{"uid":"cap_WTj_iS7lHXi6jK_5XTsuC","slug":"delx-ssrf-url-audit-e54758c4","name":"Delx SSRF URL Audit","description":"Screen a URL for private hosts, unsafe schemes, and embedded credentials. Use it as a bounded preflight or analysis step inside an enterprise agent workflow before data, policy, integration, security, or commercial decisions reach production. Returns deterministic machine-readable JSON for $0.003 USDC via x402 on Base. Execution is first-party, local-only, stateless, memory-only, and has no paid upstream or input retention. Results are advisory; the caller remains responsible for authorization…","url":"https://api.delx.ai/api/v1/x402/ssrf-url-audit","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"url":{"type":"string","description":"Input field: url."}}},"responseSchema":{"type":"json","example":{"risk":"high","schema":"delx/util-ssrf-url-audit/v1","advisory":"Resolve DNS and re-check every redirect at execution time.","findings":["private_or_metadata_host"],"hostname":"169.254.169.254"}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.003","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.003/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.003","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.003","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_FmDciXTlBa_VdFvRdTXgd","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.003","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Screens a URL for SSRF risks including private/internal hosts, unsafe schemes, and embedded credentials, returning machine-readable JSON results.","exampleAgentPrompt":"Before we fetch data from this user-supplied URL https://example.com/callback, can you run an SSRF audit on it to check for private hosts, unsafe schemes, or embedded credentials?","exampleUseCases":[{"title":"Webhook URL preflight in API integration","prompt":"We're about to register this webhook URL from a third-party partner — can you audit https://partner.example.com/hook for SSRF risks like internal host references or embedded credentials before we save it?"},{"title":"User-submitted URL safety check","prompt":"A user just submitted this URL for our data-import feature: http://admin:password@192.168.1.1/export — can you screen it for SSRF vulnerabilities, unsafe schemes, and embedded credentials before we process it?"},{"title":"Security preflight in agent pipeline","prompt":"My agent workflow is about to call an external URL fetched from a database record. Can you run an SSRF preflight on https://internal-service.corp/api/data to make sure it doesn't point to a private host or use a dangerous scheme?"}],"resultDescription":"A deterministic machine-readable JSON object indicating whether the URL is flagged for SSRF risks, including specific findings such as private/internal host detection, unsafe URL scheme (e.g. file://, gopher://), and embedded credentials in the URL string. Results are advisory and stateless.","failureModes":["Malformed or non-parseable URL input returns a validation error","Missing 'url' field in request body results in a 400-class error","Ambiguous hostnames that resolve differently per environment may yield false negatives","Edge-case IPv6 or encoded URLs may not be fully parsed in all variants","Network-level issues contacting the API return transient errors"],"whenToPreferThis":"Use this endpoint when you need a fast, stateless, deterministic SSRF preflight check before making any server-side HTTP request based on user- or externally-supplied URLs. It is ideal for enterprise agent workflows where you need a bounded, local-only security gate with no data retention. Prefer it over general-purpose URL scanners when you specifically need SSRF-pattern detection (private hosts, unsafe schemes, embedded credentials) rather than malware or phishing classification.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T13:16:17.083Z","isFirstParty":false}