-or-llm","description":"An object containing the field names and their new values"},"typecast":{"type":"boolean","required":false,"visibility":"user-or-llm","description":"When true, Airtable automatically converts string values to the field type"}},"oauth":{"required":true,"provider":"airtable"}},"airtable_upsert_records":{"id":"airtable_upsert_records","name":"Airtable Upsert Records","description":"Update existing records or create new ones in an Airtable table, matching on the specified merge fields","version":"1.0.0","params":{"accessToken":{"type":"string","required":true,"visibility":"hidden","description":"OAuth access token"},"baseId":{"type":"string","required":true,"visibility":"user-or-llm","description":"Airtable base ID (starts with \\"app\\", e.g., \\"appXXXXXXXXXXXXXX\\")"},"tableId":{"type":"string","required":true,"visibility":"user-or-llm","description":"Table ID (starts with \\"tbl\\") or table name"},"records":{"type":"json","required":true,"visibility":"user-or-llm","description":"Array of records to upsert, each with a `fields` object"},"fieldsToMergeOn":{"type":"json","required":true,"visibility":"user-or-llm","description":"Array of field names used to match existing records (max 3). A record is updated when all merge fields match, otherwise it is created. Example: [\\"Name\\"]"},"typecast":{"type":"boolean","required":false,"visibility":"user-or-llm","description":"When true, Airtable automatically converts string values to the field type"}},"oauth":{"required":true,"provider":"airtable"}},"airweave_search":{"id":"airweave_search","name":"Airweave Search","description":"Search your synced data collections using Airweave. Supports semantic search with hybrid, neural, or keyword retrieval strategies. Optionally generate AI-powered answers from search results.","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Airweave API Key for authentication"},"collectionId":{"type":"string","required":true,"visibility":"user-or-llm","description":"The readable ID of the collection to search"},"query":{"type":"string","required":true,"visibility":"user-or-llm","description":"The search query text"},"limit":{"type":"number","required":false,"visibility":"user-only","description":"Maximum number of results to return (default: 100)"},"retrievalStrategy":{"type":"string","required":false,"visibility":"user-or-llm","description":"Retrieval strategy: hybrid (default), neural, or keyword"},"expandQuery":{"type":"boolean","required":false,"visibility":"user-or-llm","description":"Generate query variations to improve recall"},"rerank":{"type":"boolean","required":false,"visibility":"user-or-llm","description":"Reorder results for improved relevance using LLM"},"generateAnswer":{"type":"boolean","required":false,"visibility":"user-or-llm","description":"Generate a natural-language answer to the query"}}},"algolia_add_record":{"id":"algolia_add_record","name":"Algolia Add Record","description":"Add or replace a record in an Algolia index","version":"1.0","params":{"applicationId":{"type":"string","required":true,"visibility":"user-only","description":"Algolia Application ID"},"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Algolia Admin API Key"},"indexName":{"type":"string","required":true,"visibility":"user-or-llm","description":"Name of the Algolia index"},"objectID":{"type":"string","required":false,"visibility":"user-or-llm","description":"Object ID for the record (auto-generated if not provided)"},"record":{"type":"json","required":true,"visibility":"user-or-llm","description":"JSON object representing the record to add"}}},"algolia_batch_operations":{"id":"algolia_batch_operations","name":"Algolia Batch Operations","description":"Perform batch add, update, partial update, or delete operations on records in an Algolia index","version":"1.0","params":{"applicationId":{"type":"string","required":true,"visibility":"user-only","description":"Algolia Application ID"},"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Algolia Admin API Key"},"indexName":{"type":"string","required":true,"visibility":"user-or-llm","description":"Name of the Algolia index"},"requests":{"type":"json","required":true,"visibility":"user-or-llm","description":"Array of batch operations. Each item has \\"action\\" (addObject, updateObject, partialUpdateObject, partialUpdateObjectNoCreate, deleteObject, delete, clear) and \\"body\\" (the record data; must include objectID for update/delete; use an empty object {} for the index-level delete/clear actions)"}}},"algolia_browse_records":{"id":"algolia_browse_records","name":"Algolia Browse Records","description":"Browse and iterate over all records in an Algolia index using cursor pagination","version":"1.0","params":{"applicationId":{"type":"string","required":true,"visibility":"user-only","description":"Algolia Application ID"},"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Algolia API Key (must have browse ACL)"},"indexName":{"type":"string","required":true,"visibility":"user-or-llm","description":"Name of the Algolia index to browse"},"query":{"type":"string","required":false,"visibility":"user-or-llm","description":"Search query to filter browsed records"},"filters":{"type":"string","required":false,"visibility":"user-or-llm","description":"Filter string to narrow down results"},"attributesToRetrieve":{"type":"string","required":false,"visibility":"user-or-llm","description":"Comma-separated list of attributes to retrieve"},"hitsPerPage":{"type":"number","required":false,"visibility":"user-or-llm","description":"Number of hits per page (default: 1000, max: 1000)"},"cursor":{"type":"string","required":false,"visibility":"user-or-llm","description":"Cursor from a previous browse response for pagination"},"aroundLatLng":{"type":"string","required":false,"visibility":"user-or-llm","description":"Coordinates for geo-search (e.g., \\"40.71,-74.01\\")"},"aroundRadius":{"type":"string","required":false,"visibility":"user-or-llm","description":"Maximum radius in meters for geo-search, or \\"all\\" for unlimited"},"insideBoundingBox":{"type":"json","required":false,"visibility":"user-or-llm","description":"Bounding box coordinates as [[lat1, lng1, lat2, lng2]] for geo-search"},"insidePolygon":{"type":"json","required":false,"visibility":"user-or-llm","description":"Polygon coordinates as [[lat1, lng1, lat2, lng2, lat3, lng3, ...]] for geo-search"}}},"algolia_clear_records":{"id":"algolia_clear_records","name":"Algolia Clear Records","description":"Clear all records from an Algolia index while keeping settings, synonyms, and rules","version":"1.0","params":{"applicationId":{"type":"string","required":true,"visibility":"user-only","description":"Algolia Application ID"},"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Algolia Admin API Key (must have deleteIndex ACL)"},"indexName":{"type":"string","required":true,"visibility":"user-or-llm","description":"Name of the Algolia index to clear"}}},"algolia_copy_move_index":{"id":"algolia_copy_move_index","name":"Algolia Copy/Move Index","description":"Copy or move an Algolia index to a new destination","version":"1.0","params":{"applicationId":{"type":"string","required":true,"visibility":"user-only","description":"Algolia Application ID"},"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Algolia Admin API Key"},"indexName":{"type":"string","required":true,"visibility":"user-or-llm","description":"Name of the source index"},"operation":{"type":"string","required":true,"visibility":"user-or-llm","description":"Operation to perform: \\"copy\\" or \\"move\\""},"destination":{"type":"string","required":true,"visibility":"user-or-llm","description":"Name of the destination index"},"scope":{"type":"json","required":false,"visibility":"user-or-llm","description":"Array of scopes to copy (only for \\"copy\\" operation): [\\"settings\\", \\"synonyms\\", \\"rules\\"]. Omit to copy everything including records."}}},"algolia_delete_by_filter":{"id":"algolia_delete_by_filter","name":"Algolia Delete By Filter","description":"Delete all records matching a filter from an Algolia index","version":"1.0","params":{"applicationId":{"type":"string","required":true,"visibility":"user-only","description":"Algolia Application ID"},"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Algolia Admin API Key (must have deleteIndex ACL)"},"indexName":{"type":"string","required":true,"visibility":"user-or-llm","description":"Name of the Algolia index"},"filters":{"type":"string","required":false,"visibility":"user-or-llm","description":"Filter expression to match records for deletion (e.g., \\"category:outdated\\")"},"facetFilters":{"type":"json","required":false,"visibility":"user-or-llm","description":"Array of facet filters (e.g., [\\"brand:Acme\\"])"},"numericFilters":{"type":"json","required":false,"visibility":"user-or-llm","description":"Array of numeric filters (e.g., [\\"price > 100\\"])"},"tagFilters":{"type":"json","required":false,"visibility":"user-or-llm","description":"Array of tag filters using the _tags attribute (e.g., [\\"published\\"])"},"aroundLatLng":{"type":"string","required":false,"visibility":"user-or-llm","description":"Coordinates for geo-search filter (e.g., \\"40.71,-74.01\\")"},"aroundRadius":{"type":"string","required":false,"visibility":"user-or-llm","description":"Maximum radius in meters for geo-search, or \\"all\\" for unlimited"},"insideBoundingBox":{"type":"json","required":false,"visibility":"user-or-llm","description":"Bounding box coordinates as [[lat1, lng1, lat2, lng2]] for geo-search filter"},"insidePolygon":{"type":"json","required":false,"visibility":"user-or-llm","description":"Polygon coordinates as [[lat1, lng1, lat2, lng2, lat3, lng3, ...]] for geo-search filter"}}},"algolia_delete_index":{"id":"algolia_delete_index","name":"Algolia Delete Index","description":"Delete an entire Algolia index and all its records","version":"1.0","params":{"applicationId":{"type":"string","required":true,"visibility":"user-only","description":"Algolia Application ID"},"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Algolia Admin API Key (must have deleteIndex ACL)"},"indexName":{"type":"string","required":true,"visibility":"user-or-llm","description":"Name of the Algolia index to delete"}}},"algolia_delete_record":{"id":"algolia_delete_record","name":"Algolia Delete Record","description":"Delete a record by objectID from an Algolia index","version":"1.0","params":{"applicationId":{"type":"string","required":true,"visibility":"user-only","description":"Algolia Application ID"},"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Algolia Admin API Key"},"indexName":{"type":"string","required":true,"visibility":"user-or-llm","description":"Name of the Algolia index"},"objectID":{"type":"string","required":true,"visibility":"user-or-llm","description":"The objectID of the record to delete"}}},"algolia_get_record":{"id":"algolia_get_record","name":"Algolia Get Record","description":"Get a record by objectID from an Algolia index","version":"1.0","params":{"applicationId":{"type":"string","required":true,"visibility":"user-only","description":"Algolia Application ID"},"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Algolia API Key"},"indexName":{"type":"string","required":true,"visibility":"user-or-llm","description":"Name of the Algolia index"},"objectID":{"type":"string","required":true,"visibility":"user-or-llm","description":"The objectID of the record to retrieve"},"attributesToRetrieve":{"type":"string","required":false,"visibility":"user-or-llm","description":"Comma-separated list of attributes to retrieve"}}},"algolia_get_records":{"id":"algolia_get_records","name":"Algolia Get Records","description":"Retrieve multiple records by objectID from one or more Algolia indices","version":"1.0","params":{"applicationId":{"type":"string","required":true,"visibility":"user-only","description":"Algolia Application ID"},"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Algolia API Key"},"indexName":{"type":"string","required":true,"visibility":"user-or-llm","description":"Default index name for all requests"},"requests":{"type":"json","required":true,"visibility":"user-or-llm","description":"Array of objects specifying records to retrieve. Each must have \\"objectID\\" and optionally \\"indexName\\" and \\"attributesToRetrieve\\"."