/checkScore a URL for phishing risk before an agent opens or trusts it. Keyless, deterministic heuristics - typosquat / homoglyph of a known brand, punycode / mixed-script hosts, credentials-in-URL, raw-IP hosts, suspicious TLDs, over-deep subdomains - plus a best-effort domain-age check (young domains are a top phishing signal). Returns a 0-100 risk score, a SAFE / SUSPICIOUS / DANGEROUS verdict, and labelled reasons. No API keys, no LLM.
{
"additionalProperties": false,
"properties": {
"url": {
"description": "The URL to check (a bare domain is accepted too).",
"type": "string"
}
},
"required": [
"url"
],
"type": "object"
}{
"domain_age_days": 4,
"host": "coinbase.com.secure-login.xyz",
"labels": [
"brand_impersonation",
"suspicious_tld"
],
"reasons": [
"'coinbase' appears in the host but the domain is secure-login.xyz, not coinbase.com"
],
"registrable_domain": "secure-login.xyz",
"risk_score": 80,
"source": "heuristics + RDAP",
"url": "https://coinbase.com.secure-login.xyz/verify",
"verdict": "DANGEROUS"
}