Run offline heuristic safety checks on a URL and return a risk level (low/medium/high), a 0+ risk score, per-check results, and warnings. Checks HTTPS, suspicious TLDs, URL shorteners, phishing keyword patterns, raw IP hosts, deceptive domain characters, and excessive subdomains. No network requests — pattern analysis only.
This page documents the MCP tool findutils:url_safety_checker. See the REST reference →
Call it over MCP
Tool name findutils:url_safety_checker
· no API keys · 120 requests/min per IP
Claude Code
claude mcp add findutils --transport http https://mcp.findutils.com/ Claude Desktop — claude_desktop_config.json
{
"mcpServers": {
"findutils": {
"url": "https://mcp.findutils.com/"
}
}
} Raw JSON-RPC (any MCP client) — verified example
curl -X POST https://mcp.findutils.com/ \
-H "Content-Type: application/json" \
-d '{
"jsonrpc": "2.0",
"id": 1,
"method": "tools/call",
"params": {
"name": "url_safety_checker",
"arguments": {
"url": "https://example.com"
}
}
}' Input schema
| Argument | Type | Required | Description |
|---|---|---|---|
| url | string | yes | The URL to check. "https://" is assumed when no scheme is given. |
Example arguments (verified)
{
"url": "https://example.com"
} Also a REST endpoint
The same tool answers plain HTTP at
POST /api/tools/url-safety-checker/execute — no key, 60 requests/min.
More Security tools
Base32 Encode
Encode UTF-8 text to RFC 4648 base32 (uppercase, "=" padding).
Data Sanitizer
Sanitize untrusted text and return the cleaned output, a list of changes made, and a risk level.
Dnpm Configurator
Returns the five files of a hardened Docker-based npm wrapper (the ./dnpm bash script, .dnpm/Dockerfile, docker-compose.node.yml, .dnpm/secc
Email Header Analyzer
Return a structured analysis of raw email headers: sender, recipient, subject, date, message id, the Received hop chain with per-hop delays,
Hash Comparison Tool
Hash text with SHA-1, SHA-256, SHA-384, or SHA-512 and compare the hex digest with an expected hash.
Jwt Decode
Decode a JWT header + payload.
Jwt Generator
Generate a signed JWT (HS256, HS384, or HS512 via HMAC) and return the token plus the decoded header and payload.
Jwt Security Validator
Decode a JWT and return a list of security checks (algorithm strength, expiration, not-before, issued-at, issuer, audience, subject, signatu