url-oracle — URL Trust Oracle
Server Details
Flags phantom-squatted/typosquatted domains and known-malicious URLs before an agent follows them.
- Status
- Healthy
- Last Tested
- Transport
- Streamable HTTP · MCP 2025-11-25
- URL
TDQS
Scored across 1 tool
There is only one tool, so there is no possibility of confusion or misselection. Its purpose (verifying a URL before use) is unambiguous and fully contained in the name and description.
The single tool name 'verify_url' follows a clear verb_noun snake_case convention that is easy to read and matches the server's stated action. With only one tool, consistency is trivially satisfied.
The server is a focused URL trust oracle whose entire purpose is a single verification operation, so one tool is exactly right. There is no redundancy or missing companion tool needed for this scope.
The tool covers the key verification steps (RDAP registration age, brand-similarity, blocklist check) and returns actionable verdicts, making the surface largely complete for URL trust checking. Minor gaps exist, such as no batch verification or redirect/SSL inspection, but agents can still work around them.
Available Tools
1 toolverify_urlVerify URLAInspect
URL Trust Oracle. Call this BEFORE fetching, citing, recommending, or following any URL you were not given directly by the user (one you generated, recalled, or inferred). LLMs routinely hallucinate plausible-looking URLs for documentation, APIs, and brands — attackers pre-register those exact domains and serve phishing/malware to whoever follows them ('phantom squatting'). This tool checks the domain's RDAP registration (does it exist, how old is it), runs a Levenshtein-distance brand-similarity check against well-known domains, and checks the exact URL against a known-malicious-infrastructure blocklist. Returns a synthetic verdict: ALLOW (no issues found), WARN (proceed with caution — read the findings), or BLOCK (do not fetch or cite this — likely a hallucinated/squatted domain or confirmed malicious URL). First 5 calls per caller are free; after that this tool requires x402 payment (USDC on Base) and will return a payment-required error with the amount and address to pay.
| Name | Required | Description | Default |
|---|---|---|---|
| url | Yes | The exact URL to verify, including scheme (e.g. "https://example.com/path"). |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description fully carries behavioral disclosure: it explains the three checks performed, the return values (ALLOW/WARN/BLOCK with definitions), the cost model (first 5 free, then x402 payment in USDC on Base with payment-required error), and the underlying mechanism (RDAP, Levenshtein, blocklist). This is rich context beyond what a bare schema would provide.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is dense but front-loaded: it opens with the critical usage rule (call before fetching), then explains the problem, the checks, the verdicts, and the payment model. Every sentence earns its place, though it is somewhat long. It could be slightly tighter, but no significant waste.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the complexity of a verification tool with no output schema, the description provides everything an agent needs: when to call, what it does, what the return verdicts mean, and the payment requirement. It is complete for correct invocation and interpretation.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100% and the schema itself documents the URL parameter well (exact URL including scheme). The description adds no further parameter-level semantics, which is fine given the schema is complete. Baseline for 100% coverage is 3; the description's rich behavioral context around the parameter's purpose lifts it slightly, but it does not clarify the parameter beyond the schema, so 4 is appropriate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description states a specific verb and resource ('checks the domain's RDAP registration', 'runs a Levenshtein-distance brand-similarity check', 'checks the exact URL against a known-malicious-infrastructure blocklist') and clearly distinguishes its purpose as a URL safety oracle. No siblings exist to differentiate from, but the purpose is unmistakable.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
It explicitly states when to use it: 'Call this BEFORE fetching, citing, recommending, or following any URL you were not given directly by the user (one you generated, recalled, or inferred).' It also explains why (phantom squatting) and gives the decision framework via verdicts (ALLOW/WARN/BLOCK).
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
1 tool update
- First observed
verify_url
Related MCP Connectors
Blocks typosquatted or hallucinated npm/PyPI packages before an AI agent installs them.
Scam and phishing detection for AI agents: safe/warn/danger verdicts for URLs and messages.
URL reality check for agents: status, content hash, classification, wayback fallback.
Threat intel for AI agents: IOCs, CVEs (EPSS/KEV), wallet sanctions and age, domain and URL checks.
Related MCP Servers
- AlicenseAqualityAmaintenanceEnables AI agents to check URL safety before fetching content, using Google Web Risk, URLhaus, PhishTank, and AI analysis to return SAFE/SUSPICIOUS/DANGEROUS verdicts.1116 npm1MIT
- AlicenseAqualityBmaintenanceProvides preflight checks and domain intelligence so agents can skip domains that will refuse them or charge a fee, covering robots.txt, edge refusals, and HTTP 402 paywalls.7MIT
- AlicenseNot gradedqualityBmaintenanceEnables checking suspicious URLs for risk without opening them, providing full checkups and lookalike detection.MIT
- AlicenseNot gradedqualityFmaintenanceA URL security scanner and MCP server that enables AI agents to analyze URLs for phishing, malware, and other threats before navigation, with optional intent alignment checks.6Apache 2.0
Glama MCP Gateway
Add one secure layer between your agents and this server.