Zero-day, not just feeds
Domain age, brand-lookalike scoring, and shortener unwinding run on every check, so the URL nobody has reported yet still gets caught.
MCP server + REST API
An agent that browses, reads email, or follows a link out of a tool result can be steered by a malicious URL exactly like a person can. SkanQRCode is a URL safety check built for the agent tool-call path: one call, a verdict, before the fetch.
check_url tool response
{
"verdict": "malicious",
"action": "block",
"mode": "url",
"reasons": ["ACTIVE_THREAT_FEED_MATCH", "KNOWN_MALWARE_MATCH"],
"cached": false,
"executionTimeMs": 38,
"environment": "production",
"licensedForProduction": true,
"requestId": "req_01J9Z8QAENP0S2"
}Quickstart
1. install
npx -y @skanqrcode/mcp-server
# claude_desktop_config.json
{
"mcpServers": {
"skanqrcode": {
"command": "npx",
"args": ["-y", "@skanqrcode/mcp-server"],
"env": {
"SKANQRCODE_API_KEY": "sk_test_..."
}
}
}
}Live on npm as @skanqrcode/mcp-server. Get a free sk_test_ key (1,000 checks/mo, no card) at app.skanqrcode.com.
MCP tool schema
check_url
Evaluates whether a URL is safe to fetch or scrape. Returns an allow, warn, or block verdict in real time.
# wherever your agent decides to fetch a URL:
var req = URLRequest(url: URL(string: "https://api.skanqrcode.com/v1/check")!)
req.httpMethod = "POST"
req.setValue("Bearer \(apiKey)", forHTTPHeaderField: "Authorization")
req.httpBody = try JSONEncoder().encode(["target": url])
let (data, _) = try await URLSession.shared.data(for: req)
let result = try JSONDecoder().decode(CheckResponse.self, from: data)
if result.action == "block" { return } // never UIApplication.shared.open(url)Why agents need this too
Domain age, brand-lookalike scoring, and shortener unwinding run on every check, so the URL nobody has reported yet still gets caught.
A check_url tool for Claude Desktop and other MCP clients, or the same endpoint for LangChain, LlamaIndex, or a custom agent loop.
If a URL your agent already fetched gets raised to suspicious or malicious later, a webhook tells you within minutes, on Pro and Business.
Pricing
Sandbox action: block and the MCP server are free, so you can verify the integration before you pay for it. A production license, higher limits, and verdict-change webhooks live on Pro.
Free
$0/mo
1,000 API calls / mo
Wire it up. Test every verdict, sandboxed.
Pro
$19.90/mo
50,000 API calls / mo
The app is live. You can stop the open.
Flexible overages at $0.001 per additional check, so production never throttles.
Business
$169.90/mo
500,000 API calls / mo
Volume is the product.
Early access
Traction for us is a package name and a request log. If your agent fetches whatever a page or tool result hands it, we want that call.