CertGuard

Free SSL/TLS certificate checker: expiry, chain trust, hostname match, TLS version, A/B/C/F grade.

我该使用它吗

质量与安全性

A
描述质量
100%
模式完整度
100%
命名质量
100%
投毒风险
100%
权限匹配度
100%
协议合规性
100%

基于对工具定义和协议合规性的自动分析。

上下文开销

~905token 数(工具定义)
~8.9 KB典型响应大小
对注意力有中等影响(占 128k 上下文窗口的 0.71%)

这是每次将服务器的工具加载到模型上下文窗口时所消耗的大致 token 数。数值越高,可用于其他任务的注意力就越少。

安装

一键安装

将以下内容添加到你的 `claude_desktop_config.json` 文件中:

{
  "mcpServers": {
    "certguard": {
      "url": "https://certguard.mike-tusa.workers.dev/mcp"
    }
  }
}

远程端点

https://certguard.mike-tusa.workers.dev/mcpstreamable-http

它能做什么

工具清单

工具(1)

🟢 只读🟡 写入🔴 删除⚪ 未知
🟢check_certificate(host, port, include_raw)

Run a live TLS handshake against host:port and audit the certificate the server presents. Returns an A/B/C/F grade and summary, expiry (days remaining), hostname match, chain completeness and trust against Mozilla's root store, negotiated TLS version and cipher suite, key type/size, findings, and a link to the full report. Revocation (OCSP/CRL) is NOT checked. Hosts on Cloudflare's own network cannot be checked live (result: isError with code live_check_unavailable, no grade); a failed handshake returns check_failed with no grade. Read-only: it only opens a TLS connection to the public host. Same engine, cache and limits as the CertGuard JSON API (GET /api/v1/check).

输入模式

{
  "type": "object",
  "properties": {
    "host": {
      "type": "string",
      "minLength": 1,
      "maxLength": 300,
      "description": "Hostname or public IP to check, e.g. example.com. An https:// URL is accepted and reduced to its host (and port). Private, internal and reserved addresses are rejected."
    },
    "port": {
      "type": "integer",
      "enum": [
        443,
        8443,
        465,
        993,
        995
      ],
      "default": 443,
      "description": "TCP port (default 443). Allowed: 443, 8443, 465, 993, 995."
    },
    "include_raw": {
      "type": "boolean",
      "default": false,
      "description": "Also return the full /api/v1/check JSON (all chain certificates, SANs, handshake attempts) in structuredContent.raw. Larger output."
    }
  },
  "required": [
    "host"
  ],
  "additionalProperties": false
}

输出模式

{
  "type": "object",
  "properties": {
    "host": {
      "type": "string"
    },
    "port": {
      "type": "integer"
    },
    "status": {
      "type": "string",
      "enum": [
        "checked"
      ]
    },
    "grade": {
      "type": "string",
      "enum": [
        "A",
        "B",
        "C",
        "F"
      ]
    },
    "gradeEstimated": {
      "type": "boolean",
      "description": "true when the result was inferred from Certificate Transparency logs instead of a live handshake"
    },
    "summary": {
      "type": "string"
    },
    "revocation_checked": {
      "type": "boolean",
      "description": "Always false: OCSP/CRL status is not queried"
    },
    "source": {
      "type": "object",
      "properties": {
        "method": {
          "type": "string",
          "enum": [
            "live_tls_handshake",
            "certificate_transparency"
          ]
        },
        "live": {
          "type": "boolean"
        },
        "ip": {
          "type": "string"
        }
      }
    },
    "expiry": {
      "type": "object",
      "properties": {
        "notBefore": {
          "type": "string"
        },
        "notAfter": {
          "type": "string"
        },
        "daysRemaining": {
          "type": "integer"
        },
        "status": {
          "type": "string",
          "enum": [
            "ok",
            "warning",
            "critical",
            "expired",
            "not_yet_valid"
          ]
        }
      }
    },
    "hostname": {
      "type": "object",
      "properties": {
        "matches": {
          "type": "boolean"
        },
        "matchedName": {
          "type": "string"
        },
        "note": {
          "type": "string"
        }
      }
    },
    "certificate": {
      "type": "object",
      "properties": {
        "subject": {
          "type": "string"
        },
        "issuer": {
          "type": "string"
        },
        "issuerOrg": {
          "type": "string"
        },
        "sans": {
          "type": "array",
          "items": {
            "type": "string"
          },
          "description": "First 20 DNS names"
        },
        "sanCount": {
          "type": "integer"
        },
        "key": {
          "type": "string"
        },
        "signatureAlgorithm": {
          "type": "string"
        },
        "validationType": {
          "type": "string"
        },
        "sha256Fingerprint": {
          "type": "string"
        }
      }
    },
    "tls": {
      "type": "object",
      "properties": {
        "version": {
          "type": "string"
        },
        "cipherSuite": {
          "type": "string"
        },
        "keyExchangeGroup": {
          "type": "string"
        },
        "ocspStapled": {
          "type": "boolean"
        }
      }
    },
    "chain": {
      "type": "object",
      "properties": {
        "presented": {
          "type": "integer"
        },
        "complete": {
          "type": "boolean"
        },
        "trusted": {
          "type": "boolean"
        },
        "trustAnchor": {
          "type": "string"
        }
      }
    },
    "issues": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "severity": {
            "type": "string",
            "enum": [
              "critical",
              "warning",
              "info"
            ]
          },
          "code": {
            "type": "string"
          },
          "message": {
            "type": "string"
          }
        },
        "required": [
          "severity",
          "code",
          "message"
        ]
      }
    },
    "notChecked": {
      "type": "array",
      "items": {
        "type": "string"
      }
    },
    "checkedAt": {
      "type": "string"
    },
    "cached": {
      "type": "boolean"
    },
    "plan": {
      "type": "string",
      "enum": [
        "anonymous",
        "key"
      ]
    },
    "reportUrl": {
      "type": "string"
    },
    "apiUrl": {
      "type": "string"
    },
    "version": {
      "type": "string"
    },
    "raw": {
      "type": "object",
      "description": "Full /api/v1/check response (only when include_raw is true)"
    }
  },
  "required": [
    "host",
    "port",
    "status",
    "grade",
    "summary",
    "revocation_checked",
    "reportUrl"
  ]
}

社区

评价此服务器

证据

最近观测

已验证未记录版本1 个工具