{"uid":"cap_lfEkMNHMDmpkCn54HPHRw","slug":"url-safety-gate-b3f2aff9","name":"URL Safety Gate","description":"URL safety preflight: screen a link before an agent opens it — syntax, host/IP, patterns, redirects, optional threat intelligence.","url":"https://mcp.dropenginehq.com/api/check-url?utm_source=zero.xyz","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"url":{"type":"string","maxLength":4096,"minLength":1}}},"responseSchema":{"type":"json","example":{"safe":false,"https":true,"cached":false,"malware":false,"sources":["local_heuristics"],"success":true,"threats":[],"degraded":true,"phishing":false,"warnings":["external_threat_intel_not_configured; heuristic-only result"],"final_url":"https://example.com/","checked_at":"2026-09-28T00:00:00.000Z","risk_level":"medium","risk_score":20,"normalized_url":"https://example.com/","recommendation":"caution","redirect_count":0,"domain_age_risk":"unknown","suspicious_domain":false,"suspicious_redirect":false}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.005","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.005/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.005","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.005","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_NakJFMq1IoroEHZ3NV1-r","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.005","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Performs a paid preflight risk assessment of a URL by checking syntax, transport security, host/IP reputation, suspicious patterns, and up to five HTTPS redirects — without fetching page content.","exampleAgentPrompt":"Before you follow that link someone just sent me — https://bit.ly/3xR9qAb — can you do a safety preflight check on it and tell me the risk level and whether it looks like phishing or malware?","exampleUseCases":[{"title":"Agent link validation before follow","prompt":"I just received a link in an email claiming to be from my bank — https://secure-login.bankofamerica.verify-now.xyz — can you run a URL safety check on it and tell me if it's phishing or high risk before I click anything?"},{"title":"Autonomous agent self-protection","prompt":"Before my workflow agent fetches data from https://api.thirdpartyservice.io/data/export, run a URL safety preflight on it to make sure it's not redirecting to a private IP or flagged for malware."},{"title":"User-submitted URL moderation","prompt":"A user submitted this URL in our platform — https://free-download-movies.ru/setup.exe — can you assess its risk score and check for suspicious domain patterns or redirect chains before we allow it to be posted?"}],"resultDescription":"Returns a JSON object with: a boolean 'safe' flag, risk_level (e.g. low/medium/high), numeric risk_score, phishing and malware boolean flags, final_url after redirects, redirect_count, suspicious_domain and suspicious_redirect flags, domain_age_risk, a recommendation string (e.g. 'caution' or 'block'), warnings array, sources array indicating whether Google Web Risk or local heuristics were used, a degraded flag if external threat intel is unavailable, and a checked_at timestamp.","failureModes":["URL targets a local or private IP — blocked with an error indicating local destination","Google Web Risk not configured — result is returned as degraded/heuristic-only with a warning","URL syntax is invalid or empty — request rejected","More than five redirects in the chain — scanning stops at the limit","Service returns success:false if an internal error occurs during assessment"],"whenToPreferThis":"Choose this endpoint when an AI agent needs a lightweight, fast preflight risk signal before following, fetching, or sharing a URL — especially in automated workflows where visiting a malicious or private-network URL would be dangerous. It is distinct from full page-content crawlers because it never fetches page content, making it safer and faster for untrusted input. Prefer it over generic HTTP HEAD checks when you need structured threat categorization (phishing, malware, redirect chain analysis) with an explicit risk score and recommendation.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-10-02T00:45:09.918Z","isFirstParty":false,"canonicalSlug":"url-safety-gate-b3f2aff9"}