reap / rules / transport posture
TLS certificate, protocol and cipher health on agent endpoints
tls-cert-health ASI09 Human-Agent Trust Exploitation severity: high
What it detects
Certificate validity, hostname mismatch, weak protocol and cipher selection. ASI09.
Inspects the live TLS handshake for expired/not-yet-valid/self-signed certs, hostname mismatch, weak TLS version, or weak cipher suite.
applies to any agent endpoint over HTTP
Why it matters
Certificate and cipher problems undermine the assurance the transport is supposed to provide.
On reap-range
| insecure target | not exercised (see limitation below) |
| correct target | — |
Run only this check
reap -t https://your-host/mcp --authorized --include tls-cert-health
Not installed? Install REAP. Only scan systems you own or are authorised to test. Reference: docs/PROBES.md.