Agent skill

Detecting Ssl Cert Issues

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Audit a target's TLS certificate beyond protocol/expiry — chain ordering, OCSP stapling, revocation status, Certificate Transparency presence, key-usage flags, and over-broad wildcards.

MITAuto-check passedLegal & Compliance

Install Detecting Ssl Cert Issues

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill detecting-ssl-cert-issues -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace detecting-ssl-cert-issues --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/detecting-ssl-cert-issues .claude/skills/detecting-ssl-cert-issues && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
detecting-ssl-cert-issues
GitHub stars
2.8k
Token cost
~1.7k tokens
SKILL.md length
575 words
Files
4 (incl. scripts, references)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Audit a target's TLS certificate beyond protocol/expiry — chain ordering, OCSP stapling, revocation status, Certificate Transparency presence, key-usage flags, and over-broad wildcards.

  • Works in 4 steps: Confirm Authorization → Run the scanner → Interpret findings → …
  • : TLS handshake already passes (skill 1 analyzing-tls-config cleared) but you suspect the cert posture is fragile
  • SKILL.md covers Overview, When the skill produces findings, Prerequisites and Instructions, plus 4 more sections
  • Runs Python scripts from its folder; calls python3 and jq

What it does

Detecting Ssl Cert Issues is an agent skill from jeremylongshore/tons-of-skills-marketplace. Audit a target's TLS certificate beyond protocol/expiry — chain ordering, OCSP stapling, revocation status, Certificate Transparency presence, key-usage flags, and over-broad wildcards. Use when: TLS handshake already passes (skill 1 analyzing-tls-config cleared) but you suspect the cert posture is fragile. Auditors flag this during SOC2 readiness when a renewal slipped or an intermediate was rotated. Threshold: missing OCSP stapling on production, fewer than 2 SCTs in the cert, intermediate served out of order…

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/PLAYBOOK.md`, `references/THEORY.md` and `scripts/check_cert_chain.py`). Compatibility notes: Designed for Claude Code

It sits in Legal & Compliance, covering Cloud networking, Cryptography and SOC 2 and security compliance. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • : TLS handshake already passes (skill 1 analyzing-tls-config cleared) but you suspect the cert posture is fragile
  • With: check cert revocation
  • Cert chain audit

Example prompts

  • “check cert revocation”
  • “audit ocsp”
  • “ct log check”
  • “/detecting-ssl-cert-issues”

Requirements

  • Python 3
  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Bash(python3:*), Bash(openssl:*)

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Confirm Authorization
  2. Run the scanner
  3. Interpret findings
  4. Cross-skill chaining

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Bash(python3:*)
    • Bash(openssl:*)

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python3
    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Detecting Ssl Cert Issues loads about 1.7k tokens when it runs, and up to ~4.5k if it reads all its reference files. Until then it costs about 198 tokens; SKILL.md has 575 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~198
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 575 words, ~1,715 tokens.

Download SKILL.mdSave it as .claude/skills/detecting-ssl-cert-issues/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
detecting-ssl-cert-issues
description
Audit a target's TLS certificate beyond protocol/expiry — chain ordering, OCSP stapling, revocation status, Certificate Transparency presence, key-usage flags, and over-broad wildcards. Use when: TLS handshake already passes (skill #1 analyzing-tls-config cleared) but you suspect the cert posture is fragile. Auditors flag this during SOC2 readiness when a renewal slipped or an intermediate was rotated. Threshold: missing OCSP stapling on production, fewer than 2 SCTs in the cert, intermediate served out of order, key usage missing digitalSignature/keyEncipherment, revoked cert presented, or wildcard scope of 2-level (e.g., *.com is rejection; *.api.example.com is fine). Trigger with: "check cert revocation", "audit ocsp", "ct log check", "cert chain audit".
allowed-tools
Read, Bash(python3:*), Bash(openssl:*)
compatibility
Designed for Claude Code
disallowed-tools
Bash(rm:*), Edit(/etc/*), Write(/etc/*)
version
3.30.0
author
Jeremy Longshore <jeremy@intentsolutions.io>
license
MIT
tags
security, tls, ocsp, certificate-transparency, pentest

