Unphurl

by 123ergo

Not rated
GitHub

About

URL intelligence for AI agents. 13 tools for security signals and data quality checks. Analyses URLs across 7 dimensions: redirect behaviour, brand impersonation, domain age, SSL/TLS, parked detection, URL structure, DNS enrichment. Risk score 0-100 with 23 configurable weights.

Details

Author
123ergo
Categories
Other, Security, AI
Tags
#web-research, #data-analysis

Setup

Install Unphurl in your MCP client (Claude Desktop, Cursor, Windsurf, and others).

Repository: https://github.com/123ergo/unphurl-mcp

Follow the installation instructions in the repository README, then restart your MCP client.

_ _ _ _ ____ _ _ _ _ ____ _ | | | | \ | | _ \| | | | | | | _ \| | | | | | \| | |_) | |_| | | | | |_) | | | |_| | |\ | __/| _ | |_| | _ <| |___ \___/|_| \_|_| |_| |_|\___/|_| \_\_____|

URL intelligence for AI agents and developers. 16 MCP tools. 25 signals. 7 dimensions.

Give your AI agent eyes for URLs. Unphurl analyses any URL across 7 dimensions (redirect behaviour, brand impersonation, domain age, SSL/TLS, parked detection, URL structure, DNS enrichment) and returns structured signals with a configurable 0-100 risk score. Signals, not verdicts. Your agent decides what to do with them.

Works with Claude Code, Claude Desktop, Claude Cowork, ChatGPT desktop, Cursor, Windsurf, and any MCP-compatible tool.

Every new account gets20 free pipeline check credits. Most lookups are free. Known domains (Tranco Top 100K) and previously analysed domains return cached results at no cost. You only pay when an unknown domain runs through the full pipeline.

One-time purchases, no subscriptions. In typical use, 95-99% of URLs resolve free.

Add to your.mcp.json(Claude Code, Claude Desktop, Claude Cowork, ChatGPT desktop, Cursor, Windsurf, or any MCP-compatible tool):

{ "mcpServers": { "unphurl": { "command": "npx", "args": ["-y", "@unphurl/mcp-server"], "env": { "UNPHURL_API_KEY": "uph_your_key_here" } } } }

The AI can create one for you. Just ask:"Sign up for Unphurl."Thesignuptool works without an API key. After signup, add the key to your MCP configuration and restart.

"Checkhttps://suspicious-domain.xyz"

"Batch check all URLs in this spreadsheet"

"Create a scoring profile called 'lead-qual' that weights parked domains at 30 and no MX record at 20"

No commands to memorize. No syntax to learn. Your AI handles the tool calls.

Every check returns signals across7 dimensions:

Every signal is business intelligence. Domain age tells you how established a company is. No MX record means they can't receive email. Expiring domains mean a business might be shutting down. Combined with your AI's ability to process in bulk and output to spreadsheets, it becomes a lightweight due diligence engine.

"Check these 500 URLs. Give me two lists: the clean ones (score under 25) and the flagged ones (score 50 or higher). Export both as CSV."

Your AI gets the batch results, filters by score, and outputs the lists. No code, no scripting.

Different jobs need different weights. A security bot cares about brand impersonation. A cold email tool cares about parked domains and missing MX records.

"Create a profile called 'cold-email' that weights parked at 30, no_mx_record at 20, and domain_age_7 at 25. Then batch check my lead list using that profile."

Unphurl inside an AI chat combines with everything else your agent has access to:

- Spreadsheets: Read a CRM export, batch-check every URL, write results back with risk scores
- Web scraping: Scrape a competitor's partner page, check every link for health
- Documents: Generate a branded PDF audit report from the results
- Scheduled tasks: "Check my critical URLs every Monday morning"

- A positive credit balance is required for all checks, even free lookups.
- Known domains(google.com, amazon.com, etc.): free, instant.
- Cached domains(analysed recently by anyone): free, instant.
- Unknown domains(first-time analysis): 1 credit each.
- Batch checks deduct credits upfront for unknowns. If you don't have enough, you get a summary showing exactly how many credits you need.
- Failed pipeline checks are automatically refunded.

Thecheck-url-safetyskill teaches your AI to proactively check URLs before following or recommending them, without being asked.

Claude Cowork or Claude Desktop:Just ask:"Install the Unphurl URL safety skill."

Claude Code, Cursor, or other dev tools:

# Global (all projects) cp node_modules/@unphurl/mcp-server/skills/check-url-safety.md ~/.claude/skills/ # Or for a specific project cp node_modules/@unphurl/mcp-server/skills/check-url-safety.md .claude/skills/

Unphurl costs you $0.04-$0.09 per check. A website link audit takes 15 minutes and uses 50-100 credits. Charge $150-$500 per audit.

Service ideas: link health audits, lead list verification, SEO backlink audits, newsletter link monitoring, vendor vetting reports, brand protection monitoring, influencer vetting.

- CLI:npx unphurl(npm)
- Hosted MCPfor Claude Cowork (no local install):
mcp.unphurl.com
- REST API:
api.unphurl.com
- Website:
unphurl.com
- Visual guides:
unphurl.com/getting-started-guides

CVE/SBOM security audits, licence compliance, frontend security scanning, domain intelligence, and public records — 55 tools, no API key required Category: Security (also fits: Compliance, Data)

AI-powered log analysis MCP server. Scans 500MB+ log files locally, analyses errors with Ollama + CrewAI agents, and automatically files structured GitHub Issues. 100% local — no logs leave your machine.

MCP-native OSINT framework for AI agents. Exposes 9 intelligence tools (email enumeration, username search, breach check, WHOIS, IP intel, subdomain enum, dorks, paste search, phone intel) via Model Context Protocol. Also works as a standalone Python CLI.

Real-time OSINT intelligence platform for global security monitoring.

Self-hosted MCP platform with multiple tools, multi-agent orchestration, web UI, and ML capabilities

EXIF for AI. AKF embeds trust scores, source provenance, and compliance metadata into every file your AI touches — DOCX, PDF, images, code, and 20+ formats. 9 MCP tools: stamp, inspect, trust, audit, scan, embed, extract, detect. Audit against EU AI Act, SOX, HIPAA, NIST in one command.

Research a person's public footprint from a name, phone, email, or username. Sourced public-web profiles for AI agents. Not a background check.

OSINT: find people & companies, build investigations

One API giving AI agents web search, page fetch as markdown, AI extraction, and deep research tools.

Institutional research and manager diligence reports on hedge funds, venture capital and private equity managers. Summary of filings, personnel changes, media screening and social signals delivered to you in minutes.

No reviews yet — be the first

Sign in to leave a review

Use Google, GitHub, or an email account so ratings stay tied to real people.

Email sign in

No reviews posted yet.