certdesk

TLS cert verdict (OK/WARN/CRITICAL/UNKNOWN) from the served chain: expiry, revocation, alerts

我該用這個嗎

品質與安全性

A
說明品質
93%
結構描述完整度
99%
命名品質
94%
汙染風險
100%
權限相符程度
100%
協定合規性
100%

發現項目(1)

  • LOWTool 'check_dns' description lacks action verb在 check_dns 中

根據工具定義與協定合規性的自動化分析。

上下文成本

~1,410Token(工具定義)
~1.1 KB典型回應大小
中等的注意力影響(128k 上下文的 1.10%)

這是每次將伺服器的工具載入模型上下文時所消耗的約略 token 數量。數量越高,可用於其他工作的注意力就越少。

安裝

一鍵安裝

將以下內容加入你的 `claude_desktop_config.json` 檔案:

{
  "mcpServers": {
    "certdesk": {
      "url": "https://certdesk.dev/mcp"
    }
  }
}

遠端端點

https://certdesk.dev/mcpstreamable-http

它能做什麼

工具清單

工具(7)

🟢 唯讀🟡 寫入🔴 刪除⚪ 未知
🟢check_certificate(domain, detail)

Check one domain's TLS certificate and return a verdict: status OK | WARN | CRITICAL | UNKNOWN, judged from the certificate chain the server actually serves — measured from Korean point A (full chain and CRL revocation) plus Korean point B and an overseas point on the Globalping public measurement network (per-point results in measuredFrom; disagreement between points is a WARN) — verification (expired, not yet valid, hostname mismatch, self-signed, untrusted root, missing intermediate, revoked via CRL), days left, renewal point, a newer certificate issued but not deployed (CT logs), the served chain and the issuing CA's incident history. If the server cannot be measured the status is UNKNOWN and CT logs are shown only as an estimate — never as OK. Set detail=true to include the full chain in the text output.

輸入結構描述

{
  "type": "object",
  "properties": {
    "domain": {
      "type": "string",
      "description": "Domain name, e.g. example.com"
    },
    "detail": {
      "type": "boolean",
      "description": "Include the full certificate chain in the text output (default false)"
    }
  },
  "required": [
    "domain"
  ]
}

輸出結構描述

{
  "type": "object",
  "properties": {
    "domain": {
      "type": "string"
    },
    "status": {
      "type": "string",
      "enum": [
        "OK",
        "WARN",
        "CRITICAL",
        "UNKNOWN"
      ],
      "description": "UNKNOWN = could not be measured (never treat as OK)"
    },
    "headline": {
      "type": "string",
      "description": "One-line verdict (Korean)"
    },
    "reasons": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "code": {
            "type": "string"
          },
          "severity": {
            "type": "string"
          },
          "message": {
            "type": "string"
          },
          "messageEn": {
            "type": "string"
          }
        },
        "required": [
          "code",
          "severity"
        ]
      }
    }
  },
  "required": [
    "domain",
    "status",
    "headline",
    "reasons"
  ]
}
🟢check_expiry(domains)

Verdict for up to 5 domains at once: status OK | WARN | CRITICAL | UNKNOWN per domain combining the served certificate (verification, days left — null when the server cannot be measured) and domain registration expiry (RDAP), plus Korean alert lines. Use this for inventories, CI gates (fail unless status is OK) and periodic checks.

輸入結構描述

{
  "type": "object",
  "properties": {
    "domains": {
      "type": "array",
      "items": {
        "type": "string"
      },
      "minItems": 1,
      "maxItems": 5,
      "description": "Domain names"
    }
  },
  "required": [
    "domains"
  ]
}

輸出結構描述

{
  "type": "object",
  "properties": {
    "results": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "domain": {
            "type": "string"
          },
          "status": {
            "type": "string",
            "enum": [
              "OK",
              "WARN",
              "CRITICAL",
              "UNKNOWN"
            ],
            "description": "UNKNOWN = could not be measured (never treat as OK)"
          },
          "headline": {
            "type": "string",
            "description": "One-line verdict (Korean)"
          },
          "reasons": {
            "type": "array",
            "items": {
              "type": "object",
              "properties": {
                "code": {
                  "type": "string"
                },
                "severity": {
                  "type": "string"
                },
                "message": {
                  "type": "string"
                },
                "messageEn": {
                  "type": "string"
                }
              },
              "required": [
                "code",
                "severity"
              ]
            }
          }
        },
        "required": [
          "domain",
          "status",
          "headline",
          "reasons"
        ]
      }
    },
    "checkedAt": {
      "type": "string"
    }
  },
  "required": [
    "results"
  ]
}
🟢check_security(domain)

Security posture check of a web server (no port scanning): TLS protocol support (legacy 1.0/1.1 detection via a Korean network probe), security headers (HSTS/CSP/X-Content-Type-Options/anti-clickjacking/Referrer-Policy), HTTP→HTTPS redirect, and certificate key/signature strength. Returns per-item pass/warn/fail and an overall grade.

輸入結構描述

{
  "type": "object",
  "properties": {
    "domain": {
      "type": "string",
      "description": "Domain name, e.g. example.com"
    }
  },
  "required": [
    "domain"
  ]
}
🟢check_dns(domain)

DNS and hosting facts for a domain: nameservers with DNS provider, A/AAAA with IP owner (ASN), CNAME, MX, CAA (which CAs may issue), SPF/DMARC, DNSSEC, registrar and domain expiry (RDAP).

輸入結構描述

{
  "type": "object",
  "properties": {
    "domain": {
      "type": "string",
      "description": "Domain name, e.g. example.com"
    }
  },
  "required": [
    "domain"
  ]
}
🟢check_dns_propagation(name, type)

Compare answers for one DNS record across resolvers — the authoritative nameservers, Korean ISPs (KT, SK Broadband, LG U+) and public resolvers (Cloudflare, Google, Quad9, OpenDNS) — measured from a Korean network. Use it to confirm a TXT/CNAME for certificate domain validation (e.g. _acme-challenge) has propagated.

輸入結構描述

{
  "type": "object",
  "properties": {
    "name": {
      "type": "string",
      "description": "Record name, e.g. _acme-challenge.example.com"
    },
    "type": {
      "type": "string",
      "enum": [
        "A",
        "AAAA",
        "CNAME",
        "TXT",
        "MX",
        "NS",
        "CAA",
        "SOA"
      ]
    }
  },
  "required": [
    "name",
    "type"
  ]
}
🟢explain_tls_error(error)

Explain a TLS/SSL certificate error message from a browser, curl/OpenSSL, Java, Python, Node.js, Go or .NET: likely causes, fixes, and links to step-by-step guides (Korean). Works offline from a curated knowledge base.

輸入結構描述

{
  "type": "object",
  "properties": {
    "error": {
      "type": "string",
      "description": "Full error text, e.g. \"PKIX path building failed\" or \"NET::ERR_CERT_DATE_INVALID\""
    }
  },
  "required": [
    "error"
  ]
}
⚪watch_expiry(email, domains)

Subscribe an email address to free daily expiry monitoring of up to 5 domains (certificate, domain registration and security grade) with email alerts. Double opt-in: a confirmation email is sent and monitoring starts only after the recipient clicks the link. Use only an address the user owns and explicitly asked to use.

輸入結構描述

{
  "type": "object",
  "properties": {
    "email": {
      "type": "string",
      "description": "Email address that will receive the alerts"
    },
    "domains": {
      "type": "array",
      "items": {
        "type": "string"
      },
      "minItems": 1,
      "maxItems": 5,
      "description": "Domain names to monitor"
    }
  },
  "required": [
    "email",
    "domains"
  ]
}

社群

為此伺服器評分

證據

近期觀測

已驗證未記錄版本7 個工具
已驗證未記錄版本7 個工具