}}},"algolia_get_settings":{"id":"algolia_get_settings","name":"Algolia Get Settings","description":"Retrieve the settings of an Algolia index","version":"1.0","params":{"applicationId":{"type":"string","required":true,"visibility":"user-only","description":"Algolia Application ID"},"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Algolia API Key"},"indexName":{"type":"string","required":true,"visibility":"user-or-llm","description":"Name of the Algolia index"}}},"algolia_get_task_status":{"id":"algolia_get_task_status","name":"Algolia Get Task Status","description":"Check whether an Algolia indexing task has finished publishing","version":"1.0","params":{"applicationId":{"type":"string","required":true,"visibility":"user-only","description":"Algolia Application ID"},"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Algolia API Key"},"indexName":{"type":"string","required":true,"visibility":"user-or-llm","description":"Name of the Algolia index the task ran against"},"taskID":{"type":"number","required":true,"visibility":"user-or-llm","description":"The taskID returned by a previous write operation"}}},"algolia_list_indices":{"id":"algolia_list_indices","name":"Algolia List Indices","description":"List all indices in an Algolia application","version":"1.0","params":{"applicationId":{"type":"string","required":true,"visibility":"user-only","description":"Algolia Application ID"},"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Algolia API Key"},"page":{"type":"number","required":false,"visibility":"user-or-llm","description":"Page number for paginating indices (default: not paginated)"},"hitsPerPage":{"type":"number","required":false,"visibility":"user-or-llm","description":"Number of indices per page (default: 100)"}}},"algolia_partial_update_record":{"id":"algolia_partial_update_record","name":"Algolia Partial Update Record","description":"Partially update a record in an Algolia index without replacing it entirely","version":"1.0","params":{"applicationId":{"type":"string","required":true,"visibility":"user-only","description":"Algolia Application ID"},"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Algolia Admin API Key"},"indexName":{"type":"string","required":true,"visibility":"user-or-llm","description":"Name of the Algolia index"},"objectID":{"type":"string","required":true,"visibility":"user-or-llm","description":"The objectID of the record to update"},"attributes":{"type":"json","required":true,"visibility":"user-or-llm","description":"JSON object with attributes to update. Supports built-in operations like {\\"stock\\": {\\"_operation\\": \\"Decrement\\", \\"value\\": 1}}"},"createIfNotExists":{"type":"boolean","required":false,"visibility":"user-or-llm","description":"Whether to create the record if it does not exist (default: true)"}}},"algolia_search":{"id":"algolia_search","name":"Algolia Search","description":"Search an Algolia index","version":"1.0","params":{"applicationId":{"type":"string","required":true,"visibility":"user-only","description":"Algolia Application ID"},"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Algolia API Key"},"indexName":{"type":"string","required":true,"visibility":"user-or-llm","description":"Name of the Algolia index to search"},"query":{"type":"string","required":true,"visibility":"user-or-llm","description":"Search query text"},"hitsPerPage":{"type":"number","required":false,"visibility":"user-or-llm","description":"Number of hits per page (default: 20)"},"page":{"type":"number","required":false,"visibility":"user-or-llm","description":"Page number to retrieve (default: 0)"},"filters":{"type":"string","required":false,"visibility":"user-or-llm","description":"Filter string (e.g., \\"category:electronics AND price < 100\\")"},"attributesToRetrieve":{"type":"string","required":false,"visibility":"user-or-llm","description":"Comma-separated list of attributes to retrieve"},"facets":{"type":"string","required":false,"visibility":"user-or-llm","description":"Comma-separated list of facet attribute names to retrieve counts for (use \\"*\\" for all)"},"getRankingInfo":{"type":"boolean","required":false,"visibility":"user-or-llm","description":"Whether to include detailed ranking information in each hit"},"aroundLatLng":{"type":"string","required":false,"visibility":"user-or-llm","description":"Coordinates for geo-search (e.g., \\"40.71,-74.01\\")"},"aroundRadius":{"type":"string","required":false,"visibility":"user-or-llm","description":"Maximum radius in meters for geo-search, or \\"all\\" for unlimited"},"insideBoundingBox":{"type":"json","required":false,"visibility":"user-or-llm","description":"Bounding box coordinates as [[lat1, lng1, lat2, lng2]] for geo-search"},"insidePolygon":{"type":"json","required":false,"visibility":"user-or-llm","description":"Polygon coordinates as [[lat1, lng1, lat2, lng2, lat3, lng3, ...]] for geo-search"}}},"algolia_update_settings":{"id":"algolia_update_settings","name":"Algolia Update Settings","description":"Update the settings of an Algolia index","version":"1.0","params":{"applicationId":{"type":"string","required":true,"visibility":"user-only","description":"Algolia Application ID"},"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Algolia Admin API Key (must have editSettings ACL)"},"indexName":{"type":"string","required":true,"visibility":"user-or-llm","description":"Name of the Algolia index"},"settings":{"type":"json","required":true,"visibility":"user-or-llm","description":"JSON object with settings to update (e.g., {\\"searchableAttributes\\": [\\"name\\", \\"description\\"], \\"customRanking\\": [\\"desc(popularity)\\"]})"},"forwardToReplicas":{"type":"boolean","required":false,"visibility":"user-or-llm","description":"Whether to apply changes to replica indices (default: false)"}}},"amplitude_event_segmentation":{"id":"amplitude_event_segmentation","name":"Amplitude Event Segmentation","description":"Query event analytics data with segmentation. Get event counts, uniques, averages, and more.","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Amplitude API Key"},"secretKey":{"type":"string","required":true,"visibility":"user-only","description":"Amplitude Secret Key"},"eventType":{"type":"string","required":true,"visibility":"user-or-llm","description":"Event type name to analyze"},"start":{"type":"string","required":true,"visibility":"user-or-llm","description":"Start date in YYYYMMDD format"},"end":{"type":"string","required":true,"visibility":"user-or-llm","description":"End date in YYYYMMDD format"},"metric":{"type":"string","required":false,"visibility":"user-or-llm","description":"Metric type: uniques, totals, pct_dau, average, histogram, sums, value_avg, or formula (default: uniques)"},"interval":{"type":"string","required":false,"visibility":"user-or-llm","description":"Time interval: 1 (daily), 7 (weekly), or 30 (monthly)"},"groupBy":{"type":"string","required":false,"visibility":"user-or-llm","description":"Property name to group by (prefix custom user properties with \\"gp:\\")"},"groupBy2":{"type":"string","required":false,"visibility":"user-or-llm","description":"Second property name to group by (prefix custom user properties with \\"gp:\\")"},"limit":{"type":"string","required":false,"visibility":"user-or-llm","description":"Maximum number of group-by values (max 1000)"},"filters":{"type":"string","required":false,"visibility":"user-or-llm","description":"JSON array of filter objects applied to the event, e.g. [{\\"subprop_type\\":\\"event\\",\\"subprop_key\\":\\"city\\",\\"subprop_op\\":\\"is\\",\\"subprop_value\\":[\\"San Francisco\\"]}]"},"formula":{"type":"string","required":false,"visibility":"user-or-llm","description":"Required when metric is \\"formula\\", e.g. \\"UNIQUES(A)/UNIQUES(B)\\""},"segment":{"type":"string","required":false,"visibility":"user-or-llm","description":"JSON segment definition(s) applied to the query"},"dataResidency":{"type":"string","required":false,"visibility":"user-or-llm","description":"Data residency region: \\"us\\" (default) or \\"eu\\""}}},"amplitude_funnels":{"id":"amplitude_funnels","name":"Amplitude Funnels","description":"Analyze conversion rates and drop-off between a sequence of events.","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Amplitude API Key"},"secretKey":{"type":"string","required":true,"visibility":"user-only","description":"Amplitude Secret Key"},"events":{"type":"string","required":true,"visibility":"user-or-llm","description":"JSON array of event objects, one per funnel step in order, e.g. [{\\"event_type\\":\\"signup\\"},{\\"event_type\\":\\"purchase\\"}]"},"start":{"type":"string","required":true,"visibility":"user-or-llm","description":"Start date in YYYYMMDD format"},"end":{"type":"string","required":true,"visibility":"user-or-llm","description":"End date in YYYYMMDD format"},"mode":{"type":"string","required":false,"visibility":"user-or-llm","description":"Funnel ordering: \\"ordered\\", \\"unordered\\", or \\"sequential\\" (default: ordered)"},"userType":{"type":"string","required":false,"visibility":"user-or-llm","description":"User type: \\"new\\" or \\"active\\" (default: active)"},"interval":{"type":"string","required":false,"visibility":"user-or-llm","description":"Time interval: -300000 (real-time), -3600000 (hourly), 1 (daily), 7 (weekly), or 30 (monthly)"},"conversionWindowSeconds":{"type":"string","required":false,"visibility":"user-or-llm","description":"Conversion window in seconds (default: 2592000, i.e. 30 days)"},"groupBy":{"type":"string","required":false,"visibility":"user-or-llm","description":"Property to group by (limit: one; prefix custom properties with \\"gp:\\")"},"limit":{"type":"string","required":false,"visibility":"user-or-llm","description":"Maximum number of group-by values (default: 100, max: 1000)"},"segment":{"type":"string","required":false,"visibility":"user-or-llm","description":"JSON segment definition(s) applied to the query"},"dataResidency":{"type":"string","required":false,"visibility":"user-or-llm","description":"Data residency region: \\"us\\" (default) or \\"eu\\""}}},"amplitude_get_active_users":{"id":"amplitude_get_active_users","name":"Amplitude Get Active Users","description":"Get active or new user counts over a date range from the Dashboard REST API.","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Amplitude API Key"},"secretKey":{"type":"string","required":true,"visibility":"user-only","description":"Amplitude Secret Key"},"start":{"type":"string","required":true,"visibility":"user-or-llm","description":"Start date in YYYYMMDD format"},"end":{"type":"string","required":true,"visibility":"user-or-llm","description":"End date in YYYYMMDD format"},"metric":{"type":"string","required":false,"visibility":"user-or-llm","description":"Metric type: \\"active\\" or \\"new\\" (default: active)"},"interval":{"type":"string","required":false,"visibility":"user-or-llm","description":"Time interval: 1 (daily), 7 (weekly), or 30 (monthly)"},"groupBy":{"type":"string","required":false,"visibility":"user-or-llm","description":"Property name to group by"},"segment":{"type":"string","required":false,"visibility":"user-or-llm","description":"JSON segment definition(s) applied to the query"},"dataResidency":{"type":"string","required":false,"visibility":"user-or-llm","description":"Data residency region: \\"us\\" (default) or \\"eu\\""}}},"amplitude_get_revenue":{"id":"amplitude_get_revenue","name":"Amplitude Get Revenue","description":"Get revenue LTV data including ARPU, ARPPU, total revenue, and paying user counts.","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Amplitude API Key"},"secretKey":{"type":"string","required":true,"visibility":"user-only","description":"Amplitude Secret Key"},"start":{"type":"string","required":true,"visibility":"user-or-llm","description":"Start date in YYYYMMDD format"},"end":{"type":"string","required":true,"visibility":"user-or-llm","description":"End date in YYYYMMDD format"},"metric":{"type":"string","required":false,"visibility":"user-or-llm","description":"Metric: 0 (ARPU), 1 (ARPPU), 2 (Total Revenue), 3 (Paying Users)"},"interval":{"type":"string","required":false,"visibility":"user-or-llm","description":"Time interval: 1 (daily), 7 (weekly), or 30 (monthly)"},"groupBy":{"type":"string","required":false,"visibility":"user-or-llm","description":"Property name to group by (limit: one)"},"segment":{"type":"string","required":false,"visibility":"user-or-llm","description":"JSON segment definition(s) applied to the query"},"dataResidency":{"type":"string","required":false,"visibility":"user-or-llm","description":"Data residency region: \\"us\\" (default) or \\"eu\\""}}},"amplitude_group_identify":{"id":"amplitude_group_identify","name":"Amplitude Group Identify","description":"Set group-level properties in Amplitude. Supports $set, $setOnce, $add, $append, $unset operations.","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Amplitude API Key"},"groupType":{"type":"string","required":true,"visibility":"user-or-llm","description":"Group classification (e.g., \\"company\\", \\"org_id\\")"},"groupValue":{"type":"string","required":true,"visibility":"user-or-llm","description":"Specific group identifier (e.g., \\"Acme Corp\\")"},"groupProperties":{"type":"string","required":true,"visibility":"user-or-llm","description":"JSON object of group properties. Use operations like $set, $setOnce, $add, $append, $unset."},"dataResidency":{"type":"string","required":false,"visibility":"user-or-llm","description":"Data residency region: \\"us\\" (default) or \\"eu\\""}}},"amplitude_identify_user":{"id":"amplitude_identify_user","name":"Amplitude Identify User","description":"Set user properties in Amplitude using the Identify API. Supports $set, $setOnce, $add, $append, $unset operations.","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Amplitude API Key"},"userId":{"type":"string","required":false,"visibility":"user-or-llm","description":"User ID (required if no device_id)"},"deviceId":{"type":"string","required":false,"visibility":"user-or-llm","description":"Device ID (required if no user_id)"},"userProperties":{"type":"string","required":true,"visibility":"user-or-llm","description":"JSON object of user properties. Use operations like $set, $setOnce, $add, $append, $unset."},"dataResidency":{"type":"string","required":false,"visibility":"user-or-llm","description":"Data residency region: \\"us\\" (default) or \\"eu\\""}}},"amplitude_list_events":{"id":"amplitude_list_events","name":"Amplitude List Events","description":"List all event types in the Amplitude project with their weekly totals and unique counts.","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Amplitude API Key"},"secretKey":{"type":"string","required":true,"visibility":"user-only","description":"Amplitude Secret Key"},"dataResidency":{"type":"string","required":false,"visibility":"user-or-llm","description":"Data residency region: \\"us\\" (default) or \\"eu\\""}}},"amplitude_realtime_active_users":{"id":"amplitude_realtime_active_users","name":"Amplitude Real-time Active Users","description":"Get real-time active user counts at 5-minute granularity for the last 2 days.","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Amplitude API Key"},"secretKey":{"type":"string","required":true,"visibility":"user-only","description":"Amplitude Secret Key"},"dataResidency":{"type":"string","required":false,"visibility":"user-or-llm","description":"Data residency region: \\"us\\" (default) or \\"eu\\""}}},"amplitude_retention":{"id":"amplitude_retention","name":"Amplitude Retention","description":"Measure how many users return to perform an action after a starting action.","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Amplitude API Key"},"secretKey":{"type":"string","required":true,"visibility":"user-only","description":"Amplitude Secret Key"},"startEvent":{"type":"string","required":true,"visibility":"user-or-llm","description":"JSON starting event object, e.g. {\\"event_type\\":\\"_new\\"} or {\\"event_type\\":\\"_active\\"}"},"returnEvent":{"type":"string","required":true,"visibility":"user-or-llm","description":"JSON returning event object, e.g. {\\"event_type\\":\\"_all\\"} or {\\"event_type\\":\\"_active\\"}"},"start":{"type":"string","required":true,"visibility":"user-or-llm","description":"Start date in YYYYMMDD format"},"end":{"type":"string","required":true,"visibility":"user-or-llm","description":"End date in YYYYMMDD format"},"retentionMode":{"type":"string","required":false,"visibility":"user-or-llm","description":"Retention type: \\"bracket\\", \\"rolling\\", or \\"n-day\\" (default: n-day)"},"retentionBrackets":{"type":"string","required":false,"visibility":"user-or-llm","description":"Required when Retention Mode is \\"bracket\\". Day ranges, e.g. [[0,4]]"},"interval":{"type":"string","required":false,"visibility":"user-or-llm","description":"Time interval: 1 (daily), 7 (weekly), or 30 (monthly)"},"groupBy":{"type":"string","required":false,"visibility":"user-or-llm","description":"Property to group by (limit: one; prefix custom properties with \\"gp:\\")"},"segment":{"type":"string","required":false,"visibility":"user-or-llm","description":"JSON segment definition(s) applied to the query"},"dataResidency":{"type":"string","required":false,"visibility":"user-or-llm","description":"Data residency region: \\"us\\" (default) or \\"eu\\""}}},"amplitude_send_event":{"id":"amplitude_send_event","name":"Amplitude Send Event","description":"Track an event in Amplitude using the HTTP V2 API.","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Amplitude API Key"},"userId":{"type":"string","required":false,"visibility":"user-or-llm","description":"User ID (required if no device_id)"},"deviceId":{"type":"string","required":false,"visibility":"user-or-llm","description":"Device ID (required if no user_id)"},"eventType":{"type":"string","required":true,"visibility":"user-or-llm","description":"Name of the event (e.g., \\"page_view\\", \\"purchase\\")"},"eventProperties":{"type":"string","required":false,"visibility":"user-or-llm","description":"JSON object of custom event properties"},"userProperties":{"type":"string","required":false,"visibility":"user-or-llm","description":"JSON object of user properties to set (supports $set, $setOnce, $add, $append, $unset)"},"time":{"type":"string","required":false,"visibility":"user-or-llm","description":"Event timestamp in milliseconds since epoch"},"sessionId":{"type":"string","required":false,"visibility":"user-or-llm","description":"Session start time in milliseconds since epoch"},"insertId":{"type":"string","required":false,"visibility":"user-or-llm","description":"Unique ID for deduplication (within 7-day window)"},"appVersion":{"type":"string","required":false,"visibility":"user-or-llm","description":"Application version string"},"platform":{"type":"string","required":false,"visibility":"user-or-llm","description":"Platform (e.g., \\"Web\\", \\"iOS\\", \\"Android\\")"},"country":{"type":"string","required":false,"visibility":"user-or-llm","description":"Two-letter country code"},"language":{"type":"string","required":false,"visibility":"user-or-llm","description":"Language code (e.g., \\"en\\")"},"ip":{"type":"string","required":false,"visibility":"user-or-llm","description":"IP address for geo-location"},"price":{"type":"string","required":false,"visibility":"user-or-llm","description":"Price of the item purchased"},"quantity":{"type":"string","required":false,"visibility":"user-or-llm","description":"Quantity of items purchased"},"revenue":{"type":"string","required":false,"visibility":"user-or-llm","description":"Revenue amount"},"productId":{"type":"string","required":false,"visibility":"user-or-llm","description":"Product identifier"},"revenueType":{"type":"string","required":false,"visibility":"user-or-llm","description":"Revenue type (e.g., \\"purchase\\", \\"refund\\")"},"dataResidency":{"type":"string","required":false,"visibility":"user-or-llm","description":"Data residency region: \\"us\\" (default) or \\"eu\\""}}},"amplitude_user_activity":{"id":"amplitude_user_activity","name":"Amplitude User Activity","description":"Get the event stream for a specific user by their Amplitude ID.","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Amplitude API Key"},"secretKey":{"type":"string","required":true,"visibility":"user-only","description":"Amplitude Secret Key"},"amplitudeId":{"type":"string","required":true,"visibility":"user-or-llm","description":"Amplitude internal user ID"},"offset":{"type":"string","required":false,"visibility":"user-or-llm","description":"Offset for pagination (default 0)"},"limit":{"type":"string","required":false,"visibility":"user-or-llm","description":"Maximum number of events to return (default 1000, max 1000)"},"direction":{"type":"string","required":false,"visibility":"user-or-llm","description":"Sort direction: \\"latest\\" or \\"earliest\\" (default: latest)"},"dataResidency":{"type":"string","required":false,"visibility":"user-or-llm","description":"Data residency region: \\"us\\" (default) or \\"eu\\""}}},"amplitude_user_profile":{"id":"amplitude_user_profile","name":"Amplitude User Profile","description":"Get a user profile including properties, cohort memberships, and computed properties. Not available for EU data-residency projects.","version":"1.0.0","params":{"secretKey":{"type":"string","required":true,"visibility":"user-only","description":"Amplitude Secret Key"},"userId":{"type":"string","required":false,"visibility":"user-or-llm","description":"External user ID (required if no device_id)"},"deviceId":{"type":"string","required":false,"visibility":"user-or-llm","description":"Device ID (required if no user_id)"},"getAmpProps":{"type":"string","required":false,"visibility":"user-or-llm","description":"Include Amplitude user properties (true/false, default: false)"},"getCohortIds":{"type":"string","required":false,"visibility":"user-or-llm","description":"Include cohort IDs the user belongs to (true/false, default: false)"},"getComputations":{"type":"string","required":false,"visibility":"user-or-llm","description":"Include computed user properties (true/false, default: false)"}}},"amplitude_user_search":{"id":"amplitude_user_search","name":"Amplitude User Search","description":"Search for a user by User ID, Device ID, or Amplitude ID using the Dashboard REST API.","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Amplitude API Key"},"secretKey":{"type":"string","required":true,"visibility":"user-only","description":"Amplitude Secret Key"},"user":{"type":"string","required":true,"visibility":"user-or-llm","description":"User ID, Device ID, or Amplitude ID to search for"},"dataResidency":{"type":"string","required":false,"visibility":"user-or-llm","description":"Data residency region: \\"us\\" (default) or \\"eu\\""}}},"apify_get_dataset_items":{"id":"apify_get_dataset_items","name":"APIFY Get Dataset Items","description":"Retrieve items stored in an APIFY dataset","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"APIFY API token from console.apify.com/account#/integrations"},"datasetId":{"type":"string","required":true,"visibility":"user-or-llm","description":"Dataset ID to read items from. Example: \\"9RnD3Pql2vGZkc5H5\\""},"itemLimit":{"type":"number","required":false,"visibility":"user-or-llm","description":"Max items to return (1-250000). Default: all items. Example: 500"},"offset":{"type":"number","required":false,"visibility":"user-or-llm","description":"Number of items to skip at the start. Default: 0"},"fields":{"type":"string","required":false,"visibility":"user-or-llm","description":"Comma-separated list of fields to include. Example: \\"title,url,price\\""}}},"apify_get_run":{"id":"apify_get_run","name":"APIFY Get Run","description":"Get the status and details of an APIFY actor run","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"APIFY API token from console.apify.com/account#/integrations"},"runId":{"type":"string","required":true,"visibility":"user-or-llm","description":"Actor run ID to fetch. Example: \\"HG7ML7M8z78YcAPEB\\""}}},"apify_run_actor_async":{"id":"apify_run_actor_async","name":"APIFY Run Actor (Async)","description":"Run an APIFY actor asynchronously with polling for long-running tasks","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"APIFY API token from console.apify.com/account#/integrations"},"actorId":{"type":"string","required":true,"visibility":"user-or-llm","description":"Actor ID or username/actor-name. Examples: \\"apify/web-scraper\\", \\"janedoe/my-actor\\", \\"moJRLRc85AitArpNN\\""},"input":{"type":"string","required":false,"visibility":"user-or-llm","description":"Actor input as JSON string. Example: {\\"startUrls\\": [{\\"url\\": \\"https://example.com\\"}], \\"maxPages\\": 10}"},"waitForFinish":{"type":"number","required":false,"visibility":"user-or-llm","description":"Initial wait time in seconds (0-60) before polling starts. Example: 30"},"itemLimit":{"type":"number","required":false,"default":100,"visibility":"user-or-llm","description":"Max dataset items to fetch (1-250000). Default: 100. Example: 500"},"memory":{"type":"number","required":false,"visibility":"user-or-llm","description":"Memory in megabytes allocated for the actor run (128-32768). Example: 1024 for 1GB, 2048 for 2GB"},"timeout":{"type":"number","required":false,"visibility":"user-or-llm","description":"Timeout in seconds for the actor run. Example: 300 for 5 minutes, 3600 for 1 hour"},"build":{"type":"string","required":false,"visibility":"user-or-llm","description":"Actor build to run. Examples: \\"latest\\", \\"beta\\", \\"1.2.3\\", \\"build-tag-name\\""}}},"apify_run_actor_sync":{"id":"apify_run_actor_sync","name":"APIFY Run Actor (Sync)","description":"Run an APIFY actor synchronously and get results (max 5 minutes)","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"APIFY API token from console.apify.com/account#/integrations"},"actorId":{"type":"string","required":true,"visibility":"user-or-llm","description":"Actor ID or username/actor-name. Examples: \\"apify/web-scraper\\", \\"janedoe/my-actor\\", \\"moJRLRc85AitArpNN\\""},"input":{"type":"string","required":false,"visibility":"user-or-llm","description":"Actor input as JSON string. Example: {\\"startUrls\\": [{\\"url\\": \\"https://example.com\\"}], \\"maxPages\\": 10}"},"memory":{"type":"number","required":false,"visibility":"user-or-llm","description":"Memory in megabytes allocated for the actor run (128-32768). Example: 1024 for 1GB, 2048 for 2GB"},"timeout":{"type":"number","required":false,"visibility":"user-or-llm","description":"Timeout in seconds for the actor run. Example: 300 for 5 minutes, 3600 for 1 hour"},"build":{"type":"string","required":false,"visibility":"user-or-llm","description":"Actor build to run. Examples: \\"latest\\", \\"beta\\", \\"1.2.3\\", \\"build-tag-name\\""}}},"apify_run_task":{"id":"apify_run_task","name":"APIFY Run Task","description":"Run a saved APIFY actor task synchronously and get dataset items (max 5 minutes)","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"APIFY API token from console.apify.com/account#/integrations"},"taskId":{"type":"string","required":true,"visibility":"user-or-llm","description":"Task ID or username/task-name. Examples: \\"janedoe/my-task\\", \\"moJRLRc85AitArpNN\\""},"input":{"type":"string","required":false,"visibility":"user-or-llm","description":"JSON string that overrides the task\'s saved input. Example: {\\"startUrls\\": [{\\"url\\": \\"https://example.com\\"}]}"},"itemLimit":{"type":"number","required":false,"visibility":"user-or-llm","description":"Max dataset items to return (1-250000). Example: 500"},"memory":{"type":"number","required":false,"visibility":"user-or-llm","description":"Memory in megabytes allocated for the run (128-32768). Example: 1024 for 1GB"},"timeout":{"type":"number","required":false,"visibility":"user-or-llm","description":"Timeout in seconds for the run. Example: 300 for 5 minutes"},"build":{"type":"string","required":false,"visibility":"user-or-llm","description":"Actor build to run. Examples: \\"latest\\", \\"beta\\", \\"1.2.3\\""}}},"apollo_account_bulk_create":{"id":"apollo_account_bulk_create","name":"Apollo Bulk Create Accounts","description":"Create up to 100 accounts at once in your Apollo database. Set run_dedupe=true to deduplicate by domain, organization_id, and name. Master key required.","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Apollo API key (master key required)"},"accounts":{"type":"array","required":true,"visibility":"user-or-llm","description":"Array of accounts to create (max 100). Each account should include a name, and may optionally include domain, phone, phone_status_cd, raw_address, owner_id, linkedin_url, facebook_url, twitter_url, salesforce_id, and hubspot_id."},"append_label_names":{"type":"array","required":false,"visibility":"user-only","description":"Array of label names to add to ALL accounts in this request"},"run_dedupe":{"type":"boolean","required":false,"visibility":"user-or-llm","description":"When true, performs aggressive deduplication by domain, organization_id, and name (defaults to false)"}}},"apollo_account_bulk_update":{"id":"apollo_account_bulk_update","name":"Apollo Bulk Update Accounts","description":"Update up to 1000 existing accounts at once in your Apollo database (higher limit than contacts!). Each account must include an id field. Master key required.","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Apollo API key (master key required)"},"account_ids":{"type":"array","required":false,"visibility":"user-or-llm","description":"Array of account IDs to update with the same values (max 1000). Use with name/owner_id for uniform updates. Use either this OR account_attributes."},"name":{"type":"string","required":false,"visibility":"user-or-llm","description":"When using account_ids, apply this name to all accounts"},"owner_id":{"type":"string","required":false,"visibility":"user-or-llm","description":"When using account_ids, apply this owner to all accounts"},"account_stage_id":{"type":"string","required":false,"visibility":"user-or-llm","description":"When using account_ids, apply this account stage to all accounts"},"account_attributes":{"type":"json","required":false,"visibility":"user-or-llm","description":"Array of account objects with individual updates (each must include id). Example: [{\\"id\\": \\"acc1\\", \\"name\\": \\"Acme\\", \\"owner_id\\": \\"u1\\", \\"account_stage_id\\": \\"s1\\", \\"typed_custom_fields\\": {\\"field_id\\": \\"value\\"}}]"},"async":{"type":"boolean","required":false,"visibility":"user-only","description":"When true, processes the update asynchronously. Only supported when using account_ids; returns 422 if used with account_attributes."}}},"apollo_account_create":{"id":"apollo_account_create","name":"Apollo Create Account","description":"Create a new account (company) in your Apollo database","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Apollo API key (master key required)"},"name":{"type":"string","required":true,"visibility":"user-or-llm","description":"Company name (e.g., \\"Acme Corporation\\")"},"domain":{"type":"string","required":false,"visibility":"user-or-llm","description":"Company domain without www. prefix (e.g., \\"acme.com\\")"},"phone":{"type":"string","required":false,"visibility":"user-or-llm","description":"Primary phone number for the account"},"owner_id":{"type":"string","required":false,"visibility":"user-only","description":"Apollo user ID of the account owner"},"account_stage_id":{"type":"string","required":false,"visibility":"user-only","description":"Apollo ID for the account stage to assign this account to"},"raw_address":{"type":"string","required":false,"visibility":"user-or-llm","description":"Corporate location (e.g., \\"San Francisco, CA, USA\\")"},"typed_custom_fields":{"type":"json","required":false,"visibility":"user-only","description":"Custom field values as { custom_field_id: value } map"}}},"apollo_account_search":{"id":"apollo_account_search","name":"Apollo Search Accounts","description":"Search your team\'s accounts in Apollo. Display limit: 50,000 records (100 records per page, 500 pages max). Use filters to narrow results. Master key required.","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Apollo API key (master key required)"},"q_organization_name":{"type":"string","required":false,"visibility":"user-or-llm","description":"Filter accounts by organization name (partial-match search)"},"account_stage_ids":{"type":"array","required":false,"visibility":"user-only","description":"Filter by account stage IDs"},"account_label_ids":{"type":"array","required":false,"visibility":"user-only","description":"Filter by account label IDs"},"sort_by_field":{"type":"string","required":false,"visibility":"user-or-llm","description":"Sort field: \\"account_last_activity_date\\", \\"account_created_at\\", or \\"account_updated_at\\""},"sort_ascending":{"type":"boolean","required":false,"visibility":"user-or-llm","description":"Sort ascending when true. Defaults to descending."},"page":{"type":"number","required":false,"visibility":"user-or-llm","description":"Page number for pagination (e.g., 1, 2, 3)"},"per_page":{"type":"number","required":false,"visibility":"user-or-llm","description":"Results per page, max 100 (e.g., 25, 50, 100)"}}},"apollo_account_update":{"id":"apollo_account_update","name":"Apollo Update Account","description":"Update an existing account in your Apollo database","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Apollo API key"},"account_id":{"type":"string","required":true,"visibility":"user-or-llm","description":"ID of the account to update (e.g., \\"acc_abc123\\")"},"name":{"type":"string","required":false,"visibility":"user-or-llm","description":"Company name (e.g., \\"Acme Corporation\\")"},"domain":{"type":"string","required":false,"visibility":"user-or-llm","description":"Company domain (e.g., \\"acme.com\\")"},"phone":{"type":"string","required":false,"visibility":"user-or-llm","description":"Company phone number"},"owner_id":{"type":"string","required":false,"visibility":"user-only","description":"Apollo user ID of the account owner"},"account_stage_id":{"type":"string","required":false,"visibility":"user-only","description":"Apollo ID for the account stage to assign this account to"},"raw_address":{"type":"string","required":false,"visibility":"user-or-llm","description":"Corporate location (e.g., \\"San Francisco, CA, USA\\")"},"typed_custom_fields":{"type":"json","required":false,"visibility":"user-only","description":"Custom field values as { custom_field_id: value } map"}}},"apollo_contact_bulk_create":{"id":"apollo_contact_bulk_create","name":"Apollo Bulk Create Contacts","description":"Create up to 100 contacts at once in your Apollo database. Supports deduplication to prevent creating duplicate contacts. Master key required.","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Apollo API key (master key required)"},"contacts":{"type":"array","required":true,"visibility":"user-or-llm","description":"Array of contacts to create (max 100). Each contact may include first_name, last_name, email, title, organization_name, account_id, owner_id, contact_stage_id, linkedin_url, phone (single string) or phone_numbers (array of {raw_number, position}), contact_emails, typed_custom_fields, and CRM IDs (salesforce_contact_id, hubspot_id, team_id) for cross-system matching"},"append_label_names":{"type":"array","required":false,"visibility":"user-or-llm","description":"Label names to add to all contacts in this request (e.g., [\\"Hot Lead\\"])"},"run_dedupe":{"type":"boolean","required":false,"visibility":"user-only","description":"Enable deduplication to prevent creating duplicate contacts. When true, existing contacts are returned without modification"}}},"apollo_contact_bulk_update":{"id":"apollo_contact_bulk_update","name":"Apollo Bulk Update Contacts","description":"Update up to 100 existing contacts at once in your Apollo database. Each contact must include an id field. Master key required.","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Apollo API key (master key required)"},"contact_ids":{"type":"array","required":false,"visibility":"user-or-llm","description":"Array of contact IDs to update. Must be paired with an object-form contact_attributes specifying the fields to apply uniformly to all listed contacts."},"contact_attributes":{"type":"json","required":false,"visibility":"user-or-llm","description":"Required. Either an array of per-contact updates (each with id) — used standalone — or a single object of attributes to apply to all contact_ids. Supported fields: owner_id, email, organization_name, title, first_name, last_name, account_id, present_raw_address, linkedin_url, typed_custom_fields"},"async":{"type":"boolean","required":false,"visibility":"user-only","description":"Force asynchronous processing. Automatically enabled for >100 contacts"}}},"apollo_contact_create":{"id":"apollo_contact_create","name":"Apollo Create Contact","description":"Create a new contact in your Apollo database","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Apollo API key"},"first_name":{"type":"string","required":true,"visibility":"user-or-llm","description":"First name of the contact"},"last_name":{"type":"string","required":true,"visibility":"user-or-llm","description":"Last name of the contact"},"email":{"type":"string","required":false,"visibility":"user-or-llm","description":"Email address of the contact"},"title":{"type":"string","required":false,"visibility":"user-or-llm","description":"Job title (e.g., \\"VP of Sales\\", \\"Software Engineer\\")"},"account_id":{"type":"string","required":false,"visibility":"user-or-llm","description":"Apollo account ID to associate with (e.g., \\"acc_abc123\\")"},"owner_id":{"type":"string","required":false,"visibility":"user-only","description":"User ID of the contact owner (accepted by Apollo but not officially documented for POST /contacts)"},"organization_name":{"type":"string","required":false,"visibility":"user-or-llm","description":"Name of the contact\'s employer (e.g., \\"Apollo\\")"},"website_url":{"type":"string","required":false,"visibility":"user-or-llm","description":"Corporate website URL (e.g., \\"https://www.apollo.io/\\")"},"label_names":{"type":"array","required":false,"visibility":"user-or-llm","description":"Lists/labels to add the contact to (e.g., [\\"Prospects\\"])"},"contact_stage_id":{"type":"string","required":false,"visibility":"user-or-llm","description":"Apollo ID for the contact stage"},"present_raw_address":{"type":"string","required":false,"visibility":"user-or-llm","description":"Personal location for the contact (e.g., \\"Atlanta, United States\\")"},"direct_phone":{"type":"string","required":false,"visibility":"user-or-llm","description":"Primary phone number"},"corporate_phone":{"type":"string","required":false,"visibility":"user-or-llm","description":"Work/office phone number"},"mobile_phone":{"type":"string","required":false,"visibility":"user-or-llm","description":"Mobile phone number"},"home_phone":{"type":"string","required":false,"visibility":"user-or-llm","description":"Home phone number"},"other_phone":{"type":"string","required":false,"visibility":"user-or-llm","description":"Alternative phone number"},"typed_custom_fields":{"type":"json","required":false,"visibility":"user-or-llm","description":"Custom field values keyed by custom field ID"},"run_dedupe":{"type":"boolean","required":false,"visibility":"user-only","description":"When true, Apollo deduplicates against existing contacts"}}},"apollo_contact_search":{"id":"apollo_contact_search","name":"Apollo Search Contacts","description":"Search your team\'s contacts in Apollo","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Apollo API key"},"q_keywords":{"type":"string","required":false,"visibility":"user-or-llm","description":"Keywords to search for"},"contact_stage_ids":{"type":"array","required":false,"visibility":"user-only","description":"Filter by contact stage IDs"},"contact_label_ids":{"type":"array","required":false,"visibility":"user-only","description":"Filter by Apollo label IDs (lists)"},"sort_by_field":{"type":"string","required":false,"visibility":"user-only","description":"Sort field: contact_last_activity_date, contact_email_last_opened_at, contact_email_last_clicked_at, contact_created_at, or contact_updated_at"},"sort_ascending":{"type":"boolean","required":false,"visibility":"user-only","description":"When true, sort ascending. Must be used together with sort_by_field"},"page":{"type":"number","required":false,"visibility":"user-or-llm","description":"Page number for pagination (e.g., 1, 2, 3)"},"per_page":{"type":"number","required":false,"visibility":"user-or-llm","description":"Results per page, max 100 (e.g., 25, 50, 100)"}}},"apollo_contact_update":{"id":"apollo_contact_update","name":"Apollo Update Contact","description":"Update an existing contact in your Apollo database","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Apollo API key"},"contact_id":{"type":"string","required":true,"visibility":"user-or-llm","description":"ID of the contact to update (e.g., \\"con_abc123\\")"},"first_name":{"type":"string","required":false,"visibility":"user-or-llm","description":"First name of the contact"},"last_name":{"type":"string","required":false,"visibility":"user-or-llm","description":"Last name of the contact"},"email":{"type":"string","required":false,"visibility":"user-or-llm","description":"Email address"},"title":{"type":"string","required":false,"visibility":"user-or-llm","description":"Job title (e.g., \\"VP of Sales\\", \\"Software Engineer\\")"},"account_id":{"type":"string","required":false,"visibility":"user-or-llm","description":"Apollo account ID (e.g., \\"acc_abc123\\")"},"owner_id":{"type":"string","required":false,"visibility":"user-only","description":"User ID of the contact owner (accepted by Apollo but not officially documented for PATCH /contacts/{id})"},"organization_name":{"type":"string","required":false,"visibility":"user-or-llm","description":"Name of the contact\'s employer (e.g., \\"Apollo\\")"},"website_url":{"type":"string","required":false,"visibility":"user-or-llm","description":"Corporate website URL (e.g., \\"https://www.apollo.io/\\")"},"label_names":{"type":"array","required":false,"visibility":"user-or-llm","description":"Lists/labels to add the contact to (e.g., [\\"Prospects\\"])"},"contact_stage_id":{"type":"string","required":false,"visibility":"user-or-llm","description":"Apollo ID for the contact stage"},"present_raw_address":{"type":"string","required":false,"visibility":"user-or-llm","description":"Personal location for the contact (e.g., \\"Atlanta, United States\\")"},"direct_phone":{"type":"string","required":false,"visibility":"user-or-llm","description":"Primary phone number"},"corporate_phone":{"type":"string","required":false,"visibility":"user-or-llm","description":"Work/office phone number"},"mobile_phone":{"type":"string","required":false,"visibility":"user-or-llm","description":"Mobile phone number"},"home_phone":{"type":"string","required":false,"visibility":"user-or-llm","description":"Home phone number"},"other_phone":{"type":"string","required":false,"visibility":"user-or-llm","description":"Alternative phone number"},"typed_custom_fields":{"type":"json","required":false,"visibility":"user-or-llm","description":"Custom field values keyed by custom field ID"}}},"apollo_email_accounts":{"id":"apollo_email_accounts","name":"Apollo Get Email Accounts","description":"Get list of team\'s linked email accounts in Apollo","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Apollo API key (master key required)"}}},"apollo_opportunity_create":{"id":"apollo_opportunity_create","name":"Apollo Create Opportunity","description":"Create a new deal for an account in your Apollo database (master key required)","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Apollo API key (master key required)"},"name":{"type":"string","required":true,"visibility":"user-or-llm","description":"Name of the opportunity/deal (e.g., \\"Enterprise License - Q1\\")"},"account_id":{"type":"string","required":false,"visibility":"user-or-llm","description":"ID of the account this opportunity belongs to (e.g., \\"acc_abc123\\")"},"amount":{"type":"string","required":false,"visibility":"user-or-llm","description":"Monetary value as a plain number string with no commas or currency symbols"},"opportunity_stage_id":{"type":"string","required":false,"visibility":"user-only","description":"ID of the opportunity stage"},"owner_id":{"type":"string","required":false,"visibility":"user-only","description":"User ID of the opportunity owner"},"closed_date":{"type":"string","required":false,"visibility":"user-or-llm","description":"Expected close date in YYYY-MM-DD format"},"typed_custom_fields":{"type":"json","required":false,"visibility":"user-only","description":"Custom field values as { custom_field_id: value } map"}}},"apollo_opportunity_get":{"id":"apollo_opportunity_get","name":"Apollo Get Opportunity","description":"Retrieve complete details of a specific deal/opportunity by ID","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Apollo API key"},"opportunity_id":{"type":"string","required":true,"visibility":"user-or-llm","description":"ID of the opportunity to retrieve (e.g., \\"opp_abc123\\")"}}},"apollo_opportunity_search":{"id":"apollo_opportunity_search","name":"Apollo Search Opportunities","description":"Search and list all deals/opportunities in your team\'s Apollo account","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Apollo API key"},"sort_by_field":{"type":"string","required":false,"visibility":"user-or-llm","description":"Sort field: \\"amount\\", \\"is_closed\\", or \\"is_won\\""},"page":{"type":"number","required":false,"visibility":"user-or-llm","description":"Page number for pagination (e.g., 1, 2, 3)"},"per_page":{"type":"number","required":false,"visibility":"user-or-llm","description":"Results per page, max 100 (e.g., 25, 50, 100)"}}},"apollo_opportunity_update":{"id":"apollo_opportunity_update","name":"Apollo Update Opportunity","description":"Update an existing deal/opportunity in your Apollo database","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Apollo API key"},"opportunity_id":{"type":"string","required":true,"visibility":"user-or-llm","description":"ID of the opportunity to update (e.g., \\"opp_abc123\\")"},"name":{"type":"string","required":false,"visibility":"user-or-llm","description":"Name of the opportunity/deal (e.g., \\"Enterprise License - Q1\\")"},"amount":{"type":"string","required":false,"visibility":"user-or-llm","description":"Monetary value as a plain number string with no commas or currency symbols"},"opportunity_stage_id":{"type":"string","required":false,"visibility":"user-only","description":"ID of the opportunity stage"},"owner_id":{"type":"string","required":false,"visibility":"user-only","description":"User ID of the opportunity owner"},"closed_date":{"type":"string","required":false,"visibility":"user-or-llm","description":"Expected close date in YYYY-MM-DD format"},"typed_custom_fields":{"type":"json","required":false,"visibility":"user-only","description":"Custom field values as { custom_field_id: value } map"}}},"apollo_organization_bulk_enrich":{"id":"apollo_organization_bulk_enrich","name":"Apollo Bulk Organization Enrichment","description":"Enrich data for up to 10 organizations at once using Apollo","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Apollo API key"},"domains":{"type":"array","required":true,"visibility":"user-or-llm","description":"Array of company domains to enrich (max 10, no www. or @, e.g., [\\"apollo.io\\", \\"stripe.com\\"])"}}},"apollo_organization_enrich":{"id":"apollo_organization_enrich","name":"Apollo Organization Enrichment","description":"Enrich data for a single organization using Apollo","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Apollo API key"},"domain":{"type":"string","required":true,"visibility":"user-or-llm","description":"Company domain (e.g., \\"apollo.io\\", \\"acme.com\\")"}}},"apollo_organization_search":{"id":"apollo_organization_search","name":"Apollo Organization Search","description":"Search Apollo\'s database for companies using filters","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Apollo API key"},"organization_locations":{"type":"array","required":false,"visibility":"user-or-llm","description":"Company HQ locations (cities, US states, or countries)"},"organization_not_locations":{"type":"array","required":false,"visibility":"user-or-llm","description":"Exclude companies whose HQ is in these locations"},"organization_num_employees_ranges":{"type":"array","required":false,"visibility":"user-or-llm","description":"Employee count ranges as \\"min,max\\" strings (e.g., [\\"1,10\\", \\"250,500\\", \\"10000,20000\\"])"},"q_organization_keyword_tags":{"type":"array","required":false,"visibility":"user-or-llm","description":"Industry or keyword tags"},"q_organization_name":{"type":"string","required":false,"visibility":"user-or-llm","description":"Organization name to search for (e.g., \\"Acme\\", \\"TechCorp\\")"},"organization_ids":{"type":"array","required":false,"visibility":"user-or-llm","description":"Apollo organization IDs to include (e.g., [\\"5e66b6381e05b4008c8331b8\\"])"},"q_organization_domains_list":{"type":"array","required":false,"visibility":"user-or-llm","description":"Domain names to filter by (no www. or @, up to 1,000)"},"page":{"type":"number","required":false,"visibility":"user-or-llm","description":"Page number for pagination (e.g., 1, 2, 3)"},"per_page":{"type":"number","required":false,"visibility":"user-or-llm","description":"Results per page, max 100 (e.g., 25, 50, 100)"}}},"apollo_people_bulk_enrich":{"id":"apollo_people_bulk_enrich","name":"Apollo Bulk People Enrichment","description":"Enrich data for up to 10 people at once using Apollo","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Apollo API key"},"people":{"type":"array","required":true,"visibility":"user-or-llm","description":"Array of people to enrich (max 10)"},"reveal_personal_emails":{"type":"boolean","required":false,"visibility":"user-only","description":"Reveal personal email addresses (uses credits)"},"reveal_phone_number":{"type":"boolean","required":false,"visibility":"user-only","description":"Reveal phone numbers (uses credits, requires webhook_url)"},"webhook_url":{"type":"string","required":false,"visibility":"user-only","description":"Webhook URL for async phone number delivery (required when reveal_phone_number is true)"}}},"apollo_people_enrich":{"id":"apollo_people_enrich","name":"Apollo People Enrichment","description":"Enrich data for a single person using Apollo","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Apollo API key"},"first_name":{"type":"string","required":false,"visibility":"user-or-llm","description":"First name of the person"},"last_name":{"type":"string","required":false,"visibility":"user-or-llm","description":"Last name of the person"},"name":{"type":"string","required":false,"visibility":"user-or-llm","description":"Full name of the person (alternative to first_name/last_name)"},"id":{"type":"string","required":false,"visibility":"user-or-llm","description":"Apollo ID for the person"},"hashed_email":{"type":"string","required":false,"visibility":"user-or-llm","description":"MD5 or SHA-256 hashed email"},"email":{"type":"string","required":false,"visibility":"user-or-llm","description":"Email address of the person"},"organization_name":{"type":"string","required":false,"visibility":"user-or-llm","description":"Company name where the person works"},"domain":{"type":"string","required":false,"visibility":"user-or-llm","description":"Company domain (e.g., \\"apollo.io\\", \\"acme.com\\")"},"linkedin_url":{"type":"string","required":false,"visibility":"user-or-llm","description":"LinkedIn profile URL"},"reveal_personal_emails":{"type":"boolean","required":false,"visibility":"user-only","description":"Reveal personal email addresses (uses credits)"},"reveal_phone_number":{"type":"boolean","required":false,"visibility":"user-only","description":"Reveal phone numbers (uses credits, requires webhook_url)"},"webhook_url":{"type":"string","required":false,"visibility":"user-only","description":"Webhook URL for async phone number delivery (required when reveal_phone_number is true)"}}},"apollo_people_search":{"id":"apollo_people_search","name":"Apollo People Search","description":"Search Apollo\'s database for people using demographic filters","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Apollo API key"},"person_titles":{"type":"array","required":false,"visibility":"user-or-llm","description":"Job titles to search for (e.g., [\\"CEO\\", \\"VP of Sales\\"])"},"include_similar_titles":{"type":"boolean","required":false,"visibility":"user-or-llm","description":"Whether to return people with job titles similar to person_titles"},"person_locations":{"type":"array","required":false,"visibility":"user-or-llm","description":"Locations to search in (e.g., [\\"San Francisco, CA\\", \\"New York, NY\\"])"},"person_seniorities":{"type":"array","required":false,"visibility":"user-or-llm","description":"Seniority levels (one of: owner, founder, c_suite, partner, vp, head, director, manager, senior, entry, intern)"},"organization_ids":{"type":"array","required":false,"visibility":"user-or-llm","description":"Apollo organization IDs to filter by (e.g., [\\"5e66b6381e05b4008c8331b8\\"])"},"organization_names":{"type":"array","required":false,"visibility":"user-or-llm","description":"Company names to search within (legacy filter)"},"organization_locations":{"type":"array","required":false,"visibility":"user-or-llm","description":"Headquarters locations of the people\'s current employer (e.g., [\'texas\', \'tokyo\', \'spain\'])"},"q_organization_domains_list":{"type":"array","required":false,"visibility":"user-or-llm","description":"Employer domain names (e.g., [\\"apollo.io\\", \\"microsoft.com\\"]) — up to 1,000, no www. or @"},"organization_num_employees_ranges":{"type":"array","required":false,"visibility":"user-or-llm","description":"Employee count ranges for the person\'s current employer. Each entry is \\"min,max\\" (e.g., [\\"1,10\\", \\"250,500\\", \\"10000,20000\\"])"},"contact_email_status":{"type":"array","required":false,"visibility":"user-or-llm","description":"Email statuses to filter by: \\"verified\\", \\"unverified\\", \\"likely to engage\\", \\"unavailable\\""},"q_keywords":{"type":"string","required":false,"visibility":"user-or-llm","description":"Keywords to search for"},"page":{"type":"number","required":false,"visibility":"user-or-llm","description":"Page number for pagination, default 1 (e.g., 1, 2, 3)"},"per_page":{"type":"number","required":false,"visibility":"user-or-llm","description":"Results per page, default 25, max 100 (e.g., 25, 50, 100)"}}},"apollo_sequence_add_contacts":{"id":"apollo_sequence_add_contacts","name":"Apollo Add Contacts to Sequence","description":"Add contacts to an Apollo sequence","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Apollo API key (master key required)"},"sequence_id":{"type":"string","required":true,"visibility":"user-or-llm","description":"ID of the sequence to add contacts to (e.g., \\"seq_abc123\\")"},"contact_ids":{"type":"array","required":false,"visibility":"user-or-llm","description":"Array of contact IDs to add to the sequence (e.g., [\\"con_abc123\\", \\"con_def456\\"]). Either contact_ids or label_names must be provided."},"label_names":{"type":"array","required":false,"visibility":"user-or-llm","description":"Array of label names to identify contacts to add to the sequence. Either contact_ids or label_names must be provided."},"send_email_from_email_account_id":{"type":"string","required":true,"visibility":"user-or-llm","description":"ID of the email account to send from. Use the Get Email Accounts operation to look this up."},"send_email_from_email_address":{"type":"string","required":false,"visibility":"user-only","description":"Specific email address to send from within the email account."},"sequence_no_email":{"type":"boolean","required":false,"visibility":"user-only","description":"Add contacts even if they have no email address"},"sequence_unverified_email":{"type":"boolean","required":false,"visibility":"user-only","description":"Add contacts with unverified email addresses"},"sequence_job_change":{"type":"boolean","required":false,"visibility":"user-only","description":"Add contacts who recently changed jobs"},"sequence_active_in_other_campaigns":{"type":"boolean","required":false,"visibility":"user-only","description":"Add contacts active in other campaigns"},"sequence_finished_in_other_campaigns":{"type":"boolean","required":false,"visibility":"user-only","description":"Add contacts who finished other campaigns"},"sequence_same_company_in_same_campaign":{"type":"boolean","required":false,"visibility":"user-only","description":"Add contacts even if others from the same company are in the sequence"},"contacts_without_ownership_permission":{"type":"boolean","required":false,"visibility":"user-only","description":"Add contacts without ownership permission"},"add_if_in_queue":{"type":"boolean","required":false,"visibility":"user-only","description":"Add contacts even if they are in the queue"},"contact_verification_skipped":{"type":"boolean","required":false,"visibility":"user-only","description":"Skip contact verification when adding"},"user_id":{"type":"string","required":false,"visibility":"user-only","description":"ID of the user performing the action"},"status":{"type":"string","required":false,"visibility":"user-only","description":"Initial status for added contacts: \\"active\\" or \\"paused\\""},"auto_unpause_at":{"type":"string","required":false,"visibility":"user-only","description":"ISO 8601 datetime to automatically unpause contacts"}}},"apollo_sequence_search":{"id":"apollo_sequence_search","name":"Apollo Search Sequences","description":"Search for sequences/campaigns in your team\'s Apollo account (master key required)","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Apollo API key (master key required)"},"q_name":{"type":"string","required":false,"visibility":"user-or-llm","description":"Search sequences by name (e.g., \\"Outbound Q1\\", \\"Follow-up\\")"},"page":{"type":"number","required":false,"visibility":"user-or-llm","description":"Page number for pagination (e.g., 1, 2, 3)"},"per_page":{"type":"number","required":false,"visibility":"user-or-llm","description":"Results per page, max 100 (e.g., 25, 50, 100)"}}},"apollo_task_create":{"id":"apollo_task_create","name":"Apollo Create Task","description":"Create one or more tasks in Apollo (one task per contact_id, master key required)","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Apollo API key (master key required)"},"user_id":{"type":"string","required":true,"visibility":"user-or-llm","description":"ID of the Apollo user the task is assigned to"},"contact_ids":{"type":"array","required":true,"visibility":"user-or-llm","description":"Array of contact IDs. One task is created per contact."},"priority":{"type":"string","required":false,"visibility":"user-or-llm","description":"Task priority: \\"high\\", \\"medium\\", or \\"low\\" (defaults to \\"medium\\")"},"due_at":{"type":"string","required":true,"visibility":"user-or-llm","description":"Due date/time in ISO 8601 format (e.g., \\"2024-12-31T23:59:59Z\\")"},"type":{"type":"string","required":true,"visibility":"user-or-llm","description":"Task type: \\"call\\", \\"outreach_manual_email\\", \\"linkedin_step_connect\\", \\"linkedin_step_message\\", \\"linkedin_step_view_profile\\", \\"linkedin_step_interact_post\\", or \\"action_item\\""},"status":{"type":"string","required":true,"visibility":"user-or-llm","description":"Task status: \\"scheduled\\", \\"completed\\", or \\"skipped\\""},"note":{"type":"string","required":false,"visibility":"user-or-llm","description":"Free-form note providing context for the task"}}},"apollo_task_search":{"id":"apollo_task_search","name":"Apollo Search Tasks","description":"Search for tasks in Apollo","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Apollo API key (master key required)"},"sort_by_field":{"type":"string","required":false,"visibility":"user-or-llm","description":"Sort field: \\"task_due_at\\" or \\"task_priority\\""},"open_factor_names":{"type":"array","required":false,"visibility":"user-or-llm","description":"Filter by status. Common values: [\\"task_types\\"] for open tasks, [\\"task_completed_at\\"] for completed tasks."},"page":{"type":"number","required":false,"visibility":"user-or-llm","description":"Page number for pagination (e.g., 1, 2, 3)"},"per_page":{"type":"number","required":false,"visibility":"user-or-llm","description":"Results per page, max 100 (e.g., 25, 50, 100)"}}},"appconfig_create_application":{"id":"appconfig_create_application","name":"AppConfig Create Application","description":"Create an application in AWS AppConfig","version":"1.0","params":{"region":{"type":"string","required":true,"visibility":"user-only","description":"AWS region (e.g., us-east-1)"},"accessKeyId":{"type":"string","required":true,"visibility":"user-only","description":"AWS access key ID"},"secretAccessKey":{"type":"string","required":true,"visibility":"user-only","description":"AWS secret access key"},"name":{"type":"string","required":true,"visibility":"user-or-llm","description":"Name of the application to create"},"description":{"type":"string","required":false,"visibility":"user-or-llm","description":"Description of the application"}}},"appconfig_create_configuration_profile":{"id":"appconfig_create_configuration_profile","name":"AppConfig Create Configuration Profile","description":"Create a configuration profile in an AWS AppConfig application","version":"1.0","params":{"region":{"type":"string","required":true,"visibility":"user-only","description":"AWS region (e.g., us-east-1)"},"accessKeyId":{"type":"string","required":true,"visibility":"user-only","description":"AWS access key ID"},"secretAccessKey":{"type":"string","required":true,"visibility":"user-only","description":"AWS secret access key"},"applicationId":{"type":"string","required":true,"visibility":"user-or-llm","description":"The application ID to create the configuration profile in"},"name":{"type":"string","required":true,"visibility":"user-or-llm","description":"Name of the configuration profile"},"locationUri":{"type":"string","required":true,"visibility":"user-or-llm","description":"Where the configuration is stored. Use \\"hosted\\" for AppConfig-hosted configurations, or an SSM/S3 URI"},"description":{"type":"string","required":false,"visibility":"user-or-llm","description":"Description of the configuration profile"},"retrievalRoleArn":{"type":"string","required":false,"visibility":"user-or-llm","description":"ARN of an IAM role to retrieve the configuration (required for non-hosted URIs)"},"type":{"type":"string","required":false,"visibility":"user-or-llm","description":"Profile type: AWS.Freeform (default) or AWS.AppConfig.FeatureFlags"}}},"appconfig_create_environment":{"id":"appconfig_create_environment","name":"AppConfig Create Environment","description":"Create an environment for an AWS AppConfig application","version":"1.0","params":{"region":{"type":"string","required":true,"visibility":"user-only","description":"AWS region (e.g., us-east-1)"},"accessKeyId":{"type":"string","required":true,"visibility":"user-only","description":"AWS access key ID"},"secretAccessKey":{"type":"string","required":true,"visibility":"user-only","description":"AWS secret access key"},"applicationId":{"type":"string","required":true,"visibility":"user-or-llm","description":"The application ID to create the environment in"},"name":{"type":"string","required":true,"visibility":"user-or-llm","description":"Name of the environment to create"},"description":{"type":"string","required":false,"visibility":"user-or-llm","description":"Description of the environment"}}},"appconfig_create_hosted_configuration_version":{"id":"appconfig_create_hosted_configuration_version","name":"AppConfig Create Hosted Configuration Version","description":"Create a new hosted configuration version for an AppConfig configuration profile","version":"1.0","params":{"region":{"type":"string","required":true,"visibility":"user-only","description":"AWS region (e.g., us-east-1)"},"accessKeyId":{"type":"string","required":true,"visibility":"user-only","description":"AWS access key ID"},"secretAccessKey":{"type":"string","required":true,"visibility":"user-only","description":"AWS secret access key"},"applicationId":{"type":"string","required":true,"visibility":"user-or-llm","description":"The application ID that owns the configuration profile"},"configurationProfileId":{"type":"string","required":true,"visibility":"user-or-llm","description":"The configuration profile ID to add the version to"},"content":{"type":"string","required":true,"visibility":"user-or-llm","description":"The configuration content (e.g., a JSON or YAML document)"},"contentType":{"type":"string","required":true,"visibility":"user-or-llm","description":"Content type of the configuration (e.g., application/json, text/plain)"},"description":{"type":"string","required":false,"visibility":"user-or-llm","description":"Description of the configuration version"},"latestVersionNumber":{"type":"number","required":false,"visibility":"user-or-llm","description":"The version number of the latest version, used for optimistic concurrency"},"versionLabel":{"type":"string","required":false,"visibility":"user-or-llm","description":"A user-defined label for the configuration version"}}},"appconfig_delete_application":{"id":"appconfig_delete_application","name":"AppConfig Delete Application","description":"Delete an AWS AppConfig application","version":"1.0","params":{"region":{"type":"string","required":true,"visibility":"user-only","description":"AWS region (e.g., us-east-1)"},"accessKeyId":{"type":"string","required":true,"visibility":"user-only","description":"AWS access key ID"},"secretAccessKey":{"type":"string","required":true,"visibility":"user-only","description":"AWS secret access key"},"applicationId":{"type":"string","required":true,"visibility":"user-or-llm","description":"The application ID to delete"}}},"appconfig_delete_configuration_profile":{"id":"appconfig_delete_configuration_profile","name":"AppConfig Delete Configuration Profile","description":"Delete an AWS AppConfig configuration profile","version":"1.0","params":{"region":{"type":"string","required":true,"visibility":"user-only","description":"AWS region (e.g., us-east-1)"},"accessKeyId":{"type":"string","required":true,"visibility":"user-only","description":"AWS access key ID"},"secretAccessKey":{"type":"string","required":true,"visibility":"user-only","description":"AWS secret access key"},"applicationId":{"type":"string","required":true,"visibility":"user-or-llm","description":"The application ID that owns the configuration profile"},"configurationProfileId":{"type":"string","required":true,"visibility":"user-or-llm","description":"The configuration profile ID to delete"}}},"appconfig_delete_environment":{"id":"appconfig_delete_environment","name":"AppConfig Delete Environment","description":"Delete an AWS AppConfig environment","version":"1.0","params":{"region":{"type":"string","required":true,"visibility":"user-only","description":"AWS region (e.g., us-east-1)"},"accessKeyId":{"type":"string","required":true,"visibility":"user-only","description":"AWS access key ID"},"secretAccessKey":{"type":"string","required":true,"visibility":"user-only","description":"AWS secret access key"},"applicationId":{"type":"string","required":true,"visibility":"user-or-llm","description":"The application ID that owns the environment"},"environmentId":{"type":"string","required":true,"visibility":"user-or-llm","description":"The environment ID to delete"}}},"appconfig_delete_hosted_configuration_version":{"id":"appconfig_delete_hosted_configuration_version","name":"AppConfig Delete Hosted Configuration Version","description":"Delete a specific hosted configuration version from an AppConfig profile","version":"1.0","params":{"region":{"type":"string","required":true,"visibility":"user-only","description":"AWS region (e.g., us-east-1)"},"accessKeyId":{"type":"string","required":true,"visibility":"user-only","description":"AWS access key ID"},"secretAccessKey":{"type":"string","required":true,"visibility":"user-only","description":"AWS secret access key"},"applicationId":{"type":"string","required":true,"visibility":"user-or-llm","description":"The application ID that owns the configuration profile"},"configurationProfileId":{"type":"string","required":true,"visibility":"user-or-llm","description":"The configuration profile ID that owns the version"},"versionNumber":{"type":"number","required":true,"visibility":"user-or-llm","description":"The version number to delete"}}},"appconfig_get_application":{"id":"appconfig_get_application","name":"AppConfig Get Application","description":"Get details about a single AWS AppConfig application","version":"1.0","params":{"region":{"type":"string","required":true,"visibility":"user-only","description":"AWS region (e.g., us-east-1)"},"accessKeyId":{"type":"string","required":true,"visibility":"user-only","description":"AWS access key ID"},"secretAccessKey":{"type":"string","required":true,"visibility":"user-only","description":"AWS secret access key"},"applicationId":{"type":"string","required":true,"visibility":"user-or-llm","description":"The application ID to retrieve"}}},"appconfig_get_configuration":{"id":"appconfig_get_configuration","name":"AppConfig Get Configuration","description":"Retrieve the latest deployed configuration for an AppConfig application, environment, and profile","version":"1.0","params":{"region":{"type":"string","required":true,"visibility":"user-only","description":"AWS region (e.g., us-east-1)"},"accessKeyId":{"type":"string","required":true,"visibility":"user-only","description":"AWS access key ID"},"secretAccessKey":{"type":"string","required":true,"visibility":"user-only","description":"AWS secret access key"},"applicationId":{"type":"string","required":true,"visibility":"user-or-llm","description":"The application ID or name to retrieve configuration for"},"environmentId":{"type":"string","required":true,"visibility":"user-or-llm","description":"The environment ID or name to retrieve configuration for"},"configurationProfileId":{"type":"string","required":true,"visibility":"user-or-llm","description":"The configuration profile ID or name to retrieve"}}},"appconfig_get_configuration_profile":{"id":"appconfig_get_configuration_profile","name":"AppConfig Get Configuration Profile","description":"Get details about a single AWS AppConfig configuration profile","version":"1.0","params":{"region":{"type":"string","required":true,"visibility":"user-only","description":"AWS region (e.g., us-east-1)"},"accessKeyId":{"type":"string","required":true,"visibility":"user-only","description":"AWS access key ID"},"secretAccessKey":{"type":"string","required":true,"visibility":"user-only","description":"AWS secret access key"},"applicationId":{"type":"string","required":true,"visibility":"user-or-llm","description":"The application ID that owns the configuration profile"},"configurationProfileId":{"type":"string","required":true,"visibility":"user-or-llm","description":"The configuration profile ID to retrieve"}}},"appconfig_get_deployment":{"id":"appconfig_get_deployment","name":"AppConfig Get Deployment","description":"Get details about a specific AWS AppConfig deployment","version":"1.0","params":{"region":{"type":"string","required":true,"visibility":"user-only","description":"AWS region (e.g., us-east-1)"},"accessKeyId":{"type":"string","required":true,"visibility":"user-only","description":"AWS access key ID"},"secretAccessKey":{"type":"string","required":true,"visibility":"user-only","description":"AWS secret access key"},"applicationId":{"type":"string","required":true,"visibility":"user-or-llm","description":"The application ID of the deployment"},"environmentId":{"type":"string","required":true,"visibility":"user-or-llm","description":"The environment ID of the deployment"},"deploymentNumber":{"type":"number","required":true,"visibility":"user-or-llm","description":"The sequence number of the deployment"}}},"appconfig_get_environment":{"id":"appconfig_get_environment","name":"AppConfig Get Environment","description":"Get details about a single AWS AppConfig environment","version":"1.0","params":{"region":{"type":"string","required":true,"visibility":"user-only","description":"AWS region (e.g., us-east-1)"},"accessKeyId":{"type":"string","required":true,"visibility":"user-only","description":"AWS access key ID"},"secretAccessKey":{"type":"string","required":true,"visibility":"user-only","description":"AWS secret access key"},"applicationId":{"type":"string","required":true,"visibility":"user-or-llm","description":"The application ID that owns the environment"},"environmentId":{"type":"string","required":true,"visibility":"user-or-llm","description":"The environment ID to retrieve"}}},"appconfig_get_hosted_configuration_version":{"id":"appconfig_get_hosted_configuration_version","name":"AppConfig Get Hosted Configuration Version","description":"Retrieve a specific hosted configuration version from an AppConfig profile","version":"1.0","params":{"region":{"type":"string","required":true,"visibility":"user-only","description":"AWS region (e.g., us-east-1)"},"accessKeyId":{"type":"string","required":true,"visibility":"user-only","description":"AWS access key ID"},"secretAccessKey":{"type":"string","required":true,"visibility":"user-only","description":"AWS secret access key"},"applicationId":{"type":"string","required":true,"visibility":"user-or-llm","description":"The application ID that owns the configuration profile"},"configurationProfileId":{"type":"string","required":true,"visibility":"user-or-llm","description":"The configuration profile ID to read the version from"},"versionNumber":{"type":"number","required":true,"visibility":"user-or-llm","description":"The version number to retrieve"}}},"appconfig_list_applications":{"id":"appconfig_list_applications","name":"AppConfig List