# Block Malicious Url Entry

> Block a malicious zws short URL, destination URL, or hostname in production PostgreSQL and Redis.

- Skill: `zws-im/block-malicious-url-entry` (Agent Skill)
- Install (CLI): `npx skillmds@latest add zws-im/block-malicious-url-entry`
- Raw SKILL.md: https://api.skillmd.com/api/skills/zws-im/block-malicious-url-entry/raw
- Safety review: pending
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Coding & Dev Tools
- Author: zws-im (https://skillmd.com/u/zws-im)
- Updated: 2026-09-17
- Page: https://skillmd.com/skills/zws-im/block-malicious-url-entry

---


# Block Malicious URL Entry

Block the destination hostname, not `zws.im`. Production defaults to Railway environment `production`, service `API`.

## Procedure

1. Provide the known hostname, destination URL, or `zws.im` short URL. Stop if the hostname is ambiguous or belongs to a shared platform.
2. Run `railway status` and confirm project `zws`, environment `production`, and service `API`.
3. From `apps/api`, run `railway run --service API --environment production -- node scripts/block-malicious-url.ts --dry-run --hostname '<hostname>'` (or pass `--url`/`--target-url`). Review the resolved hostname and whether it is already blocked.
4. After approval, repeat with `--apply`. The script inserts the hostname, refreshes Redis, and verifies the supplied short URL when `--url` is used.

The script intentionally does not bulk-update `urls.blocked`: retrieval checks the hostname block and lazily marks each matching row. Never print connection strings, credentials, or full environment output. Confirm the resolved hostname before applying.

