# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Security Services Vulnerability Protection Signatures API version: 1.0.0 extends: openapi/palo-alto-networks-vulnerability-protection-signatures-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-10-01' generator: build-phrasing.py label: Generated by API Evangelist operations: 10 - target: $.paths['/vulnerability-protection-signatures'].get update: x-apievangelist-phrasing: intent: List custom vulnerability signatures effect: read questions: - Which custom vulnerability protection signatures exist in a folder? - Can I page through vulnerability signatures on a device? instructions: - text: List vulnerability protection signatures in folder {folder}. slots: folder: query.folder - text: Show {limit} vulnerability signatures from snippet {snippet}. slots: limit: query.limit snippet: query.snippet method: generated generated: '2026-09-26' - target: $.paths['/vulnerability-protection-signatures'].post update: x-apievangelist-phrasing: intent: Create a custom vulnerability signature effect: write questions: - How do I write a custom vulnerability protection signature for an exploit? - What affected host, direction and severity does a new vulnerability signature need? instructions: - text: Create vuln signature {threatname}, threat {threat_id}, severity {severity}, direction {direction}, host {affected_host}, pattern {signature}. slots: threatname: requestBody.threatname threat_id: requestBody.threat_id severity: requestBody.severity direction: requestBody.direction affected_host: requestBody.affected_host signature: requestBody.signature - text: Add a vulnerability signature for CVE {cve} named {threatname}. slots: cve: requestBody.cve threatname: requestBody.threatname method: generated generated: '2026-09-26' - target: $.paths['/vulnerability-protection-signatures/{id}'].get update: x-apievangelist-phrasing: intent: Get a vulnerability protection signature effect: read questions: - What CVE and affected host does a given vulnerability signature cover? - Can I read a vulnerability signature by ID? instructions: - text: Get vulnerability protection signature {id}. slots: id: path.id - text: Show the CVE and severity on vulnerability signature {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/vulnerability-protection-signatures/{id}'].put update: x-apievangelist-phrasing: intent: Update a vulnerability protection signature effect: write questions: - Can I change the default action on a custom vulnerability signature? - How do I update the affected host on an existing vulnerability signature? instructions: - text: Update vulnerability signature {id} to severity {severity}. slots: id: path.id severity: requestBody.severity - text: Set default action {default_action} on vulnerability signature {id}. slots: default_action: requestBody.default_action id: path.id method: generated generated: '2026-09-26' - target: $.paths['/vulnerability-protection-signatures/{id}'].delete update: x-apievangelist-phrasing: intent: Delete a vulnerability protection signature effect: destructive questions: - How do I remove a custom vulnerability protection signature? - Is a deleted vulnerability signature gone for good? instructions: - text: Delete vulnerability protection signature {id}. slots: id: path.id - text: Remove the custom vulnerability signature {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/sse/config/v1/vulnerability-protection-signatures'].get update: x-apievangelist-phrasing: intent: List custom vulnerability signatures effect: read questions: - Which custom vulnerability protection signatures exist through the SSE config v1 API? - Can I look up a vulnerability signature by name? instructions: - text: List vulnerability protection signatures in folder {folder} through the SSE config v1 endpoint. slots: folder: query.folder - text: Find vulnerability signature {name} in folder {folder}. slots: name: query.name folder: query.folder method: generated generated: '2026-10-01' - target: $.paths['/sse/config/v1/vulnerability-protection-signatures'].post update: x-apievangelist-phrasing: intent: Create a custom vulnerability signature effect: write questions: - How do I write a custom signature to block an exploit for a specific CVE? - What threat ID range is allowed for custom vulnerability signatures? instructions: - text: Create vulnerability signature {threatname} with threat ID {threat_id} in folder {folder}. slots: threatname: requestBody.threatname threat_id: requestBody.threat_id folder: query.folder - text: Add signature {threatname}, ID {threat_id}, for CVE {cve} with severity {severity} in {folder}. slots: threatname: requestBody.threatname threat_id: requestBody.threat_id cve: requestBody.cve severity: requestBody.severity folder: query.folder method: generated generated: '2026-10-01' - target: $.paths['/sse/config/v1/vulnerability-protection-signatures/{id}'].get update: x-apievangelist-phrasing: intent: Get a custom vulnerability signature effect: read questions: - Where can I see the details of one custom vulnerability signature? - What default action and severity does a given signature have? instructions: - text: Get vulnerability signature {id}. slots: id: path.id - text: Show the CVE and severity of vulnerability signature {id}. slots: id: path.id method: generated generated: '2026-10-01' - target: $.paths['/sse/config/v1/vulnerability-protection-signatures/{id}'].put update: x-apievangelist-phrasing: intent: Edit a custom vulnerability signature effect: write questions: - How do I change the default action of an existing vulnerability signature? - Can I raise the severity of a signature I already created? instructions: - text: Set vulnerability signature {id} ({threatname}, ID {threat_id}) to action {action}. slots: id: path.id threatname: requestBody.threatname threat_id: requestBody.threat_id action: requestBody.default_action - text: Change the severity of vulnerability signature {id} to {severity}. slots: id: path.id severity: requestBody.severity method: generated generated: '2026-10-01' - target: $.paths['/sse/config/v1/vulnerability-protection-signatures/{id}'].delete update: x-apievangelist-phrasing: intent: Delete a custom vulnerability signature effect: destructive questions: - Can I remove a custom vulnerability signature? - Is deleting a vulnerability protection signature permanent? instructions: - text: Delete vulnerability signature {id}. slots: id: path.id - text: Remove the custom vulnerability protection signature {id}. slots: id: path.id method: generated generated: '2026-10-01'