Skip to content

Security hints: urlscan.io reputation provider #289

Description

@mortenn

Part of #285, #249, and meta #245.

Provider

urlscan.io.

Fit

Powerful URL scanning and enrichment provider, but highest privacy sensitivity among the candidate providers because it can actively visit and store submitted URLs. This should be a later, explicit bring-your-own-key integration.

Data Sent

Browser Picker would submit the full URL to urlscan.io for scanning or query prior scan/search data. The submitted URL and resulting scan may be visible according to the configured visibility level.

API / Terms Notes

urlscan.io requires an API key for practical API use. Scan visibility can be public, unlisted, or private depending on account and request settings. Rate limits are per action and window, and responses include X-Rate-Limit headers.

Acceptance Notes

  • Disabled by default.
  • User-triggered only; no automatic scan submission on picker open.
  • Bring-your-own urlscan.io API key.
  • Require an explicit visibility setting before any submission.
  • Strong pre-submit copy explaining that urlscan.io may fetch, store, and expose the submitted URL according to visibility/provider terms.
  • Respect X-Rate-Limit headers and show quota failures neutrally.
  • Do not log submitted URLs or API keys.
  • Do not automatically call this provider when a URL matches Defaults.

Out of Scope

  • Silent scan submission.
  • Defaulting scans to public visibility.
  • RDAP or public CT history lookups.

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions