Server definition
- Hash
- sha256:1a2abb40583b4fb1afe96c21f5770c7a187b3508dee775053c98a7abc669943b
- What it is
- What a remote MCP server returned when asked what it offers: 7 tools
The blob, as servednamed by its sha256
{
"instructions": "certdesk: TLS/SSL certificate diagnostics. check_certificate = one domain in depth; check_expiry = up to 5 domains; check_security = server hardening grade; check_dns = nameservers, DNS provider, IP owner, CAA, SPF/DMARC, DNSSEC, registrar; check_dns_propagation = compare a record across Korean ISPs, public resolvers and authoritative servers (for TXT/CNAME domain validation); explain_tls_error = what an error message means and how to fix it; watch_expiry = free email alerts (double opt-in, only with the user's own address). Guides are Korean: https://certdesk.dev/ko/guide/",
"tools": [
{
"description": "Check one domain's TLS certificate and return a verdict: status OK | WARN | CRITICAL | UNKNOWN, judged from the certificate chain the server actually serves — measured from Korean point A (full chain and CRL revocation) plus Korean point B and an overseas point on the Globalping public measurement network (per-point results in measuredFrom; disagreement between points is a WARN) — verification (expired, not yet valid, hostname mismatch, self-signed, untrusted root, missing intermediate, revoked via CRL), days left, renewal point, a newer certificate issued but not deployed (CT logs), the served chain and the issuing CA's incident history. If the server cannot be measured the status is UNKNOWN and CT logs are shown only as an estimate — never as OK. Set detail=true to include the full chain in the text output.",
"inputSchema": {
"properties": {
"detail": {
"description": "Include the full certificate chain in the text output (default false)",
"type": "boolean"
},
"domain": {
"description": "Domain name, e.g. example.com",
"type": "string"
}
},
"required": [
"domain"
],
"type": "object"
},
"name": "check_certificate",
"outputSchema": {
"properties": {
"domain": {
"type": "string"
},
"headline": {
"description": "One-line verdict (Korean)",
"type": "string"
},
"reasons": {
"items": {
"properties": {
"code": {
"type": "string"
},
"message": {
"type": "string"
},
"messageEn": {
"type": "string"
},
"severity": {
"type": "string"
}
},
"required": [
"code",
"severity"
],
"type": "object"
},
"type": "array"
},
"status": {
"description": "UNKNOWN = could not be measured (never treat as OK)",
"enum": [
"OK",
"WARN",
"CRITICAL",
"UNKNOWN"
],
"type": "string"
}
},
"required": [
"domain",
"status",
"headline",
"reasons"
],
"type": "object"
}
},
{
"description": "DNS and hosting facts for a domain: nameservers with DNS provider, A/AAAA with IP owner (ASN), CNAME, MX, CAA (which CAs may issue), SPF/DMARC, DNSSEC, registrar and domain expiry (RDAP).",
"inputSchema": {
"properties": {
"domain": {
"description": "Domain name, e.g. example.com",
"type": "string"
}
},
"required": [
"domain"
],
"type": "object"
},
"name": "check_dns",
"outputSchema": null
},
{
"description": "Compare answers for one DNS record across resolvers — the authoritative nameservers, Korean ISPs (KT, SK Broadband, LG U+) and public resolvers (Cloudflare, Google, Quad9, OpenDNS) — measured from a Korean network. Use it to confirm a TXT/CNAME for certificate domain validation (e.g. _acme-challenge) has propagated.",
"inputSchema": {
"properties": {
"name": {
"description": "Record name, e.g. _acme-challenge.example.com",
"type": "string"
},
"type": {
"enum": [
"A",
"AAAA",
"CNAME",
"TXT",
"MX",
"NS",
"CAA",
"SOA"
],
"type": "string"
}
},
"required": [
"name",
"type"
],
"type": "object"
},
"name": "check_dns_propagation",
"outputSchema": null
},
{
"description": "Verdict for up to 5 domains at once: status OK | WARN | CRITICAL | UNKNOWN per domain combining the served certificate (verification, days left — null when the server cannot be measured) and domain registration expiry (RDAP), plus Korean alert lines. Use this for inventories, CI gates (fail unless status is OK) and periodic checks.",
"inputSchema": {
"properties": {
"domains": {
"description": "Domain names",
"items": {
"type": "string"
},
"maxItems": 5,
"minItems": 1,
"type": "array"
}
},
"required": [
"domains"
],
"type": "object"
},
"name": "check_expiry",
"outputSchema": {
"properties": {
"checkedAt": {
"type": "string"
},
"results": {
"items": {
"properties": {
"domain": {
"type": "string"
},
"headline": {
"description": "One-line verdict (Korean)",
"type": "string"
},
"reasons": {
"items": {
"properties": {
"code": {
"type": "string"
},
"message": {
"type": "string"
},
"messageEn": {
"type": "string"
},
"severity": {
"type": "string"
}
},
"required": [
"code",
"severity"
],
"type": "object"
},
"type": "array"
},
"status": {
"description": "UNKNOWN = could not be measured (never treat as OK)",
"enum": [
"OK",
"WARN",
"CRITICAL",
"UNKNOWN"
],
"type": "string"
}
},
"required": [
"domain",
"status",
"headline",
"reasons"
],
"type": "object"
},
"type": "array"
}
},
"required": [
"results"
],
"type": "object"
}
},
{
"description": "Security posture check of a web server (no port scanning): TLS protocol support (legacy 1.0/1.1 detection via a Korean network probe), security headers (HSTS/CSP/X-Content-Type-Options/anti-clickjacking/Referrer-Policy), HTTP→HTTPS redirect, and certificate key/signature strength. Returns per-item pass/warn/fail and an overall grade.",
"inputSchema": {
"properties": {
"domain": {
"description": "Domain name, e.g. example.com",
"type": "string"
}
},
"required": [
"domain"
],
"type": "object"
},
"name": "check_security",
"outputSchema": null
},
{
"description": "Explain a TLS/SSL certificate error message from a browser, curl/OpenSSL, Java, Python, Node.js, Go or .NET: likely causes, fixes, and links to step-by-step guides (Korean). Works offline from a curated knowledge base.",
"inputSchema": {
"properties": {
"error": {
"description": "Full error text, e.g. \"PKIX path building failed\" or \"NET::ERR_CERT_DATE_INVALID\"",
"type": "string"
}
},
"required": [
"error"
],
"type": "object"
},
"name": "explain_tls_error",
"outputSchema": null
},
{
"description": "Subscribe an email address to free daily expiry monitoring of up to 5 domains (certificate, domain registration and security grade) with email alerts. Double opt-in: a confirmation email is sent and monitoring starts only after the recipient clicks the link. Use only an address the user owns and explicitly asked to use.",
"inputSchema": {
"properties": {
"domains": {
"description": "Domain names to monitor",
"items": {
"type": "string"
},
"maxItems": 5,
"minItems": 1,
"type": "array"
},
"email": {
"description": "Email address that will receive the alerts",
"type": "string"
}
},
"required": [
"email",
"domains"
],
"type": "object"
},
"name": "watch_expiry",
"outputSchema": null
}
]
}Verify it yourself
curl -s https://api.teppi.xyz/v1/evidence/sha256:1a2abb40583b4fb1afe96c21f5770c7a187b3508dee775053c98a7abc669943b | sha256sum