# URL Safety Gate

> URL Safety Gate is a paid API for AI agents from mcp.dropenginehq.com, paid per call via x402, $0.005/call, status unknown (last checked 2026-10-02).

Performs a paid preflight risk assessment of a URL by checking syntax, transport security, host/IP reputation, suspicious patterns, and up to five HTTPS redirects — without fetching page content.

## Facts

- Endpoint: POST https://mcp.dropenginehq.com/api/check-url?utm_source=zero.xyz
- Price: $0.005/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-02
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/url-safety-gate-b3f2aff9
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_lfEkMNHMDmpkCn54HPHRw

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability url-safety-gate-b3f2aff9 -d '<json body>'
```

Example prompt: Before you follow that link someone just sent me — https://bit.ly/3xR9qAb — can you do a safety preflight check on it and tell me the risk level and whether it looks like phishing or malware?

## When to prefer this

Choose this endpoint when an AI agent needs a lightweight, fast preflight risk signal before following, fetching, or sharing a URL — especially in automated workflows where visiting a malicious or private-network URL would be dangerous. It is distinct from full page-content crawlers because it never fetches page content, making it safer and faster for untrusted input. Prefer it over generic HTTP HEAD checks when you need structured threat categorization (phishing, malware, redirect chain analysis) with an explicit risk score and recommendation.

## Known failure modes

- URL targets a local or private IP — blocked with an error indicating local destination
- Google Web Risk not configured — result is returned as degraded/heuristic-only with a warning
- URL syntax is invalid or empty — request rejected
- More than five redirects in the chain — scanning stops at the limit
- Service returns success:false if an internal error occurs during assessment

## How this service works

Paid URL preflight check ($0.005 USDC): assess URL syntax, transport, host/IP, suspicious patterns, and at most five HTTPS redirects without fetching page content. Blocks local/private destinations. Optional Google Web Risk threat intelligence is used only if configured; otherwise results are explicitly heuristic-only and degraded. This is a risk signal, not a guarantee that a URL is safe.

## Output

Returns a JSON object with: a boolean 'safe' flag, risk_level (e.g. low/medium/high), numeric risk_score, phishing and malware boolean flags, final_url after redirects, redirect_count, suspicious_domain and suspicious_redirect flags, domain_age_risk, a recommendation string (e.g. 'caution' or 'block'), warnings array, sources array indicating whether Google Web Risk or local heuristics were used, a degraded flag if external threat intel is unavailable, and a checked_at timestamp.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "properties": {
  "url": {
   "type": "string",
   "maxLength": 4096,
   "minLength": 1
  }
 }
}
```

## Response schema (JSON Schema)

```json
{
 "type": "json",
 "example": {
  "safe": false,
  "https": true,
  "cached": false,
  "malware": false,
  "sources": [
   "local_heuristics"
  ],
  "success": true,
  "threats": [],
  "degraded": true,
  "phishing": false,
  "warnings": [
   "external_threat_intel_not_configured; heuristic-only result"
  ],
  "final_url": "https://example.com/",
  "checked_at": "2026-09-28T00:00:00.000Z",
  "risk_level": "medium",
  "risk_score": 20,
  "normalized_url": "https://example.com/",
  "recommendation": "caution",
  "redirect_count": 0,
  "domain_age_risk": "unknown",
  "suspicious_domain": false,
  "suspicious_redirect": false
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/url-safety-gate-b3f2aff9/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from mcp.dropenginehq.com](https://www.zero.xyz/host/mcp.dropenginehq.com/llms.txt)
