ssl-tls-audit

Audit TLS/SSL configurations across multiple ports and map findings to compliance frameworks.

13|1|Updated Feb 4, 2026
One-click install
npx skills add https://github.com/0x0pointer/skills --skill ssl-tls-audit
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: ssl-tls-audit
Source: https://github.com/0x0pointer/skills/tree/main/ssl-tls-audit
Command: npx skills add https://github.com/0x0pointer/skills --skill ssl-tls-audit

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

It provides a thorough audit of TLS/SSL configurations, identifying weak protocols, cipher issues, certificate problems, and compliance gaps across multiple services.

Core Features & Use Cases

  • Comprehensive scanning of protocol versions, cipher suites, and certificate chains.
  • Detection of known vulnerabilities such as Heartbleed, POODLE, DROWN, and more.
  • Multi‑port TLS assessment for over 20 common services.
  • Automatic mapping of findings to PCI DSS 4.0, NIST SP 800‑52r2, and FedRAMP controls.
  • Generates structured reports, Mermaid diagrams, and live dashboards.

Quick Start

Run the ssl-tls-audit skill on target host 10.0.0.1:443 with depth standard.

Frequently Asked Questions about ssl-tls-audit

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I audit TLS and SSL configurations for compliance with PCI DSS and NIST?

To audit TLS and SSL configurations for compliance, scan protocols, ciphers, and certificates across multiple ports. This process maps identified vulnerabilities directly to PCI DSS 4.0, NIST SP 800-52r2, and FedRAMP controls.

Can I detect vulnerabilities like Heartbleed and POODLE during an SSL scan?

Yes, an SSL scan can detect known vulnerabilities like Heartbleed, POODLE, and DROWN. The audit assesses protocols, cipher suites, and session management to identify these specific security flaws.

What tools do I need to perform a comprehensive TLS audit on a target host?

Performing a comprehensive TLS audit requires access to Kali tools like testssl.sh, sslscan, sslyze, OpenSSL, Nmap, and nuclei via the MCP toolset to assess protocols and identify vulnerabilities.

How do I scan TLS configurations across multiple ports for over 20 services?

Scanning TLS configurations across multiple ports involves assessing over 20 common services. The audit evaluates protocol versions, certificate chains, and session management for each targeted port.

Does this TLS audit generate structured compliance reports and diagrams?

Yes, the TLS audit generates structured compliance reports, Mermaid diagrams, and live dashboards. These outputs map scanned vulnerabilities and weak cipher issues directly to regulatory frameworks.

What is the best way to check for weak cipher suites and certificate chain issues?

The best way to check for weak cipher suites and certificate chain issues is a comprehensive scan. It evaluates protocol versions, session management, and certificates to pinpoint configuration weaknesses.