Skip to main content
Glama
brianbooms

Quiet Menders MCP Server

qm_data_cert

Check TLS certificate issuer, validity window, and days remaining to alert before expiry on your or clients' infrastructure.

Instructions

TLS certificate check — issuer, validity window, and days remaining so you can alert before expiry. Monitors your own infrastructure or a client's. Price: $0.01 USDC on Base via x402 (the live 402 challenge is authoritative). Two-phase: call without 'payment' to get the live payment requirements (payTo, amount, accepted networks); pay from your own wallet, then re-call with 'payment' set to the base64-encoded x402 payload — the data comes back in the tool result. This tool never pays, never touches private keys, and never holds funds. Resale permitted: you may resell this data output at your own price.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
domainYesDomain name. Example: example.com.
paymentNoBase64-encoded x402 v1 payment payload (the signed ExactEvmPayload JSON). Omit on the first call to receive the payment requirements; sign in your own wallet / x402 client, then re-call with this set. The server only forwards it to the rail — it never signs, never holds funds, never touches private keys.

Schema Changelog

Changes observed during successful MCP inspections.

  1. Addedv0.1.0

TDQS

A4.5/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, the description carries the full burden and does so well: it discloses the two-phase payment flow, the authoritative 402 challenge, the exact price, and explicit safety boundaries (never pays, never touches private keys, never holds funds). Resale permission is also stated, which an agent otherwise could not infer.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loads purpose before payment mechanics. The 'never signs/holds funds/touches keys' promise appears twice (description and payment param schema) and could be trimmed, but overall most sentences earn their place.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

No output schema exists, and the description tells the agent where results land ('the data comes back in the tool result') and covers payment, safety, and prerequisites. It stops short of describing the shape of the certificate payload or failure behavior for an unreachable domain.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, so the baseline is 3, but the description adds the sequencing semantics that matter operationally: omit 'payment' first to receive live requirements, then re-call with the signed base64 x402 payload. It goes beyond restating the schema fields.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

Opens with a specific verb+resource ('TLS certificate check') and enumerates the returned fields (issuer, validity window, days remaining). This is clearly distinguishable from near-neighbors like qm_data_dns and qm_data_httpcheck without opening any schema.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

States the intended context clearly — monitor your own infrastructure or a client's, to alert before expiry. It does not name an alternative tool or state when not to use it, so it stops short of the 5-level routing guidance.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.