DropEngine
Agent Preflight · URL Safety Gate · PAID MCP TOOL

check_url

Checks an unknown URL before an agent opens or relies on it, returning a structured allow, caution, or block signal.

When an agent should call it

Uses deterministic URL, host/IP, pattern, and HTTPS redirect checks. It never loads page content or uses an LLM. Without an optional threat-intelligence key, results are marked heuristic-only and degraded.

Input: One HTTP or HTTPS URL, up to 4096 characters

Price: $0.005 USDC per call, paid in USDC via x402 on Base.

MCP connection: one-time setup, then call check_url on each needed workflow.

Direct HTTP resource: https://mcp.dropenginehq.com/api/check-url

Example input

{
  "url": "https://example.com"
}

Representative output

This is an example of the response shape, not a live result. Current registry data and provider configuration can change the values.

{
  "success": true,
  "safe": false,
  "risk_score": 20,
  "risk_level": "medium",
  "recommendation": "caution",
  "normalized_url": "https://example.com/",
  "final_url": "https://example.com/",
  "redirect_count": 0,
  "https": true,
  "domain_age_risk": "unknown",
  "phishing": false,
  "malware": false,
  "suspicious_redirect": false,
  "suspicious_domain": false,
  "threats": [],
  "warnings": [
    "external_threat_intel_not_configured; heuristic-only result"
  ],
  "sources": [
    "local_heuristics"
  ],
  "cached": false,
  "degraded": true,
  "checked_at": "2026-09-28T00:00:00.000Z"
}

Each call requests payment for this tool only. The agent receives a structured result and decides what to do next. Check the limits above before acting on risk, market, freshness, or availability results.

MCP endpoint: https://mcp.dropenginehq.com/api/paid-mcp