BusinessMCP
URL Security Scanner logo

URL Security Scanner

Free forever

cybrlab-ai · Security

427 installs

Connect in 1 click

The URL Security Scanner from Cybrlab AI (cybrlab-ai-urlcheck-mcp) is an MCP-native security tool built specifically to protect AI agent workflows from phishing links, malware droppers, and suspicious redirect chains before they ever reach a user or downstream system. As AI agents increasingly browse, summarize, and act on links pulled from email, chat, support tickets, and web search results, a single unchecked URL can expose a business to credential theft, malicious payloads, or brand-damaging redirects. This MCP server gives any connected agent a fast, standardized way to check a URL's reputation and structure before clicking, fetching, or citing it.

Under the hood, the scanner inspects URL structure, domain age and reputation signals, redirect behavior, and known phishing or malware indicators to return a clear risk verdict an agent can act on programmatically. Because it speaks native MCP, it doesn't require custom API glue code for every agent framework — Claude, GPT, Gemini, or any other model-agnostic agent can call the same tool set the same way. That consistency matters for teams running multiple AI tools across support, marketing, and engineering who need one dependable URL security scanner rather than a patchwork of point solutions.

On BusinessMCP, this server is connected once and exposed through your single hosted MCP endpoint at /api/mcp, authenticated with your mcph_* Bearer key. That means your AI agents don't need direct access to a third-party scanning API, separate credentials, or bespoke integration work — they call your unified endpoint, and the URL security scanning tool is simply one more capability sitting alongside your other connected tools, databases, and ad platforms. Every scan request and result also feeds into the BusinessMCP business-intelligence dashboard, so security teams and operators gain visibility into how often agents encounter risky URLs, which categories of threats are most common, and where workflow-level guardrails might be needed — without standing up separate logging infrastructure.

This makes the URL Security Scanner a natural fit for support automation that opens links shared by customers, marketing agents that vet affiliate or partner URLs before publishing, RAG pipelines that ingest web content, and internal chatbots that summarize links from Slack or email. Because it's cookieless and GDPR-friendly by design, it fits privacy-conscious environments where you can't rely on browser cookies or invasive tracking to establish trust signals. Pair it with fetch or browser-automation tools for a scan-then-fetch pattern, or with credential managers to make sure agents never autofill secrets into a flagged phishing page.

Teams evaluating AI agent security tooling, phishing URL detection for chatbots, or malware link scanning for automated workflows will find this server addresses a specific, recurring risk: agents acting on untrusted URLs at machine speed, with no human in the loop to notice a suspicious domain. Hosting it through BusinessMCP turns that risk check into a reusable, centrally managed capability rather than a one-off script buried in a single agent's code, and keeps the audit trail visible in your BI dashboard for compliance and incident review.

$ npx mcphosting-cli add cybrlab-ai-urlcheck

Just say it in a thread

No configs, no docs. Once connected, these are the kinds of messages your agents act on.

"Analyze a single url for phishing, malware, and suspicious structural or redirect patterns and return a risk verdict — and give me the highlights."

"Scan a list of urls at once and return risk verdicts and flagged categories for each for me, then post a summary in the thread."

"Look up reputation and age signals for a domain to help assess trustworthiness and flag anything that needs my approval."

What teams use it for

  • Screen links shared by customers in support chat before an AI agent opens or summarizes them
  • Vet affiliate, partner, or ad-destination URLs before a marketing agent publishes or clicks them
  • Pre-check URLs ingested by a RAG pipeline or web-browsing agent to avoid pulling malicious content
  • Flag suspicious redirect chains or newly registered domains in inbound email links processed by an AI triage agent
  • Log and audit URL risk verdicts across all agents in a central BI dashboard for security review

Agent-callable tools

scan_url

Analyze a single URL for phishing, malware, and suspicious structural or redirect patterns and return a risk verdict.

batch_scan_urls

Scan a list of URLs at once and return risk verdicts and flagged categories for each.

check_domain_reputation

Look up reputation and age signals for a domain to help assess trustworthiness.

trace_redirect_chain

Follow and report the full redirect chain for a shortened or obfuscated URL.

extract_url_metadata

Pull structural details from a URL such as domain, path, query parameters, and TLD for further analysis.

get_scan_history

Retrieve prior scan results for a given URL or domain from stored records.

report_malicious_url

Submit a URL to be flagged as malicious or phishing for future reference and team visibility.

Your data stays yours

Credentials live in your vault. We route requests — we never store, log, or train on your data.

Works with every AI

Connect once — portable across Claude, GPT, Gemini, and every local agent you run.

Frequently asked questions

What does the URL Security Scanner actually check?

It analyzes URL structure, domain reputation and age, redirect behavior, and known phishing or malware indicators to produce a risk verdict an agent can act on.

How do AI agents access this scanner through BusinessMCP?

Once connected, it's exposed as a tool on your single hosted MCP endpoint at /api/mcp, so any model-agnostic agent authenticated with your mcph_* Bearer key can call it without separate API integration.

Can I see how often my agents encounter risky URLs?

Yes, scan activity and risk outcomes surface in the BusinessMCP business-intelligence dashboard alongside your other connected tools, so you can spot trends without building separate logging.

Give your AI team the URL Security Scanner skill

Free forever plan, no credit card. Connected and working in under five minutes.

Connect URL Security Scanner free