Skip to content
onelayer.
All tools

Tool detail

url-threat

Screens a URL for phishing heuristics, traces redirects across hosts and optionally checks URLhaus, returning a 0-100 risk score.

Categories: Security

Use when

  • check whether a URL looks like phishing before following it
  • trace a URL's redirect chain for cross-host risk

Not for

  • not a sandboxed detonation — heuristics and public threat data only

Inputs

POST JSON body: { url: string (required) } — absolute http(s) URL to screen

Admitted input schema

{
  "type": "object",
  "properties": {
    "url": {
      "type": "string",
      "minLength": 0,
      "maxLength": 4096,
      "description": "Absolute http(s) URL to screen"
    }
  },
  "required": [
    "url"
  ],
  "additionalProperties": false,
  "description": "URL Threat Check input. Screen a URL before your agent follows it: phishing-pattern heuristics (IP-literal hosts, punycode, credentials in the URL, shorteners, deep subdomain nesting), a safe server-side redirect trace with cross-host detection, and an optional URLhaus malware-database lookup. Returns a 0-100 risk score with named flags. Honest scope: heuristics + public threat data, not a sandbox."
}

Endpoint

Method
POST
URL
https://agentbit.app/v1/security/url-threat

Payment

Protocol
x402
Listed price
0.01 USDC per request on Base
Payment method
exact
Network
eip155:8453
Asset
0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913

Listed terms are catalog metadata. The caller supplies inputs and calls the tool outside Onelayer. If payment is required, the caller uses a compatible wallet to pay.

Source

Record
POST https://agentbit.app/v1/security/url-threat
Retrieved
2026-09-30T20:37:07.382Z
Catalog file SHA-256
6837ccddf886f0007cf3727ea9d27faaa5047b51b4f425345c554ce1c271a524
Catalog built
2026-09-30T22:31:58.034Z