Detecting SSL Certificate Issues

Overview

This skill is the second-level cert audit, run after analyzing-tls-config clears the protocol+cipher+expiry+hostname basics. It surfaces issues that don't break the handshake today but make the cert fragile or open to soft-bypass attacks: missing OCSP stapling forces clients to phone home to the CA (privacy + latency hit), missing Certificate Transparency SCTs are rejected by Chrome since 2018, an out-of-order chain confuses older clients, and over-broad wildcards expand the blast radius of any future key compromise.

When the skill produces findings

FindingSeverityThresholdAffected control
Revoked certificate presentedCRITICALOCSP responder says "revoked"RFC 6960
Missing or invalid OCSP stapleHIGHNo status_request response on productionRFC 6066, CA/B BR
Fewer than 2 SCTs embeddedHIGHCT-policy violation (Chrome enforces)RFC 6962, CA/B Baseline Reqs
Intermediate served out of RFC 5246 orderMEDIUMServer sends root before leafRFC 5246 §7.4.2
AIA extension missingMEDIUMNo CA Issuers / OCSP URL in certRFC 5280 §4.2.2.1
Over-broad wildcardHIGHScope of 2-level or wider (e.g., *.com)CA/B Baseline Reqs §3.2.2
Wildcard at apex SANLOW*.example.com without example.comRFC 6125 §6.4.3
Key Usage missing digitalSignatureMEDIUMKU bit absent for TLS server certRFC 5280 §4.2.1.3
Cert chain longer than 4LOWPerformance + trust expansionCA/B Baseline Reqs

Prerequisites

  • Python 3.9+ with cryptography library
  • openssl CLI 1.1.1+ (for OCSP query + chain enumeration)
  • Authorization for non-local targets (see references/AUTHORIZATION.md in skill #1 analyzing-tls-config for the canonical pattern)

Instructions

Step 1 — Confirm Authorization

Active scan; ask the user verbatim:

"Do you have authorization to perform TLS testing on this target? I need confirmation before proceeding."

Step 2 — Run the scanner
bash
python3 ${CLAUDE_PLUGIN_ROOT}/skills/detecting-ssl-cert-issues/scripts/check_cert_chain.py \
    https://target.example.com \
    --authorized

Options:

Usage: check_cert_chain.py URL [OPTIONS]

Options:
  --authorized       Attest authorization for non-local targets (required)
  --port PORT        Target port (default: 443)
  --output FILE      Write findings to FILE (default: stdout)
  --format FMT       json | jsonl | markdown (default: markdown)
  --min-severity SEV critical|high|medium|low|info (default: info)
  --timeout SECS     Per-probe timeout (default: 10)
  --skip-ocsp        Skip OCSP responder query (offline mode)
Step 3 — Interpret findings

CRITICAL/HIGH map to immediate action items; MEDIUM/LOW to backlog hardening. Cross-reference references/PLAYBOOK.md for OCSP stapling config snippets per server type.

Step 4 — Cross-skill chaining
  • After this skill, suggest checking-http-security-headers (#4) to verify HSTS preload status — HSTS preload depends on a clean cert chain to be effective.
  • For CI integration patterns, see references/PLAYBOOK.md § CI posture-monitoring.

Examples

Show full SKILL.md (243 more words)Show less
Example 1 — OCSP stapling audit before adopting must-staple

User: "We're considering Must-Staple — what's our OCSP stapling posture look like across endpoints?"

bash
for ENDPOINT in https://api.example.com https://app.example.com https://admin.example.com; do
  python3 ${CLAUDE_PLUGIN_ROOT}/skills/detecting-ssl-cert-issues/scripts/check_cert_chain.py \
      "$ENDPOINT" --authorized --min-severity medium
done

If any endpoint reports "Missing OCSP staple" HIGH, adopting Must-Staple on that cert breaks it on next renewal until OCSP-stapling config lands. Pair with references/PLAYBOOK.md § OCSP stapling for nginx / Caddy / Apache config.

Example 2 — CT-log compliance check before public launch

User: "Pre-launch — does our cert have enough SCTs for Chrome to trust it?"

bash
python3 ${CLAUDE_PLUGIN_ROOT}/skills/detecting-ssl-cert-issues/scripts/check_cert_chain.py \
    https://new-site.example.com --authorized

The scanner extracts embedded SCTs from the cert's CT extension. <2 SCTs → HIGH finding; Chrome's CT enforcement policy rejects the connection silently in HTTPS, leaving users with a generic error.

Example 3 — Wildcard scope audit

User: "An auditor flagged our wildcard cert as too broad."

bash
python3 ${CLAUDE_PLUGIN_ROOT}/skills/detecting-ssl-cert-issues/scripts/check_cert_chain.py \
    https://example.com --authorized --format json | jq '.[] | select(.title | contains("wildcard"))'

The JSON output captures the wildcard scope; pair with the auditor's request to either narrow the SAN list or move to per-service certs.

Output

JSON / JSONL / Markdown per lib/report.py. Exit codes: 0 clean, 1 high/critical, 2 error.

Error Handling

  • OCSP responder timeout → emitted as MEDIUM finding (not an error exit) with note to investigate responder availability.
  • CT log lookup unavailable → falls back to embedded-SCT parsing only; emits INFO note.
  • Untrusted cert → out of scope (skill #1 handles); this skill assumes the chain validates and looks at deeper posture.

Resources

  • references/THEORY.md — OCSP, CT, AIA, chain ordering, wildcard scope reasoning with RFC anchors
  • references/PLAYBOOK.md — OCSP stapling config per server type + CT-log compliance + AIA extension correctness
  • ../analyzing-tls-config/references/AUTHORIZATION.md — canonical ROE template + 2-step gate (shared across all active-scan skills)

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references) in skills/.curated/detecting-ssl-cert-issues of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • references/PLAYBOOK.md
  • references/THEORY.md
  • scripts/check_cert_chain.py

Open the folder on GitHubat commit cfae287

Compare with similar skills

Detecting Ssl Cert Issues next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Detecting Ssl Cert Issues compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Detecting Ssl Cert Issues this skilljeremylongshore/tons-of-skills-marketplace2.8k—~1.7kAutomated safety check: PassMIT
Implementing Hashicorp Vault Dynamic Secretsmukul975/Anthropic-Cybersecurity-Skills34k—~5.2kAutomated safety check: PassApache-2.0
Implementing Tlsancoleman/ai-design-components525—~3.6kAutomated safety check: NotesMIT
Performing Ssl Certificate Lifecycle Managementmukul975/Anthropic-Cybersecurity-Skills34k—~867Automated safety check: PassApache-2.0
Auditing Tls Certificate Transparency Logsmukul975/Anthropic-Cybersecurity-Skills34k—~4kAutomated safety check: PassApache-2.0
Trust Center BuilderGRCEngClub/claude-grc-engineering419—~2.6kAutomated safety check: PassCustom licence

Similar skills

  • Implementing Hashicorp Vault Dynamic Secrets

    mukul975/Anthropic-Cybersecurity-Skills

    Configures HashiCorp Vault dynamic secrets engines for database credentials, AWS IAM keys, and PKI certificates, with automatic generation, lease management, and rotation to eliminate static secrets…

    34k GitHub stars~5.2k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Implementing Tls

    ancoleman/ai-design-components

    Configure TLS certificates and encryption for secure communications.

