MCPサーバー

certdesk

dev.certdesk/certdesk
クラウド・インフラ セキュリティ 公開・接続可能 MCP 2026-07-28

このMCPでできること

Diagnoses TLS certificates, DNS, certificate expiry, propagation, security headers, and related web-server security issues, with optional expiry monitoring.

check_certificate
Check one domain's TLS certificate in depth: expiry and days left for the certificate the server actually serves (measured from a Korean network, CT logs as fallback), whether a newer certificate exists in CT logs but is not deployed, live TLS verification from a global PoP and from Korea, certificate chain (leaf → intermediates → root), revocation, SAN list, and recent incident history of the issuing CA.
読み取り専用 外部アクセスあり
入力スキーマ
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'description': 'Domain name, e.g. example.com'}}}
check_dns
DNS and hosting facts for a domain: nameservers with DNS provider, A/AAAA with IP owner (ASN), CNAME, MX, CAA (which CAs may issue), SPF/DMARC, DNSSEC, registrar and domain expiry (RDAP).
読み取り専用 外部アクセスあり
入力スキーマ
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'description': 'Domain name, e.g. example.com'}}}
check_dns_propagation
Compare answers for one DNS record across resolvers — the authoritative nameservers, Korean ISPs (KT, SK Broadband, LG U+) and public resolvers (Cloudflare, Google, Quad9, OpenDNS) — measured from a Korean network. Use it to confirm a TXT/CNAME for certificate domain validation (e.g. _acme-challenge) has propagated.
読み取り専用 外部アクセスあり
入力スキーマ
{'type': 'object', 'required': ['name', 'type'], 'properties': {'name': {'type': 'string', 'description': 'Record name, e.g. _acme-challenge.example.com'}, 'type': {'enum': ['A', 'AAAA', 'CNAME', 'TXT', 'MX', 'NS', 'CAA', 'SOA'], 'type': 'string'}}}
check_expiry
Expiry summary for up to 5 domains at once: served certificate expiry and issuer, undeployed newer certificate in CT logs, domain registration expiry (RDAP), and alert lines (Korean). Use this for inventories and periodic checks.
読み取り専用 外部アクセスあり
入力スキーマ
{'type': 'object', 'required': ['domains'], 'properties': {'domains': {'type': 'array', 'items': {'type': 'string'}, 'maxItems': 5, 'minItems': 1, 'description': 'Domain names'}}}
check_security
Security posture check of a web server (no port scanning): TLS protocol support (legacy 1.0/1.1 detection via a Korean network probe), security headers (HSTS/CSP/X-Content-Type-Options/anti-clickjacking/Referrer-Policy), HTTP→HTTPS redirect, and certificate key/signature strength. Returns per-item pass/warn/fail and an overall grade.
読み取り専用 外部アクセスあり
入力スキーマ
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'description': 'Domain name, e.g. example.com'}}}
explain_tls_error
Explain a TLS/SSL certificate error message from a browser, curl/OpenSSL, Java, Python, Node.js, Go or .NET: likely causes, fixes, and links to step-by-step guides (Korean). Works offline from a curated knowledge base.
読み取り専用
入力スキーマ
{'type': 'object', 'required': ['error'], 'properties': {'error': {'type': 'string', 'description': 'Full error text, e.g. "PKIX path building failed" or "NET::ERR_CERT_DATE_INVALID"'}}}
watch_expiry
Subscribe an email address to free daily expiry monitoring of up to 5 domains (certificate, domain registration and security grade) with email alerts. Double opt-in: a confirmation email is sent and monitoring starts only after the recipient clicks the link. Use only an address the user owns and explicitly asked to use.
外部アクセスあり
入力スキーマ
{'type': 'object', 'required': ['email', 'domains'], 'properties': {'email': {'type': 'string', 'description': 'Email address that will receive the alerts'}, 'domains': {'type': 'array', 'items': {'type': 'string'}, 'maxItems': 5, 'minItems': 1, 'description': 'Domain names to monitor'}}}
追加
watch_expiry
2026年9月27日2:40
追加
explain_tls_error
2026年9月27日2:40
追加
check_dns_propagation
2026年9月27日2:40
追加
check_dns
2026年9月27日2:40
追加
check_security
2026年9月27日2:40
追加
check_expiry
2026年9月27日2:40
追加
check_certificate
2026年9月27日2:40