sslmate-cert-spotter-api — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited sslmate-cert-spotter-api (Agent Skill) and scored it 96/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 1 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 1 flagged
The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
SSLMate's Cert Spotter API is a tool that allows developers to monitor newly issued SSL/TLS certificates. It's used by security professionals, researchers, and domain owners to detect potential phishing attacks, brand abuse, and unauthorized certificate issuance.
Official docs: https://sslmate.com/certspotter/api/
This skill uses the Membrane CLI (npx @membranehq/cli@latest) to interact with SSLMate — Cert Spotter API. Membrane handles authentication and credentials refresh automatically — so you can focus on the integration logic rather than auth plumbing.
npx @membranehq/cli@latest login --tenantA browser window opens for authentication. After login, credentials are stored in ~/.membrane/credentials.json and reused for all future commands.
Headless environments: Run the command, copy the printed URL for the user to open in a browser, then complete with npx @membranehq/cli@latest login complete <code>.
npx @membranehq/cli@latest search sslmate-cert-spotter-api --elementType=connector --jsonTake the connector ID from output.items[0].element?.id, then:
npx @membranehq/cli@latest connect --connectorId=CONNECTOR_ID --jsonThe user completes authentication in the browser. The output contains the new connection id.
When you are not sure if connection already exists:
npx @membranehq/cli@latest connection list --jsonIf a SSLMate — Cert Spotter API connection exists, note its connectionId
When you know what you want to do but not the exact action ID:
npx @membranehq/cli@latest action list --intent=QUERY --connectionId=CONNECTION_ID --jsonThis will return action objects with id and inputSchema in it, so you will know how to run it.
Use npx @membranehq/cli@latest action list --intent=QUERY --connectionId=CONNECTION_ID --json to discover available actions.
npx @membranehq/cli@latest action run --connectionId=CONNECTION_ID ACTION_ID --jsonTo pass JSON parameters:
npx @membranehq/cli@latest action run --connectionId=CONNECTION_ID ACTION_ID --json --input "{ \"key\": \"value\" }"When the available actions don't cover your use case, you can send requests directly to the SSLMate — Cert Spotter API API through Membrane's proxy. Membrane automatically appends the base URL to the path you provide and injects the correct authentication headers — including transparent credential refresh if they expire.
npx @membranehq/cli@latest request CONNECTION_ID /path/to/endpointCommon options:
| Flag | Description |
|---|---|
-X, --method | HTTP method (GET, POST, PUT, PATCH, DELETE). Defaults to GET |
-H, --header | Add a request header (repeatable), e.g. -H "Accept: application/json" |
-d, --data | Request body (string) |
--json | Shorthand to send a JSON body and set Content-Type: application/json |
--rawData | Send the body as-is without any processing |
--query | Query-string parameter (repeatable), e.g. --query "limit=10" |
--pathParam | Path parameter (repeatable), e.g. --pathParam "id=123" |
You can also pass a full URL instead of a relative path — Membrane will use it as-is.
npx @membranehq/cli@latest action list --intent=QUERY (replace QUERY with your intent) to find existing actions before writing custom API calls. Pre-built actions handle pagination, field mapping, and edge cases that raw API calls miss.~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.