    525 GitHub stars~3.6k tokensUpdated 10 mo ago
    SecurityAuto-check: notes
  • Performing Ssl Certificate Lifecycle Management

    mukul975/Anthropic-Cybersecurity-Skills

    Automates the full SSL/TLS certificate lifecycle, including generating Certificate Signing Requests, issuing, deploying, monitoring, renewing, and revoking X.509 certificates, using Python and ACME…

    34k GitHub stars~867 tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Auditing Tls Certificate Transparency Logs

    mukul975/Anthropic-Cybersecurity-Skills

    Monitors Certificate Transparency (CT) logs to detect unauthorized certificate issuance, discover subdomains via CT data, and alert on suspicious certificate activity for owned domains.

    34k GitHub stars~4k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Trust Center Builder

    GRCEngClub/claude-grc-engineering

    Builds and deploys a serverless trust center that publishes a company's compliance posture, with gated access to audit reports and an admin dashboard.

    419 GitHub stars~2.6k tokensUpdated 6 days ago
    Legal & ComplianceAuto-check passed
  • Linux Hardening

    BagelHole/DevOps-Security-Agent-Skills

    Apply CIS benchmarks and secure Linux servers. An agent skill from BagelHole/DevOps-Security-Agent-Skills.

    1.2k GitHub stars~662 tokensUpdated 4 mo ago
    DevOps & CloudAuto-check: notes

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Questions about Detecting Ssl Cert Issues

What does Detecting Ssl Cert Issues do?

Audit a target's TLS certificate beyond protocol/expiry — chain ordering, OCSP stapling, revocation status, Certificate Transparency presence, key-usage flags, and over-broad wildcards. Detecting Ssl Cert Issues is an agent skill from jeremylongshore/tons-of-skills-marketplace. Audit a target's TLS certificate beyond protocol/expiry — chain ordering, OCSP stapling, revocation status, Certificate Transparency presence, key-usage flags, and over-broad wildcards.

When should I use Detecting Ssl Cert Issues?

Detecting Ssl Cert Issues fits situations like: : TLS handshake already passes (skill 1 analyzing-tls-config cleared) but you suspect the cert posture is fragile; with: check cert revocation; cert chain audit.

How do I install Detecting Ssl Cert Issues in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill detecting-ssl-cert-issues -a claude-code`. Or copy the skill folder (skills/.curated/detecting-ssl-cert-issues in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/detecting-ssl-cert-issues in your project. Claude Code loads it when a task matches its description.

How do I install Detecting Ssl Cert Issues in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill detecting-ssl-cert-issues -a codex`. Or copy the skill folder (skills/.curated/detecting-ssl-cert-issues in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/detecting-ssl-cert-issues in your project. Codex loads it when a task matches its description.

Can I use Detecting Ssl Cert Issues in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill detecting-ssl-cert-issues -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/detecting-ssl-cert-issues, .gemini/skills/detecting-ssl-cert-issues, .github/skills/detecting-ssl-cert-issues and .opencode/skills/detecting-ssl-cert-issues in your project.

What does Detecting Ssl Cert Issues need to run?

Going by SKILL.md and its folder, Detecting Ssl Cert Issues needs Python for the scripts in its folder and the command-line tools its instructions call (python3 and jq). Our summary lists: Python 3. Its frontmatter pre-approves these tools: Read, Bash(python3:*), Bash(openssl:*). Compatibility (from SKILL.md): Designed for Claude Code.

Does Detecting Ssl Cert Issues access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Detecting Ssl Cert Issues safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Detecting Ssl Cert Issues use?

Detecting Ssl Cert Issues is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Detecting Ssl Cert Issues use?

About 1.7k tokens (SKILL.md is roughly 6.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.8k tokens, read only when the agent opens those files.

What are the alternatives to Detecting Ssl Cert Issues?

Skills that share tags, products or a category with Detecting Ssl Cert Issues: Implementing Hashicorp Vault Dynamic Secrets (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Implementing Tls (ancoleman/ai-design-components, 525 stars), Performing Ssl Certificate Lifecycle Management (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Auditing Tls Certificate Transparency Logs (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Detecting Ssl Cert Issues?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.