AI Agent Hub
Back to skills
Website Diagnosis Tool icon

Website Diagnosis Tool

IT Ops & Security Updated 2026.08.30

Paste the following prompt into your AI chat to install this skill:

Please follow https://skillhub.cn/install/skillhub.md to install @user_d703b0f6/website-diagnosis

About this skill

Problem

When a website is unreachable, slow, has certificate errors, expires, or shows suspicious content, the cause often spans WHOIS, DNS, SSL, HTTP, response headers, and page content. Manual checks can miss combinations such as valid DNS but blocked 80/443, valid HTTPS with Mixed Content, or SPF records that do not cover the actual sending IP.

How It Works

The skill diagnoses a target domain or URL across Windows, macOS, and Linux. It checks domain registration and expiry, DNS records and IP location, SSL validity and domain match, HTTP/HTTPS response time and redirect chains, security response headers, server fingerprints, and page title, content, and suspicious keywords. Implementation relies on pure HTTP APIs and Python standard library components to reduce external dependencies.

It converts raw results into risk assessments. Core header checks focus on HSTS, CSP, X-Content-Type-Options, X-Frame-Options, and Referrer-Policy; Expect-CT is ignored, and X-XSS-Protection: 0 is treated as a modern best practice. The output includes an overall rating and prioritized fixes, such as certificate renewal, firewall or security group changes, redirect cleanup, and compromised-content investigation.

Boundaries

This is useful for site health checks, security configuration screening, and fault localization. It does not replace server log analysis, full-path network troubleshooting, load testing, penetration testing, or mail system validation. Results involving CDNs, GeoDNS, multi-node certificates, shared hosting, or residential ISP port blocking should be reviewed against the actual deployment environment.

Use Cases

  • When users report a domain as unreachable, check WHOIS expiry, DNS records, HTTP/HTTPS timeouts, and blocked ports.
  • Before release, verify SSL certificate status and core HSTS/CSP headers, then list missing items and fixes.
  • When a page shows suspicious keywords or an abnormal title, use content checks to assess possible tampering.
  • For slow-access complaints, review response time, redirect chains, server IP location, and shared-hosting limits.

Best For

  • Ops engineer: debugging unreachable domains by checking WHOIS, DNS, ports, and server faults.
  • Website owner: pre-release review of SSL certificate and core security headers, with missing items listed.
  • Security on-call: assessing pages with abnormal content for possible malicious keyword injection.
  • Technical support: handling slow-access or certificate alerts and producing priority fixes.