@guardbee/mcp-ssl-inspector
π¬π§ English | πΉπ· TΓΌrkΓ§e

An MCP server that inspects TLS certificates, cipher suites, and protocol configuration for any domain. Uses Node.js's built-in tls module β no external dependencies.
This package sends usage telemetry by default (tool name + short parameters β see @guardbee/mcp-telemetry). Disable with GUARDBEE_TELEMETRY=0.
Features
- Certificate Inspection β validity, days until expiry, SHA-256 fingerprint, SANs, issuer chain
- Protocol Check β TLS 1.0/1.1 deprecation warning, SSLv2/v3 critical warning
- Cipher Analysis β detects NULL, EXPORT, RC4, DES, 3DES, anonymous ciphers
- HSTS Check β
Strict-Transport-Security header, max-age, includeSubdomains
- Bulk Scanning β scans N domains in parallel
- Certificate Expiry Monitoring β π¨ / β οΈ / β
icons for upcoming expirations
- 12 Unit Tests β pure logic tests, no network connection required
Quick Start
npm install -g @guardbee/mcp-ssl-inspector
Add to claude_desktop_config.json:
{
"mcpServers": {
"guardbee-ssl-inspector": {
"command": "npx",
"args": ["-y", "@guardbee/mcp-ssl-inspector"]
}
}
}
| Tool | Description |
|---|
inspect_ssl | Full TLS inspection for a single domain (cert + cipher + protocol + HSTS) |
inspect_ssl_bulk | Inspects multiple domains in parallel |
check_cert_expiry | Checks certificate expiry dates for N domains |
get_cert_info | Detailed certificate info for a domain (fingerprint, SAN, chain, serial number) |
Example Usage
You can ask Claude:
"Is example.com's SSL certificate valid?"
"When do these domains' certificates expire: example.com, api.example.com, shop.example.com"
"Is example.com using a weak cipher suite?"
Example Output
ββ example.com:443
β Protocol : TLSv1.3
β Cipher : TLS_AES_256_GCM_SHA384 (256 bit)
β Chain : depth=2 valid=yes
β Cert CN : example.com
β Validity : Mar 15 2024 β Jun 13 2024 (expires in 45 days)
β SANs : example.com, www.example.com
β Issuer : Let's Encrypt
β SHA-256 : AA:BB:CC:DD:...
β HSTS : enabled (max-age=31536000, includeSubdomains)
β β
No security issues found
Security Findings
| Finding | Severity | Description |
|---|
CERT_EXPIRED | π΄ Critical | Certificate has expired |
CERT_EXPIRY_CRITICAL | π΄ Critical | < 7 days remaining |
CERT_EXPIRY_SOON | π High | < 30 days remaining |
CERT_EXPIRY_WARN | π‘ Medium | < 90 days remaining |
CERT_CHAIN_INVALID | π High | Chain validation error |
CERT_NO_SAN | π‘ Medium | No Subject Alternative Name |
DEPRECATED_PROTOCOL | π High | TLS 1.0 or 1.1 |
OBSOLETE_PROTOCOL | π΄ Critical | SSLv2 or SSLv3 |
WEAK_CIPHER | π΄ Critical | NULL/EXPORT/RC4/anonymous cipher |
NO_HSTS | π‘ Medium | No HSTS header found |
HSTS_SHORT_MAX_AGE | π΅ Low | max-age < 15552000s |
CLI β CI/CD Integration
In addition to MCP server mode, this can also be used directly as a CLI:
npx @guardbee/mcp-ssl-inspector inspect example.com
npx @guardbee/mcp-ssl-inspector inspect example.com api.example.com shop.example.com
npx @guardbee/mcp-ssl-inspector inspect example.com:8443
npx @guardbee/mcp-ssl-inspector expiry example.com api.example.com
npx @guardbee/mcp-ssl-inspector inspect example.com --fail-on=critical
npx @guardbee/mcp-ssl-inspector inspect example.com --format=json
Exit codes: 0 = no issues Β· 1 = findings above threshold / expired cert Β· 2 = error
Configuration via guardbee.yml
Create a guardbee.yml at your project root to persist CLI flags. CLI flags always override file settings.
ssl-inspector:
fail-on: high
port: 443
hosts:
- example.com
- api.example.com
- shop.example.com
See guardbee.example.yml for a sample file.
GitHub Actions β Post-Deployment Check
name: SSL Check
on:
workflow_run:
workflows: ["Deploy"]
types: [completed]
jobs:
ssl-check:
runs-on: ubuntu-latest
steps:
- name: Inspect SSL certificate
run: npx @guardbee/mcp-ssl-inspector inspect ${{ vars.DOMAIN }} --fail-on=high
- name: Check cert expiry (warn if < 30 days)
run: npx @guardbee/mcp-ssl-inspector expiry ${{ vars.DOMAIN }}
Scheduled Expiry Monitor
name: Cert Expiry Monitor
on:
schedule:
- cron: "0 9 * * 1"
jobs:
expiry:
runs-on: ubuntu-latest
steps:
- name: Check certificate expiry dates
run: |
npx @guardbee/mcp-ssl-inspector expiry \
example.com \
api.example.com \
shop.example.com \
--format=json
GitLab CI
ssl-inspect:
image: node:20
script:
- npx @guardbee/mcp-ssl-inspector inspect $DOMAIN --fail-on=high
environment:
name: production
only:
- main
Development
npm install
npm test
npm run build
License
MIT β GuardBee