url-oracle — URL Trust Oracle
Flags phantom-squatted/typosquatted domains and known-malicious URLs before an agent follows them.
Should I use this
Quality & Safety
Based on automated analysis of tool definitions and protocol compliance.
Context Cost
This is the approximate number of tokens consumed each time the server's tools are loaded into a model's context. Higher counts reduce the attention available for other tasks.
Install
One-Click Install
Add this to your `claude_desktop_config.json` file:
{
"mcpServers": {
"url-oracle": {
"url": "https://url-oracle.fly.dev/mcp"
}
}
}Remote endpoints
https://url-oracle.fly.dev/mcpstreamable-httpWhat it can do
Tool inventory
Tools (1)
🟢verify_url(url)
URL Trust Oracle. Call this BEFORE fetching, citing, recommending, or following any URL you were not given directly by the user (one you generated, recalled, or inferred). LLMs routinely hallucinate plausible-looking URLs for documentation, APIs, and brands — attackers pre-register those exact domains and serve phishing/malware to whoever follows them ('phantom squatting'). This tool checks the domain's RDAP registration (does it exist, how old is it), runs a Levenshtein-distance brand-similarity check against well-known domains, and checks the exact URL against a known-malicious-infrastructure blocklist. Returns a synthetic verdict: ALLOW (no issues found), WARN (proceed with caution — read the findings), or BLOCK (do not fetch or cite this — likely a hallucinated/squatted domain or confirmed malicious URL). First 5 calls per caller are free; after that this tool requires x402 payment (USDC on Base) and will return a payment-required error with the amount and address to pay.
Input Schema
{
"type": "object",
"properties": {
"url": {
"type": "string",
"format": "uri",
"maxLength": 2048,
"description": "The exact URL to verify, including scheme (e.g. \"https://example.com/path\")."
}
},
"required": [
"url"
],
"additionalProperties": false,
"$schema": "http://json-schema.org/draft-07/schema#"
}Community
Evidence