certdesk
TLS cert verdict (OK/WARN/CRITICAL/UNKNOWN) from the served chain: expiry, revocation, alerts
我該用這個嗎
品質與安全性
發現項目(1)
- LOW在 check_dns 中
根據工具定義與協定合規性的自動化分析。
上下文成本
這是每次將伺服器的工具載入模型上下文時所消耗的約略 token 數量。數量越高,可用於其他工作的注意力就越少。
安裝
一鍵安裝
將以下內容加入你的 `claude_desktop_config.json` 檔案:
{
"mcpServers": {
"certdesk": {
"url": "https://certdesk.dev/mcp"
}
}
}遠端端點
https://certdesk.dev/mcpstreamable-http它能做什麼
工具清單
工具(7)
🟢check_certificate(domain, detail)
Check one domain's TLS certificate and return a verdict: status OK | WARN | CRITICAL | UNKNOWN, judged from the certificate chain the server actually serves — measured from Korean point A (full chain and CRL revocation) plus Korean point B and an overseas point on the Globalping public measurement network (per-point results in measuredFrom; disagreement between points is a WARN) — verification (expired, not yet valid, hostname mismatch, self-signed, untrusted root, missing intermediate, revoked via CRL), days left, renewal point, a newer certificate issued but not deployed (CT logs), the served chain and the issuing CA's incident history. If the server cannot be measured the status is UNKNOWN and CT logs are shown only as an estimate — never as OK. Set detail=true to include the full chain in the text output.
輸入結構描述
{
"type": "object",
"properties": {
"domain": {
"type": "string",
"description": "Domain name, e.g. example.com"
},
"detail": {
"type": "boolean",
"description": "Include the full certificate chain in the text output (default false)"
}
},
"required": [
"domain"
]
}輸出結構描述
{
"type": "object",
"properties": {
"domain": {
"type": "string"
},
"status": {
"type": "string",
"enum": [
"OK",
"WARN",
"CRITICAL",
"UNKNOWN"
],
"description": "UNKNOWN = could not be measured (never treat as OK)"
},
"headline": {
"type": "string",
"description": "One-line verdict (Korean)"
},
"reasons": {
"type": "array",
"items": {
"type": "object",
"properties": {
"code": {
"type": "string"
},
"severity": {
"type": "string"
},
"message": {
"type": "string"
},
"messageEn": {
"type": "string"
}
},
"required": [
"code",
"severity"
]
}
}
},
"required": [
"domain",
"status",
"headline",
"reasons"
]
}🟢check_expiry(domains)
Verdict for up to 5 domains at once: status OK | WARN | CRITICAL | UNKNOWN per domain combining the served certificate (verification, days left — null when the server cannot be measured) and domain registration expiry (RDAP), plus Korean alert lines. Use this for inventories, CI gates (fail unless status is OK) and periodic checks.
輸入結構描述
{
"type": "object",
"properties": {
"domains": {
"type": "array",
"items": {
"type": "string"
},
"minItems": 1,
"maxItems": 5,
"description": "Domain names"
}
},
"required": [
"domains"
]
}輸出結構描述
{
"type": "object",
"properties": {
"results": {
"type": "array",
"items": {
"type": "object",
"properties": {
"domain": {
"type": "string"
},
"status": {
"type": "string",
"enum": [
"OK",
"WARN",
"CRITICAL",
"UNKNOWN"
],
"description": "UNKNOWN = could not be measured (never treat as OK)"
},
"headline": {
"type": "string",
"description": "One-line verdict (Korean)"
},
"reasons": {
"type": "array",
"items": {
"type": "object",
"properties": {
"code": {
"type": "string"
},
"severity": {
"type": "string"
},
"message": {
"type": "string"
},
"messageEn": {
"type": "string"
}
},
"required": [
"code",
"severity"
]
}
}
},
"required": [
"domain",
"status",
"headline",
"reasons"
]
}
},
"checkedAt": {
"type": "string"
}
},
"required": [
"results"
]
}🟢check_security(domain)
Security posture check of a web server (no port scanning): TLS protocol support (legacy 1.0/1.1 detection via a Korean network probe), security headers (HSTS/CSP/X-Content-Type-Options/anti-clickjacking/Referrer-Policy), HTTP→HTTPS redirect, and certificate key/signature strength. Returns per-item pass/warn/fail and an overall grade.
輸入結構描述
{
"type": "object",
"properties": {
"domain": {
"type": "string",
"description": "Domain name, e.g. example.com"
}
},
"required": [
"domain"
]
}🟢check_dns(domain)
DNS and hosting facts for a domain: nameservers with DNS provider, A/AAAA with IP owner (ASN), CNAME, MX, CAA (which CAs may issue), SPF/DMARC, DNSSEC, registrar and domain expiry (RDAP).
輸入結構描述
{
"type": "object",
"properties": {
"domain": {
"type": "string",
"description": "Domain name, e.g. example.com"
}
},
"required": [
"domain"
]
}🟢check_dns_propagation(name, type)
Compare answers for one DNS record across resolvers — the authoritative nameservers, Korean ISPs (KT, SK Broadband, LG U+) and public resolvers (Cloudflare, Google, Quad9, OpenDNS) — measured from a Korean network. Use it to confirm a TXT/CNAME for certificate domain validation (e.g. _acme-challenge) has propagated.
輸入結構描述
{
"type": "object",
"properties": {
"name": {
"type": "string",
"description": "Record name, e.g. _acme-challenge.example.com"
},
"type": {
"type": "string",
"enum": [
"A",
"AAAA",
"CNAME",
"TXT",
"MX",
"NS",
"CAA",
"SOA"
]
}
},
"required": [
"name",
"type"
]
}🟢explain_tls_error(error)
Explain a TLS/SSL certificate error message from a browser, curl/OpenSSL, Java, Python, Node.js, Go or .NET: likely causes, fixes, and links to step-by-step guides (Korean). Works offline from a curated knowledge base.
輸入結構描述
{
"type": "object",
"properties": {
"error": {
"type": "string",
"description": "Full error text, e.g. \"PKIX path building failed\" or \"NET::ERR_CERT_DATE_INVALID\""
}
},
"required": [
"error"
]
}⚪watch_expiry(email, domains)
Subscribe an email address to free daily expiry monitoring of up to 5 domains (certificate, domain registration and security grade) with email alerts. Double opt-in: a confirmation email is sent and monitoring starts only after the recipient clicks the link. Use only an address the user owns and explicitly asked to use.
輸入結構描述
{
"type": "object",
"properties": {
"email": {
"type": "string",
"description": "Email address that will receive the alerts"
},
"domains": {
"type": "array",
"items": {
"type": "string"
},
"minItems": 1,
"maxItems": 5,
"description": "Domain names to monitor"
}
},
"required": [
"email",
"domains"
]
}社群
證據