Skip to main content
Glama

Weio site check

Check a website's HTTPS certificate

check_https
Read-onlyIdempotent

Checks what a visitor sees when opening a domain in a browser, for both example.com and www.example.com: whether the site loads securely, or shows a full-page privacy warning / 'Not secure', and why (expired certificate, name mismatch, self-signed, no HTTPS, redirect problems, unreachable). Returns a cause code, whether a browser shows a warning, the certificate expiry date and a one-sentence plain-English explanation per address. Public websites only.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
domainYesDomain or URL, e.g. example.com or https://www.example.com/page

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observed

TDQS

A4.1/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare readOnly, idempotent, open-world. The description adds real behavioral context beyond that: it silently tests BOTH example.com and www.example.com, and it reports cause codes, a warning flag, certificate expiry, and a plain-English explanation per address. The 'public websites only' restriction is also disclosed. No auth or rate-limit detail, but the safety profile is already covered by annotations.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loaded with the core behavior, then the enumerated failure causes and the return shape. One long sentence carries a lot but every clause earns its place; only mild density cost prevents a 5.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

There is no output schema, so the description must describe returns and it does: cause code, warning presence, expiry date, and a per-address explanation. Combined with the dual-hostname behavior and the public-site restriction, an agent has everything needed to call it and interpret results.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, so the baseline is 3, but the description adds meaning the schema does not: the single domain input is effectively expanded to two hostnames (apex and www), which materially changes what the agent should expect. It also implicitly accepts domains or full URLs, matching the schema example.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource: it checks what a browser visitor sees for a domain, covering both the apex and www variants, and enumerates the failure modes it detects. It is unmistakably about HTTPS/certificate health, though it never names or contrasts itself with the sibling site_info, so an agent must infer the boundary.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Gives clear context for when it applies (diagnosing browser security warnings for a domain) and an explicit scope exclusion ('public websites only'). It does not route the agent between this and site_info, which is the one missing piece for a top score.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources