{"uid":"cap_oTB6iPCOmncbhpuaU2lZt","slug":"delx-commerce-ssrf-url-audit-85b1f790","name":"Delx Commerce SSRF URL Audit","description":"Pay-per-result APIs for agents. No signup. Exact price. Verifiable delivery. USDC on Base + Solana via x402.","url":"https://commerce.delx.ai/api/v1/x402/ssrf-url-audit?utm_source=zero.xyz","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"url":{"type":"string","description":"Input field: url."}}},"responseSchema":{"type":"json","example":{"risk":"high","schema":"delx/util-ssrf-url-audit/v1","advisory":"Resolve DNS and re-check every redirect at execution time.","findings":["private_or_metadata_host"],"hostname":"169.254.169.254"}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.003","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.003/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.003","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.003","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_60zVal9Oxo0Mb_jmfIcmG","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.003","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Audits a URL for SSRF (Server-Side Request Forgery) risk by checking if its hostname resolves to private, internal, or cloud metadata IP ranges","exampleAgentPrompt":"Before we fetch this webhook URL from our backend, can you run an SSRF safety check on https://webhook.example.com/callback to see if it resolves to any private, internal, or cloud metadata host?","exampleUseCases":[{"title":"Safe webhook URL validation before fetch","prompt":"We're about to hit this user-submitted webhook URL from our server — can you audit https://user-submitted-hook.example.com/notify for SSRF risk before we make the request?"},{"title":"Cloud metadata endpoint detection","prompt":"Can you check if https://169.254.169.254/latest/meta-data/ is flagged as an SSRF risk? I want to make sure our agent doesn't accidentally expose AWS instance metadata."},{"title":"Redirect chain SSRF screening","prompt":"A user gave us a URL that seems to redirect a few times — audit https://short.link/abc123 for SSRF risk so we know if any hop in the chain leads to a private or reserved host."}],"resultDescription":"Returns a JSON object with a `risk` field (e.g. 'high'), a `schema` identifier, a human-readable `advisory` message, a list of `findings` (e.g. ['private_or_metadata_host']), and the resolved `hostname`. The agent can use the risk level and findings to decide whether to proceed with a server-side fetch.","failureModes":["Invalid or malformed URL input returns an error","Unresolvable hostnames may yield inconclusive results","Dynamic DNS or redirect-based obfuscation may require re-auditing at execution time (as noted in the advisory)","Payment failure or insufficient USDC balance blocks the request"],"whenToPreferThis":"Use this endpoint when your agent or backend needs to validate user-supplied or third-party URLs before making server-side HTTP requests, particularly when SSRF attacks are a concern. It is purpose-built for SSRF detection — not generic URL reachability or link preview — and returns structured risk verdicts suitable for automated decision-making. Prefer it over manual IP-range checks or regex heuristics, especially when redirect chains or DNS rebinding could obscure a malicious destination.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-10-01T00:53:53.466Z","isFirstParty":false,"canonicalSlug":"delx-commerce-ssrf-url-audit-85b1f790"}