Token导航 LogoToken导航TokenDH.com
研究检索需要联网github未标认证来源可访问许可证需确认审计异常

certificate-transparency证书透明度

Agent Skill

certificate-transparency 用于查找、检索和筛选相关信息,适合在 Codex、Claude、Cursor、Gemini CLI 中需要根据关键词、任务场景或来源线索快速定位候选结果时使用。可结合来源仓库、安装命令和原始 README 继续核验具体用法。安装前建议确认权限范围、维护状态,以及是否会触发联网、命令执行或文件读写。

总安装

261

周安装

11

GitHub Stars

222

下载量

92
CodexClaudeCursorGemini CLI

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

unknown

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:certificate-transparency(证书透明度)
来源仓库:https://github.com/transilienceai/communitytools
仓库路径:skills/certificate-transparency
安装命令:
npx skills add https://github.com/transilienceai/communitytools --skill certificate-transparency
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 npx skills 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

skills.shnpx skills
npx skills add https://github.com/transilienceai/communitytools --skill certificate-transparency

简介

Certificate Transparency 查询公开日志以发现域名关联的已签发证书。

  • 适用于安全监控、内部命名规范识别和潜在滥用证书的检测。
  • 通过 crt.sh API 获取 JSON 格式的证书详情和 Subject Alternative Names。
  • 安装前需确认是否会发起公网请求,注意遵守目标站点速率限制规则。
  • 输出为证书指纹列表和 SAN 解析结果,供人工进一步分析使用。

SKILL.md

Certificate Transparency Skill

Purpose

Query Certificate Transparency logs to discover certificates issued for a domain, extract Subject Alternative Names (SANs), and identify internal naming conventions.

Operations

1. query_crt_sh_json

Query crt.sh for all certificates matching a domain.

Endpoint:

GET https://crt.sh/?q=%25.{domain}&output=json

Request Headers:

User-Agent: TechStackAgent/1.0
Accept: application/json

Process:

  1. URL encode domain with wildcard prefix
  2. Make HTTP GET request to crt.sh
  3. Parse JSON response array
  4. Extract certificate metadata

Response Fields:

{
  "issuer_ca_id": 183267,
  "issuer_name": "C=US, O=Let's Encrypt, CN=R3",
  "common_name": "example.com",
  "name_value": "example.com\nwww.example.com\napi.example.com",
  "id": 1234567890,
  "entry_timestamp": "2024-01-15T10:30:00.000",
  "not_before": "2024-01-15T09:00:00",
  "not_after": "2024-04-15T09:00:00",
  "serial_number": "abc123..."
}

2. extract_sans

Parse Subject Alternative Names from certificate data.

Process:

  1. Split name_value field by newlines
  2. Filter for domain matches
  3. Deduplicate entries
  4. Validate format (no wildcards in extracted names)

Example:

Input: "example.com\n*.example.com\napi.example.com\nwww.example.com"
Output: ["example.com", "api.example.com", "www.example.com"]

3. identify_naming_patterns

Analyze SANs to detect internal naming conventions.

Pattern Detection:

patterns = {
    "environment_prefix": r"^(prod|staging|dev|test|qa|uat)-",
    "environment_suffix": r"-(prod|staging|dev|test|qa|uat)$",
    "numbered_instances": r"(\d+)$",
    "geo_prefix": r"^(us|eu|apac|asia|emea|latam)-",
    "service_pattern": r"^(api|app|web|cdn|static|assets)-"
}

Example Output:

{
  "patterns": [
    {
      "type": "environment_prefix",
      "regex": "^(prod|staging|dev)-",
      "matches": ["prod-api", "staging-api", "dev-api"]
    },
    {
      "type": "geo_prefix",
      "regex": "^(us|eu)-",
      "matches": ["us-east-api", "eu-west-api"]
    }
  ]
}

4. find_wildcard_certs

Identify wildcard certificate usage.

Process:

  1. Filter certificates where common_name starts with "*."
  2. Note wildcard scope (*.domain.com vs *.subdomain.domain.com)
  3. Flag potential security implications

Wildcard Analysis:

{
  "wildcards": [
    {
      "pattern": "*.example.com",
      "scope": "root_domain",
      "certificates_count": 5,
      "latest_issue": "2024-01-15"
    },
    {
      "pattern": "*.api.example.com",
      "scope": "subdomain",
      "certificates_count": 2,
      "latest_issue": "2024-01-10"
    }
  ]
}

Output

{
  "skill": "certificate_transparency",
  "domain": "string",
  "results": {
    "certificates": [
      {
        "id": "number",
        "issuer": "string",
        "common_name": "string",
        "sans": ["array"],
        "not_before": "date",
        "not_after": "date",
        "is_wildcard": "boolean"
      }
    ],
    "unique_subdomains": ["array"],
    "naming_patterns": [
      {
        "type": "string",
        "pattern": "string",
        "examples": ["array"]
      }
    ],
    "wildcard_analysis": {
      "wildcards_found": "number",
      "patterns": ["array"]
    },
    "issuers": {
      "issuer_name": "count"
    }
  },
  "evidence": [
    {
      "type": "ct_certificate",
      "id": "number",
      "common_name": "string",
      "issuer": "string",
      "timestamp": "ISO-8601"
    }
  ],
  "metadata": {
    "total_certificates": "number",
    "unique_subdomains": "number",
    "query_timestamp": "ISO-8601"
  }
}

Certificate Issuer Analysis

Track which CAs are used (reveals hosting/security practices):

Issuer PatternIndicates
Let's EncryptCost-conscious, automated cert management
DigiCert, SectigoEnterprise/compliance requirements
AWS Certificate ManagerAWS infrastructure
CloudflareCloudflare CDN/proxy
Google Trust ServicesGCP infrastructure

Rate Limiting

  • crt.sh: Max 10 requests/minute
  • Implement exponential backoff on 429 responses
  • Cache results to avoid repeated queries

Error Handling

  • If crt.sh returns 503, wait 30s and retry
  • If timeout, retry with longer timeout (60s)
  • If JSON parse fails, log raw response
  • Continue with partial results if some queries fail

Security Considerations

  • Only query public CT logs
  • Do not attempt to access certificate private keys
  • Log all queries for audit trail
  • Respect crt.sh rate limits

适合场景

01

用户想查找某类 Agent Skill 时

02

需要根据任务场景推荐可安装能力包时

03

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

Codex

38.32%
按下载量换算35

Claude

28.58%
按下载量换算26

Cursor

20.6%
按下载量换算19

Gemini CLI

8.87%
按下载量换算8

安全审计

Gen Agent Trust Hub

通过

Socket

未通过

Snyk

通过

权限和风险

需要联网

该 Skill 可能需要联网访问来源站点、仓库或外部 API;具体网络访问范围需要结合源码和 README 复核。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。来源安全扫描存在 warning/failed 结果,不能写成本站确认安全。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills