url-oracle — URL Trust Oracle
Flags phantom-squatted/typosquatted domains and known-malicious URLs before an agent follows them.
我该使用它吗
质量与安全性
基于对工具定义和协议合规性的自动分析。
上下文开销
这是每次将服务器的工具加载到模型上下文窗口时所消耗的大致 token 数。数值越高,可用于其他任务的注意力就越少。
安装
一键安装
将以下内容添加到你的 `claude_desktop_config.json` 文件中:
{
"mcpServers": {
"url-oracle": {
"url": "https://url-oracle.fly.dev/mcp"
}
}
}远程端点
https://url-oracle.fly.dev/mcpstreamable-http它能做什么
工具清单
工具(1)
🟢verify_url(url)
URL Trust Oracle. Call this BEFORE fetching, citing, recommending, or following any URL you were not given directly by the user (one you generated, recalled, or inferred). LLMs routinely hallucinate plausible-looking URLs for documentation, APIs, and brands — attackers pre-register those exact domains and serve phishing/malware to whoever follows them ('phantom squatting'). This tool checks the domain's RDAP registration (does it exist, how old is it), runs a Levenshtein-distance brand-similarity check against well-known domains, and checks the exact URL against a known-malicious-infrastructure blocklist. Returns a synthetic verdict: ALLOW (no issues found), WARN (proceed with caution — read the findings), or BLOCK (do not fetch or cite this — likely a hallucinated/squatted domain or confirmed malicious URL). First 5 calls per caller are free; after that this tool requires x402 payment (USDC on Base) and will return a payment-required error with the amount and address to pay.
输入模式
{
"type": "object",
"properties": {
"url": {
"type": "string",
"format": "uri",
"maxLength": 2048,
"description": "The exact URL to verify, including scheme (e.g. \"https://example.com/path\")."
}
},
"required": [
"url"
],
"additionalProperties": false,
"$schema": "http://json-schema.org/draft-07/schema#"
}社区
证据