Endpoints: 28,729MCP servers: 18,413Payout addresses: 2,071Paid calls: 1,537Letters: 14Defects: 1,323counted 1 min ago
teppi

Server definition

Hash
sha256:c962213b3be52d097a3ea1c98236047a6f15d1126f39f1a287039a27a4d2526a
What it is
What a remote MCP server returned when asked what it offers: 1 tools

The blob, as servednamed by its sha256

{ "instructions": "Give ssl_check a URL and it opens its own TLS handshakes to that host at the URL's explicit port, or port 443 when none is named. It never loads the page. An http-scheme input reports only that the caller submitted HTTP and whether TLS answers on the probed port; it does not establish whether plain HTTP is served or redirected. Measured wall time is 0.05-1.5 seconds against real hosts, and a stalling server is cut off at 12 seconds per probe.\n\nRoute here for the padlock and the certificate: 'is my SSL working', 'why does the browser say Not Secure', an expired or soon-to-expire certificate, a warning that names the wrong hostname, a renewal someone wants confirmed, or a question about which TLS versions a server still accepts.\n\nBe precise about what comes back. The probe establishes two things and only two: the protocol versions the server agrees to speak, and the certificate it serves (subject, issuer, the hostnames it covers, and the dates it was issued and expires). The grade in the result is this app's own reading of protocol support alone; it is not a Qualys SSL Labs grade. The probe does not build or verify the full chain of trust, does not check revocation, and does not inspect cipher suites, so a clean reading here is not a promise that every browser will trust the site. One more limit worth stating when it bites: the probe opens handshakes to one resolved endpoint, so on an anycast or load-balanced host it reports the certificate that one node served. A renewal that has only partially rolled out can still read clean. Say so whenever the user's question turns on trust rather than configuration.\n\nThis app knows nothing about the rest of the site. Send protection-header questions (Content-Security-Policy, HSTS, X-Frame-Options) to Security Headers Check, JavaScript libraries carrying known published vulnerabilities to JS Vulnerability Check, third-party trackers and cookies to Site Privacy Scan, and page load time to Website Speed Test. Nothing in this suite builds a trust chain or checks revocation, so when that is the real question, say plainly that it is outside what these tools measure.\n\nLead the answer with whether anything is wrong, then the certificate (who issued it, what it covers, when it was issued and when it expires), then the protocol list.", "tools": [ { "description": "Opens its own TLS handshakes to one public host with openssl, using the URL's explicit port or 443 by default, and reports what they establish: which of TLS 1.3, TLS 1.2, TLS 1.1, TLS 1.0 and SSLv3 the server accepts, a protocol-support grade, and the certificate the server actually serves (subject, issuer, covered hostnames, hostname match, and validity dates). Reach for it on padlock, HTTPS, 'Not Secure', certificate-expiry and wrong-hostname questions, and to inspect which certificate is served after a renewal on the probed endpoint; this does not verify every load-balanced node. It does not fetch the page or establish whether plain HTTP is actually served or redirected, and it is not a browser trust decision: no chain-of-trust build, no revocation check, no cipher-suite inspection. Measured 0.05-1.5 seconds against real hosts; each probe is cut off at 12 seconds.", "inputSchema": { "additionalProperties": false, "properties": { "url": { "description": "Full public URL of the site to probe. Its hostname and explicit port drive the handshakes; port 443 is used when no port is named. The submitted scheme is reported, but the page is never fetched and plain-HTTP serving or redirects are not tested", "pattern": "^https?://", "type": "string" } }, "required": [ "url" ], "type": "object" }, "name": "ssl_check", "outputSchema": { "additionalProperties": false, "properties": { "certificate": { "additionalProperties": false, "description": "The certificate the server served during the handshake", "properties": { "daysUntilExpiry": { "description": "Rounded days until expiry; use expired for the exact validity state because an expiry within twelve hours can round to zero", "type": "number" }, "expired": { "description": "Whether the certificate is already past its notAfter", "type": "boolean" }, "expiresAt": { "description": "Certificate notAfter as an ISO 8601 timestamp", "type": "string" }, "expiringSoon": { "description": "Whether the certificate expires within 30 days", "type": "boolean" }, "hostnameMatches": { "description": "Whether a DNS subjectAltName matches the probed hostname or an IP subjectAltName matches the probed IP address", "type": "boolean" }, "issuedAt": { "description": "Certificate notBefore as an ISO 8601 timestamp (when this certificate became valid, which is what confirms a renewal is the one being served)", "type": "string" }, "issuer": { "description": "Issuing CA distinguished name", "type": "string" }, "names": { "description": "DNS names and IP addresses from subjectAltName; the subject common name is display-only", "items": { "type": "string" }, "type": "array" }, "subject": { "description": "Certificate subject distinguished name", "type": "string" } }, "required": [ "names" ], "type": "object" }, "checkedAt": { "description": "Probe timestamp", "type": "string" }, "host": { "description": "The hostname the handshakes were opened against", "type": "string" }, "https": { "description": "Whether anything completed a TLS handshake on the port", "type": "boolean" }, "issues": { "description": "Protocol, certificate, and submitted-scheme observations found by the probe", "items": { "type": "string" }, "type": "array" }, "port": { "description": "The port the handshakes were opened against (443 unless the URL named another)", "type": "number" }, "protocolGrade": { "description": "A+ (TLS 1.3, no legacy protocols), A, B, or C: read from protocol support ALONE by this app. It ignores the certificate entirely, so an expired or wrong-hostname certificate can still sit behind an A. Not a Qualys SSL Labs grade", "type": "string" }, "protocols": { "additionalProperties": false, "description": "Protocol versions the server agreed to speak", "properties": { "ssl3": { "description": "Obsolete SSLv3 still accepted", "type": "boolean" }, "tls10": { "description": "Deprecated TLS 1.0 still accepted", "type": "boolean" }, "tls11": { "description": "Deprecated TLS 1.1 still accepted", "type": "boolean" }, "tls12": { "description": "TLS 1.2 accepted", "type": "boolean" }, "tls13": { "description": "TLS 1.3 accepted", "type": "boolean" } }, "required": [ "tls13", "tls12", "tls11", "tls10", "ssl3" ], "type": "object" }, "servedOverHttp": { "description": "Legacy field name: true when the submitted URL used the http scheme and TLS answered on the probed port. It records the input scheme in this TLS result, not whether HTTP content is served, redirected or enforced", "type": "boolean" }, "url": { "description": "The URL as requested", "type": "string" } }, "required": [ "url", "host", "port", "checkedAt", "https", "issues" ], "type": "object" } } ] }
Verify it yourselfcurl -s https://api.teppi.xyz/v1/evidence/sha256:c962213b3be52d097a3ea1c98236047a6f15d1126f39f1a287039a27a4d2526a | sha256sum