Applications","description":"List applications in AWS AppConfig","version":"1.0","params":{"region":{"type":"string","required":true,"visibility":"user-only","description":"AWS region (e.g., us-east-1)"},"accessKeyId":{"type":"string","required":true,"visibility":"user-only","description":"AWS access key ID"},"secretAccessKey":{"type":"string","required":true,"visibility":"user-only","description":"AWS secret access key"},"maxResults":{"type":"number","required":false,"visibility":"user-or-llm","description":"Maximum number of applications to return (1-50)"},"nextToken":{"type":"string","required":false,"visibility":"user-or-llm","description":"Pagination token from a previous response"}}},"appconfig_list_configuration_profiles":{"id":"appconfig_list_configuration_profiles","name":"AppConfig List Configuration Profiles","description":"List configuration profiles for an AWS AppConfig application","version":"1.0","params":{"region":{"type":"string","required":true,"visibility":"user-only","description":"AWS region (e.g., us-east-1)"},"accessKeyId":{"type":"string","required":true,"visibility":"user-only","description":"AWS access key ID"},"secretAccessKey":{"type":"string","required":true,"visibility":"user-only","description":"AWS secret access key"},"applicationId":{"type":"string","required":true,"visibility":"user-or-llm","description":"The application ID that owns the configuration profiles"},"maxResults":{"type":"number","required":false,"visibility":"user-or-llm","description":"Maximum number of configuration profiles to return (1-50)"},"nextToken":{"type":"string","required":false,"visibility":"user-or-llm","description":"Pagination token from a previous response"}}},"appconfig_list_deployment_strategies":{"id":"appconfig_list_deployment_strategies","name":"AppConfig List Deployment Strategies","description":"List deployment strategies available in AWS AppConfig","version":"1.0","params":{"region":{"type":"string","required":true,"visibility":"user-only","description":"AWS region (e.g., us-east-1)"},"accessKeyId":{"type":"string","required":true,"visibility":"user-only","description":"AWS access key ID"},"secretAccessKey":{"type":"string","required":true,"visibility":"user-only","description":"AWS secret access key"},"maxResults":{"type":"number","required":false,"visibility":"user-or-llm","description":"Maximum number of deployment strategies to return (1-50)"},"nextToken":{"type":"string","required":false,"visibility":"user-or-llm","description":"Pagination token from a previous response"}}},"appconfig_list_deployments":{"id":"appconfig_list_deployments","name":"AppConfig List Deployments","description":"List deployments for an AWS AppConfig environment","version":"1.0","params":{"region":{"type":"string","required":true,"visibility":"user-only","description":"AWS region (e.g., us-east-1)"},"accessKeyId":{"type":"string","required":true,"visibility":"user-only","description":"AWS access key ID"},"secretAccessKey":{"type":"string","required":true,"visibility":"user-only","description":"AWS secret access key"},"applicationId":{"type":"string","required":true,"visibility":"user-or-llm","description":"The application ID of the deployments"},"environmentId":{"type":"string","required":true,"visibility":"user-or-llm","description":"The environment ID of the deployments"},"maxResults":{"type":"number","required":false,"visibility":"user-or-llm","description":"Maximum number of deployments to return (1-50)"},"nextToken":{"type":"string","required":false,"visibility":"user-or-llm","description":"Pagination token from a previous response"}}},"appconfig_list_environments":{"id":"appconfig_list_environments","name":"AppConfig List Environments","description":"List environments for an AWS AppConfig application","version":"1.0","params":{"region":{"type":"string","required":true,"visibility":"user-only","description":"AWS region (e.g., us-east-1)"},"accessKeyId":{"type":"string","required":true,"visibility":"user-only","description":"AWS access key ID"},"secretAccessKey":{"type":"string","required":true,"visibility":"user-only","description":"AWS secret access key"},"applicationId":{"type":"string","required":true,"visibility":"user-or-llm","description":"The application ID that owns the environments"},"maxResults":{"type":"number","required":false,"visibility":"user-or-llm","description":"Maximum number of environments to return (1-50)"},"nextToken":{"type":"string","required":false,"visibility":"user-or-llm","description":"Pagination token from a previous response"}}},"appconfig_list_hosted_configuration_versions":{"id":"appconfig_list_hosted_configuration_versions","name":"AppConfig List Hosted Configuration Versions","description":"List hosted configuration versions for an AWS AppConfig configuration profile","version":"1.0","params":{"region":{"type":"string","required":true,"visibility":"user-only","description":"AWS region (e.g., us-east-1)"},"accessKeyId":{"type":"string","required":true,"visibility":"user-only","description":"AWS access key ID"},"secretAccessKey":{"type":"string","required":true,"visibility":"user-only","description":"AWS secret access key"},"applicationId":{"type":"string","required":true,"visibility":"user-or-llm","description":"The application ID that owns the configuration profile"},"configurationProfileId":{"type":"string","required":true,"visibility":"user-or-llm","description":"The configuration profile ID to list versions for"},"maxResults":{"type":"number","required":false,"visibility":"user-or-llm","description":"Maximum number of versions to return (1-50)"},"nextToken":{"type":"string","required":false,"visibility":"user-or-llm","description":"Pagination token from a previous response"}}},"appconfig_start_deployment":{"id":"appconfig_start_deployment","name":"AppConfig Start Deployment","description":"Start deploying a configuration version to an AWS AppConfig environment","version":"1.0","params":{"region":{"type":"string","required":true,"visibility":"user-only","description":"AWS region (e.g., us-east-1)"},"accessKeyId":{"type":"string","required":true,"visibility":"user-only","description":"AWS access key ID"},"secretAccessKey":{"type":"string","required":true,"visibility":"user-only","description":"AWS secret access key"},"applicationId":{"type":"string","required":true,"visibility":"user-or-llm","description":"The application ID to deploy in"},"environmentId":{"type":"string","required":true,"visibility":"user-or-llm","description":"The environment ID to deploy to"},"deploymentStrategyId":{"type":"string","required":true,"visibility":"user-or-llm","description":"The deployment strategy ID to use"},"configurationProfileId":{"type":"string","required":true,"visibility":"user-or-llm","description":"The configuration profile ID to deploy"},"configurationVersion":{"type":"string","required":true,"visibility":"user-or-llm","description":"The configuration version to deploy"},"description":{"type":"string","required":false,"visibility":"user-or-llm","description":"Description of the deployment"}}},"appconfig_stop_deployment":{"id":"appconfig_stop_deployment","name":"AppConfig Stop Deployment","description":"Stop an in-progress AWS AppConfig deployment","version":"1.0","params":{"region":{"type":"string","required":true,"visibility":"user-only","description":"AWS region (e.g., us-east-1)"},"accessKeyId":{"type":"string","required":true,"visibility":"user-only","description":"AWS access key ID"},"secretAccessKey":{"type":"string","required":true,"visibility":"user-only","description":"AWS secret access key"},"applicationId":{"type":"string","required":true,"visibility":"user-or-llm","description":"The application ID of the deployment"},"environmentId":{"type":"string","required":true,"visibility":"user-or-llm","description":"The environment ID of the deployment"},"deploymentNumber":{"type":"number","required":true,"visibility":"user-or-llm","description":"The sequence number of the deployment to stop"}}},"appconfig_update_application":{"id":"appconfig_update_application","name":"AppConfig Update Application","description":"Update the name or description of an AWS AppConfig application","version":"1.0","params":{"region":{"type":"string","required":true,"visibility":"user-only","description":"AWS region (e.g., us-east-1)"},"accessKeyId":{"type":"string","required":true,"visibility":"user-only","description":"AWS access key ID"},"secretAccessKey":{"type":"string","required":true,"visibility":"user-only","description":"AWS secret access key"},"applicationId":{"type":"string","required":true,"visibility":"user-or-llm","description":"The application ID to update"},"name":{"type":"string","required":false,"visibility":"user-or-llm","description":"New name for the application"},"description":{"type":"string","required":false,"visibility":"user-or-llm","description":"New description for the application"}}},"appconfig_update_configuration_profile":{"id":"appconfig_update_configuration_profile","name":"AppConfig Update Configuration Profile","description":"Update the name, description, or retrieval role of an AppConfig configuration profile","version":"1.0","params":{"region":{"type":"string","required":true,"visibility":"user-only","description":"AWS region (e.g., us-east-1)"},"accessKeyId":{"type":"string","required":true,"visibility":"user-only","description":"AWS access key ID"},"secretAccessKey":{"type":"string","required":true,"visibility":"user-only","description":"AWS secret access key"},"applicationId":{"type":"string","required":true,"visibility":"user-or-llm","description":"The application ID that owns the configuration profile"},"configurationProfileId":{"type":"string","required":true,"visibility":"user-or-llm","description":"The configuration profile ID to update"},"name":{"type":"string","required":false,"visibility":"user-or-llm","description":"New name for the configuration profile"},"description":{"type":"string","required":false,"visibility":"user-or-llm","description":"New description for the configuration profile"},"retrievalRoleArn":{"type":"string","required":false,"visibility":"user-or-llm","description":"New ARN of the IAM role used to retrieve the configuration"}}},"appconfig_update_environment":{"id":"appconfig_update_environment","name":"AppConfig Update Environment","description":"Update the name or description of an AWS AppConfig environment","version":"1.0","params":{"region":{"type":"string","required":true,"visibility":"user-only","description":"AWS region (e.g., us-east-1)"},"accessKeyId":{"type":"string","required":true,"visibility":"user-only","description":"AWS access key ID"},"secretAccessKey":{"type":"string","required":true,"visibility":"user-only","description":"AWS secret access key"},"applicationId":{"type":"string","required":true,"visibility":"user-or-llm","description":"The application ID that owns the environment"},"environmentId":{"type":"string","required":true,"visibility":"user-or-llm","description":"The environment ID to update"},"name":{"type":"string","required":false,"visibility":"user-or-llm","description":"New name for the environment"},"description":{"type":"string","required":false,"visibility":"user-or-llm","description":"New description for the environment"}}},"arxiv_get_author_papers":{"id":"arxiv_get_author_papers","name":"ArXiv Get Author Papers","description":"Search for papers by a specific author on ArXiv.","version":"1.0.0","params":{"authorName":{"type":"string","required":true,"visibility":"user-or-llm","description":"Author name to search for"},"maxResults":{"type":"number","required":false,"visibility":"user-only","description":"Maximum number of results to return (default: 10, max: 2000)"}}},"arxiv_get_paper":{"id":"arxiv_get_paper","name":"ArXiv Get Paper","description":"Get detailed information about a specific ArXiv paper by its ID.","version":"1.0.0","params":{"paperId":{"type":"string","required":true,"visibility":"user-or-llm","description":"ArXiv paper ID (e.g., \\"1706.03762\\")"}}},"arxiv_search":{"id":"arxiv_search","name":"ArXiv Search","description":"Search for academic papers on ArXiv by keywords, authors, titles, or other fields.","version":"1.0.0","params":{"searchQuery":{"type":"string","required":true,"visibility":"user-or-llm","description":"The search query to execute"},"searchField":{"type":"string","required":false,"visibility":"user-only","description":"Field to search in: all, ti (title), au (author), abs (abstract), co (comment), jr (journal), cat (category), rn (report number)"},"maxResults":{"type":"number","required":false,"visibility":"user-only","description":"Maximum number of results to return (default: 10, max: 2000)"},"sortBy":{"type":"string","required":false,"visibility":"user-only","description":"Sort by: relevance, lastUpdatedDate, submittedDate (default: relevance)"},"sortOrder":{"type":"string","required":false,"visibility":"user-only","description":"Sort order: ascending, descending (default: descending)"}}},"asana_add_comment":{"id":"asana_add_comment","name":"Asana Add Comment","description":"Add a comment (story) to an Asana task","version":"1.0.0","params":{"accessToken":{"type":"string","required":true,"visibility":"hidden","description":"OAuth access token for Asana"},"taskGid":{"type":"string","required":true,"visibility":"user-or-llm","description":"Asana task GID (numeric string)"},"text":{"type":"string","required":true,"visibility":"user-or-llm","description":"The text content of the comment"}},"oauth":{"required":true,"provider":"asana"}},"asana_add_followers":{"id":"asana_add_followers","name":"Asana Add Followers","description":"Add one or more followers to an Asana task","version":"1.0.0","params":{"accessToken":{"type":"string","required":true,"visibility":"hidden","description":"OAuth access token for Asana"},"taskGid":{"type":"string","required":true,"visibility":"user-or-llm","description":"GID of the Asana task (numeric string)"},"followers":{"type":"array","required":true,"visibility":"user-or-llm","description":"Array of user GIDs to add as followers to the task"}},"oauth":{"required":true,"provider":"asana"}},"asana_create_project":{"id":"asana_create_project","name":"Asana Create Project","description":"Create a new project in an Asana workspace","version":"1.0.0","params":{"accessToken":{"type":"string","required":true,"visibility":"hidden","description":"OAuth access token for Asana"},"workspace":{"type":"string","required":true,"visibility":"user-or-llm","description":"Asana workspace GID (numeric string) where the project will be created"},"name":{"type":"string","required":true,"visibility":"user-or-llm","description":"Name of the project"},"notes":{"type":"string","required":false,"visibility":"user-or-llm","description":"Notes or description for the project"}},"oauth":{"required":true,"provider":"asana"}},"asana_create_section":{"id":"asana_create_section","name":"Asana Create Section","description":"Create a new section in an Asana project","version":"1.0.0","params":{"accessToken":{"type":"string","required":true,"visibility":"hidden","description":"OAuth access token for Asana"},"projectGid":{"type":"string","required":true,"visibility":"user-or-llm","description":"GID of the Asana project (numeric string) to add the section to"},"name":{"type":"string","required":true,"visibility":"user-or-llm","description":"Name of the section"}},"oauth":{"required":true,"provider":"asana"}},"asana_create_subtask":{"id":"asana_create_subtask","name":"Asana Create Subtask","description":"Create a subtask under an existing Asana task","version":"1.0.0","params":{"accessToken":{"type":"string","required":true,"visibility":"hidden","description":"OAuth access token for Asana"},"taskGid":{"type":"string","required":true,"visibility":"user-or-llm","description":"GID of the parent Asana task (numeric string)"},"name":{"type":"string","required":true,"visibility":"user-or-llm","description":"Name of the subtask"},"notes":{"type":"string","required":false,"visibility":"user-or-llm","description":"Notes or description for the subtask"},"assignee":{"type":"string","required":false,"visibility":"user-or-llm","description":"User GID to assign the subtask to"},"due_on":{"type":"string","required":false,"visibility":"user-or-llm","description":"Due date in YYYY-MM-DD format"}},"oauth":{"required":true,"provider":"asana"}},"asana_create_task":{"id":"asana_create_task","name":"Asana Create Task","description":"Create a new task in Asana","version":"1.0.0","params":{"accessToken":{"type":"string","required":true,"visibility":"hidden","description":"OAuth access token for Asana"},"workspace":{"type":"string","required":true,"visibility":"user-or-llm","description":"Asana workspace GID (numeric string) where the task will be created"},"name":{"type":"string","required":true,"visibility":"user-or-llm","description":"Name of the task"},"notes":{"type":"string","required":false,"visibility":"user-or-llm","description":"Notes or description for the task"},"assignee":{"type":"string","required":false,"visibility":"user-or-llm","description":"User GID to assign the task to"},"due_on":{"type":"string","required":false,"visibility":"user-or-llm","description":"Due date in YYYY-MM-DD format"}},"oauth":{"required":true,"provider":"asana"}},"asana_delete_task":{"id":"asana_delete_task","name":"Asana Delete Task","description":"Delete an Asana task by its GID (moves it to the trash)","version":"1.0.0","params":{"accessToken":{"type":"string","required":true,"visibility":"hidden","description":"OAuth access token for Asana"},"taskGid":{"type":"string","required":true,"visibility":"user-or-llm","description":"GID of the Asana task to delete (numeric string)"}},"oauth":{"required":true,"provider":"asana"}},"asana_get_project":{"id":"asana_get_project","name":"Asana Get Project","description":"Retrieve a single Asana project by its GID","version":"1.0.0","params":{"accessToken":{"type":"string","required":true,"visibility":"hidden","description":"OAuth access token for Asana"},"projectGid":{"type":"string","required":true,"visibility":"user-or-llm","description":"Asana project GID (numeric string) to retrieve"}},"oauth":{"required":true,"provider":"asana"}},"asana_get_projects":{"id":"asana_get_projects","name":"Asana Get Projects","description":"Retrieve all projects from an Asana workspace","version":"1.0.0","params":{"accessToken":{"type":"string","required":true,"visibility":"hidden","description":"OAuth access token for Asana"},"workspace":{"type":"string","required":true,"visibility":"user-or-llm","description":"Asana workspace GID (numeric string) to retrieve projects from"}},"oauth":{"required":true,"provider":"asana"}},"asana_get_task":{"id":"asana_get_task","name":"Asana Get Task","description":"Retrieve a single task by GID or get multiple tasks with filters","version":"1.0.0","params":{"accessToken":{"type":"string","required":true,"visibility":"hidden","description":"OAuth access token for Asana"},"taskGid":{"type":"string","required":false,"visibility":"user-or-llm","description":"The globally unique identifier (GID) of the task. If not provided, will get multiple tasks."},"workspace":{"type":"string","required":false,"visibility":"user-or-llm","description":"Asana workspace GID (numeric string) to filter tasks (required when not using taskGid)"},"project":{"type":"string","required":false,"visibility":"user-or-llm","description":"Asana project GID (numeric string) to filter tasks"},"limit":{"type":"number","required":false,"visibility":"user-or-llm","description":"Maximum number of tasks to return (default: 50)"}},"oauth":{"required":true,"provider":"asana"}},"asana_list_sections":{"id":"asana_list_sections","name":"Asana List Sections","description":"List all sections in an Asana project","version":"1.0.0","params":{"accessToken":{"type":"string","required":true,"visibility":"hidden","description":"OAuth access token for Asana"},"projectGid":{"type":"string","required":true,"visibility":"user-or-llm","description":"GID of the Asana project (numeric string) to list sections from"}},"oauth":{"required":true,"provider":"asana"}},"asana_list_workspaces":{"id":"asana_list_workspaces","name":"Asana List Workspaces","description":"List all Asana workspaces and organizations the authenticated user belongs to","version":"1.0.0","params":{"accessToken":{"type":"string","required":true,"visibility":"hidden","description":"OAuth access token for Asana"}},"oauth":{"required":true,"provider":"asana"}},"asana_search_tasks":{"id":"asana_search_tasks","name":"Asana Search Tasks","description":"Search for tasks in an Asana workspace","version":"1.0.0","params":{"accessToken":{"type":"string","required":true,"visibility":"hidden","description":"OAuth access token for Asana"},"workspace":{"type":"string","required":true,"visibility":"user-or-llm","description":"Asana workspace GID (numeric string) to search tasks in"},"text":{"type":"string","required":false,"visibility":"user-or-llm","description":"Text to search for in task names"},"assignee":{"type":"string","required":false,"visibility":"user-or-llm","description":"Filter tasks by assignee user GID"},"projects":{"type":"array","required":false,"visibility":"user-or-llm","description":"Array of Asana project GIDs (numeric strings) to filter tasks by"},"completed":{"type":"boolean","required":false,"visibility":"user-or-llm","description":"Filter by completion status"}},"oauth":{"required":true,"provider":"asana"}},"asana_update_task":{"id":"asana_update_task","name":"Asana Update Task","description":"Update an existing task in Asana","version":"1.0.0","params":{"accessToken":{"type":"string","required":true,"visibility":"hidden","description":"OAuth access token for Asana"},"taskGid":{"type":"string","required":true,"visibility":"user-or-llm","description":"Asana task GID (numeric string) of the task to update"},"name":{"type":"string","required":false,"visibility":"user-or-llm","description":"Updated name for the task"},"notes":{"type":"string","required":false,"visibility":"user-or-llm","description":"Updated notes or description for the task"},"assignee":{"type":"string","required":false,"visibility":"user-or-llm","description":"Updated assignee user GID"},"completed":{"type":"boolean","required":false,"visibility":"user-or-llm","description":"Mark task as completed or not completed"},"due_on":{"type":"string","required":false,"visibility":"user-or-llm","description":"Updated due date in YYYY-MM-DD format"}},"oauth":{"required":true,"provider":"asana"}},"ashby_add_candidate_tag":{"id":"ashby_add_candidate_tag","name":"Ashby Add Candidate Tag","description":"Adds a tag to a candidate in Ashby and returns the updated candidate.","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Ashby API Key"},"candidateId":{"type":"string","required":true,"visibility":"user-or-llm","description":"The UUID of the candidate to add the tag to"},"tagId":{"type":"string","required":true,"visibility":"user-or-llm","description":"The UUID of the tag to add"}}},"ashby_anonymize_candidate":{"id":"ashby_anonymize_candidate","name":"Ashby Anonymize Candidate","description":"Strips personally identifiable information from a candidate in Ashby. This does not delete the candidate - the record and its applications remain, with the PII removed. Ashby exposes no candidate deletion endpoint; true deletion is UI-only, restricted by role, and limited to a 10-day window. Requires the candidatesWrite permission.","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Ashby API Key"},"candidateId":{"type":"string","required":true,"visibility":"user-or-llm","description":"UUID of the candidate to anonymize"}}},"ashby_change_application_source":{"id":"ashby_change_application_source","name":"Ashby Change Application Source","description":"Changes the source attributed to an existing application, so programmatically created applications report correctly on the recruiting side. Requires the candidatesWrite permission.","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Ashby API Key"},"applicationId":{"type":"string","required":true,"visibility":"user-or-llm","description":"UUID of the application whose source should change"},"sourceId":{"type":"string","required":false,"visibility":"user-or-llm","description":"UUID of the source to attribute the application to, as returned by List Sources. Omit only when unsetSource is true."},"unsetSource":{"type":"boolean","required":false,"visibility":"user-or-llm","description":"Set true to deliberately clear the application source. Required to unset, so that a missing or empty sourceId cannot wipe attribution by accident."}}},"ashby_change_application_stage":{"id":"ashby_change_application_stage","name":"Ashby Change Application Stage","description":"Moves an application to a different interview stage. Requires an archive reason when moving to an Archived stage.","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Ashby API Key"},"applicationId":{"type":"string","required":true,"visibility":"user-or-llm","description":"The UUID of the application to update the stage of"},"interviewStageId":{"type":"string","required":true,"visibility":"user-or-llm","description":"The UUID of the interview stage to move the application to"},"archiveReasonId":{"type":"string","required":false,"visibility":"user-or-llm","description":"Archive reason UUID. Required when moving to an Archived stage, ignored otherwise"}}},"ashby_create_application":{"id":"ashby_create_application","name":"Ashby Create Application","description":"Creates a new application for a candidate on a job. Optionally specify interview plan, stage, source, and credited user.","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Ashby API Key"},"candidateId":{"type":"string","required":true,"visibility":"user-or-llm","description":"The UUID of the candidate to consider for the job"},"jobId":{"type":"string","required":true,"visibility":"user-or-llm","description":"The UUID of the job to consider the candidate for"},"interviewPlanId":{"type":"string","required":false,"visibility":"user-or-llm","description":"UUID of the interview plan to use (defaults to the job default plan)"},"interviewStageId":{"type":"string","required":false,"visibility":"user-or-llm","description":"UUID of the interview stage to place the application in (defaults to first Lead stage)"},"sourceId":{"type":"string","required":false,"visibility":"user-or-llm","description":"UUID of the source to set on the application"},"creditedToUserId":{"type":"string","required":false,"visibility":"user-or-llm","description":"UUID of the user the application is credited to"},"createdAt":{"type":"string","required":false,"visibility":"user-or-llm","description":"ISO 8601 timestamp to set as the application creation date (defaults to now)"}}},"ashby_create_candidate":{"id":"ashby_create_candidate","name":"Ashby Create Candidate","description":"Creates a new candidate record in Ashby.","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Ashby API Key"},"name":{"type":"string","required":true,"visibility":"user-or-llm","description":"The candidate full name"},"email":{"type":"string","required":false,"visibility":"user-or-llm","description":"Primary email address for the candidate"},"phoneNumber":{"type":"string","required":false,"visibility":"user-or-llm","description":"Primary phone number for the candidate"},"linkedInUrl":{"type":"string","required":false,"visibility":"user-or-llm","description":"LinkedIn profile URL"},"githubUrl":{"type":"string","required":false,"visibility":"user-or-llm","description":"GitHub profile URL"},"website":{"type":"string","required":false,"visibility":"user-or-llm","description":"Personal website URL"},"sourceId":{"type":"string","required":false,"visibility":"user-or-llm","description":"UUID of the source to attribute the candidate to"},"creditedToUserId":{"type":"string","required":false,"visibility":"user-or-llm","description":"UUID of the Ashby user to credit with sourcing this candidate"},"createdAt":{"type":"string","required":false,"visibility":"user-or-llm","description":"Backdated creation timestamp in ISO 8601 (e.g. 2024-01-01T00:00:00Z). Defaults to now."},"alternateEmailAddresses":{"type":"json","required":false,"visibility":"user-or-llm","description":"Array of additional email address strings to add to the candidate, e.g. [\\"a@x.com\\",\\"b@y.com\\"]"}}},"ashby_create_note":{"id":"ashby_create_note","name":"Ashby Create Note","description":"Creates a note on a candidate in Ashby. Supports plain text and HTML content (bold, italic, underline, links, lists, code).","version":"1.0.0","params":{"apiKey":{"type":"string","required":true,"visibility":"user-only","description":"Ashby API Key"},"candidateId":{"type":"string","required":true,"visibility":"user-or-llm","description":"The UUID of the candidate to add the note to"},"note":{"type":"string","required":true,"visibility":"user-or-llm","description":"The note content. If noteType is text/html, supports: , , , ,