Skip to main content
Glama

MAD Synapse · Web & Research

TLS certificate check

tls_check
Read-onlyIdempotent

A site's TLS certificate: issuer, validity, days until expiry, SANs, protocol, cipher, chain and whether browsers trust it. Live TLS handshake to the host. Flags expired, expiring (< 14 days), untrusted or name-mismatched certificates. Price: $0.001 per call (10 free/day; after that a payment-required result lists x402 options). Errors: returns isError with a message for invalid input or an upstream failure (not charged).

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
hostYesHostname without scheme or path, e.g. "example.com".
portNoTCP port serving TLS. Range 1-65535. Default 443.

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
okNo
sanNo
alpnNo
hostNo
portNo
chainNo
cipherNo
issuerNo
serialNo
subjectNo
trustedNo
key_bitsNo
protocolNo
valid_toNo
warningsNo
days_leftNo
issuer_cnNo
valid_fromNo
trust_errorNo
handshake_msNo
fingerprint_sha256No

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observed

TDQS

A4.2/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already cover the safety profile (readOnly, idempotent, openWorld, non-destructive), and the description goes well beyond them: it discloses cost ($0.001/call, 10 free/day, x402 payment-required result), error semantics (isError with a message for invalid input or upstream failure, and explicitly not charged), and the alerting thresholds (< 14 days, expired, untrusted, name-mismatch).

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loaded with the resource and its returned fields, then escalation details, pricing and error behavior, each sentence carrying distinct information. The opening field list is dense, but nothing is redundant and the ordering is sensible for an agent scanning for cost and failure modes.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

An output schema exists, yet the description still outlines the certificate surface and adds the details an agent most needs for decision-making: cost model, free tier, payment fallback, and error/charging behavior. For a two-parameter read-only tool, nothing material is missing.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100% for both parameters, so the schema already documents 'host' (hostname without scheme or path) and 'port' (default 443, range). The description adds only the 'live handshake' framing, which clarifies that host must be resolvable and port reachable, but no syntax or format detail beyond the schema. Baseline 3 applies when the schema does the heavy lifting.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description states a specific verb+resource (inspect a site's live TLS certificate) and enumerates exactly what it returns (issuer, validity, days to expiry, SANs, protocol, cipher, chain, browser trust). It is clearly distinguishable from adjacent siblings such as dns_lookup, domain_whois, http_probe and robots_check, which do not perform a TLS handshake.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Usage context is implied ('Live TLS handshake to the host', flags for expired/expiring/untrusted/name-mismatch certificates), so an agent can infer when the tool is relevant. However, it never names an alternative (e.g. domain_whois, http_probe, vuln_check) or states when NOT to use it, so routing between siblings is left to inference.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources