I often need to check what is happening on a website beyond simply asking whether it is online. I may want to check its content, metadata, technologies, SSL certificate, DNS records, or even see how the page looks.
Checking all of this separately gets tedious, especially when I want to look at several websites. I started thinking about what would happen if I could give an AI agent a URL and let it investigate the website for me.
So I built a small website observatory using an AI client, MCP, and web APIs. I can give it a website and ask it to collect different signals, compare the results, and tell me what changed or stands out.
I found this useful for quickly understanding a website without opening several tools manually. In this article, I’ll show you how I built it and how you can create a similar workflow yourself.
What I Wanted the Observatory to Do
I didn’t want to build another dashboard that simply shows whether a website is up or down. I wanted to give an AI agent enough information to understand a website from several angles.
My basic requirement was simple. I should be able to give it a URL and ask questions such as:
- Is the website accessible?
- What has changed on the page?
- What metadata does it expose?
- What technologies does it use?
- Is its SSL certificate valid?
- What DNS information is available?
- What does the page currently look like?
I also wanted the agent to bring these results together instead of returning a collection of unrelated API responses. That made MCP a good fit for the experiment because the AI client could access multiple web capabilities through the same workflow.
The APIs I Used
I used Geekflare as the data source for the observatory because it provides APIs for several aspects of website analysis. I picked the ones that could give me a useful view of a website from different angles.
- Site Uptime API: Check whether a website is reachable and inspect its HTTP status.
- Web Scraping API: Extract webpage content in formats such as Markdown, HTML, or JSON.
- Meta Scraping API: Collect webpage metadata and structured information.
- Screenshot API: Capture a visual snapshot of a webpage.
- Loadtime API: Check webpage loading and network timing metrics.
- DNS Record API: Retrieve DNS records for a domain.
- TLS Scan API: Inspect TLS and certificate information.
- Broken Link API: Find broken links on a webpage.
I wanted these checks to be available to the AI agent through one interface. Geekflare MCP provides that connection, letting me give the agent a website and ask it to perform multiple checks as part of the same workflow.
With the APIs selected, I could move on to building the observatory.
Setting Up Geekflare MCP
The setup is pretty straightforward and took me around five minutes. I connected Geekflare MCP to Claude Code, and once the connection was ready, the available Geekflare tools appeared in the AI client.
You can set it up yourself using the Geekflare MCP setup guide for Claude Code.
Once the connection was working, I could start building the website observatory.
Running the Observatory
Once the MCP connection was ready, I gave Claude Code a website URL and asked it to run the relevant Geekflare checks. I wanted the different observations in one response, so I asked Claude to organize the results in a table and point out anything that stood out.
I used https://www.nasa.gov/ for the first test and gave Claude the following prompt:
Analyze this website as a website observatory:
https://www.nasa.gov/
Use the available Geekflare MCP tools to collect the following information:
1. Check whether the website is reachable and return its HTTP status.
2. Scrape the homepage and summarize its main content.
3. Extract the page title, description, canonical URL, Open Graph data, Twitter metadata, and structured data.
4. Capture a full-page screenshot of the homepage.
5. Check the page load time and report the available timing metrics.
6. Retrieve the domain's DNS records.
7. Check the SSL/TLS certificate and report its validity and expiration details.
8. Check the homepage for broken internal and external links.
9. Check whether the URL redirects and show the redirect path if applicable.
Present all the collected results in a clear table. Add a short summary after the table highlighting anything unusual, noteworthy, or potentially requiring attention.
Do not invent values. If a tool does not return information, state that it was unavailable.
Claude Code then used the available Geekflare MCP tools and organized the results into a single table.
Here is the response:
The full respone:
Here are the results from nine Geekflare checks on https://www.nasa.gov/, run on 18 Sep 2026 around 14:10 UTC.
| # | Check | Result |
|---|---|---|
| 1 | Reachability | Reachable. HTTP 200 OK. |
| 2 | Homepage content | This is NASA's news and discovery hub. It has mega-menu navigation (Missions, Humans in Space, Earth, Solar System, Universe, Science, Aeronautics, Technology, Learning Resources, About, NASA en Español, News, Multimedia). The main feature is an International Observe the Moon Night promo (Sept 19). Featured news includes a record-young "baby" planet, Progress 96 cargo launch, ISS crew updates, and "NASA Watches Earth's Weight". There is also an LRO "once-in-century" Moon crater story, and the Image of the Day is the 1976 Space Shuttle Enterprise rollout. Other items are Hubble/Webb/Chandra galleries, a newsletter signup, and a promo for the MAX POWER aerospace festival at Kennedy (Nov 7–8). |
| 3a | Title / Description | Title: "NASA". Description: "NASA.gov brings you the latest news, images and videos from America's space agency, pioneering the future in space exploration, scientific discovery and aeronautics research." |
| 3b | Canonical, language, robots | Canonical https://www.nasa.gov/. Language en-US. Robots: follow, index, max-snippet:-1, max-video-preview:-1, max-image-preview:large
|
| 3c | Open Graph | type website, locale en_US, title/site_name "NASA", url https://www.nasa.gov/. Image .../2018/07/174116main_2006_01777_highres.jpg (1024×819, alt "NASA Meatball paint refresh"). Video .../2026/09/farside-earth-moon-line-nocard-1080p30.mp4. Updated 2026-09-17T15:19:25-04:00 |
| 3d | card summary_large_image, same title, description and image as OG |
|
| 3e | Structured data (JSON-LD) | An @graph with Organization, WebSite (with SearchAction ?s={search_term_string}), ImageObject (meatball_hires.jpg), WebPage (published 2022-12-07, modified 2026-09-17), Person (author "Dacia Massengill"), Article, and VideoObject (1920×1080) |
| 3f | Other meta | Generator: WordPress 7.0.5. Parse.ly and Search.gov tags are present. |
| 4 | Full-page screenshot | Captured (desktop PNG): https://cdn.geekflare.com/tests/screenshot/BQ24SkNqpQT1QlWA |
| 5 | Load time (from US test server) | DNS 3 ms, connect 31 ms, TLS 37 ms, send 0 ms, wait/TTFB 31 ms, download 48 ms, total 148 ms. No redirect time. 351,527 bytes read. Remote IP 192.0.66.108. Server nginx, x-cache: HIT, cache-control: max-age=300. Protocols: HTTP/1.1 and HTTP/2 supported, HTTP/3 and HTTP/1.0 not. |
| 6a | DNS: A / AAAA | A 192.0.66.108. AAAA 2a04:fa87:fffd::c000:426c
|
| 6b | DNS: MX |
nasa-gov.mail.protection.outlook.com (priority 0), i.e. Microsoft 365 |
| 6c | DNS: NS / SOA | Six Akamai nameservers (a1-32, a5-66, a8-66, a9-64, a12-64, a14-67 .akam.net). SOA primary a1-32.akam.net, hostmaster dns.nasa.gov, serial 202301354, refresh 7200, retry 900, expire 1209600, min TTL 300 |
| 6d | DNS: TXT | 22 records. These include a strict SPF (-all, Outlook plus eight internal includes), Amazon SES, several Google/OpenAI verifications, Microsoft, Apple, Atlassian, DocuSign, Webex, Smartsheet, and several opaque tokens. |
| 6e | DNS: CNAME / CAA / SRV | None returned |
| 7 | SSL/TLS certificate | CN nasa.gov, SANs nasa.gov, www.nasa.gov. Issuer Let's Encrypt (YE2). Valid from Aug 11 2026 to Nov 9 2026 23:22:58 GMT (about 52 days left). Trusted, hostname matches, chain complete (5 certs up to ISRG Root X1), not expired. Protocols: TLS 1.2 and 1.3 only. Negotiated cipher TLS_AES_128_GCM_SHA256 with ECDH forward secrecy. Tool flags: "weak key" (256-bit), Logjam: vulnerable, OCSP stapling off, HTTP compression on (BREACH advisory). No POODLE, DROWN, FREAK, Sweet32, RC4, CRIME, null or anonymous ciphers. |
| 8 | Broken links | 231 links checked. 0 broken, 200 OK, 31 redirects (mostly 301s, one 307, two 302s), 0 server errors, 0 forbidden, 0 timeouts. |
| 9 | Redirects | None. https://www.nasa.gov/ answers directly with 200. HSTS: max-age=31536000; includeSubdomains; preload
|
Summary
Overall the site is in very good health. It is up, fast (148 ms total, served from cache), has no broken links, uses HTTPS with HSTS preload, allows only TLS 1.2/1.3, and has a trusted certificate with a complete chain.
Security flags that are probably false positives
- Logjam: The Logjam warning reports a 253-bit key. That size matches X25519 elliptic-curve key exchange, and Logjam is an attack on weak finite-field Diffie-Hellman. This is very likely a misreading by the scanner.
- "Weak key": The 256-bit "weak key" flag is consistent with an ECDSA P-256 certificate, which is considered strong. It would only be weak if it were an RSA key.
- OCSP stapling: No stapling is expected, since Let's Encrypt has been phasing out OCSP.
I'd confirm the first two with a second scanner (such as SSL Labs) before acting on them. The certificate expires in about seven weeks, which is normal for Let's Encrypt's 90-day certificates, as long as auto-renewal is working.
Things worth tidying up
-
Redirecting links: 31 homepage links go through redirects instead of pointing straight at the final page. Examples:
- Internal pages such as
/events,/live,/accessibility/and/contact-nasa/. - Many science.nasa.gov links missing a trailing slash (e.g.
/mars,/venus). - A footer link to
http://oig.nasa.gov/over plain HTTP. - A temporary 307 on
science.nasa.gov/solar-system/overview/.
- Internal pages such as
-
Metadata quirks:
- The Open Graph image is a 2018 photo, while the structured data names a different primary image.
- The structured data describes the homepage as an Article with a personal author and a 2022 VideoObject.
- The description text contains a double-encoded
'. - The
ya:ovs:upload_datevalue is malformed ("2022-12-07EST13:25:23-05:00").
- Stale search suggestions: "Expedition 64" and "SpaceX Crew-2" date from 2020–21.
- Version disclosure: The page publicly reveals it runs WordPress 7.0.5.
Not covered by these checks
- Security headers such as Content-Security-Policy and X-Content-Type-Options didn't appear in the response headers returned, but I didn't run a dedicated header audit.
- DMARC (
_dmarc.nasa.gov) wasn't checked, because the DNS lookup only covers the apex domain.
Conclusion
I built this website observatory to bring different website checks into one AI driven workflow. Instead of checking each signal separately, I can give Claude a URL and let Geekflare MCP collect the data and organize it for me.
The setup is simple, but the workflow can be useful for developers who need to inspect websites regularly. You can also add more checks or change the prompt based on what you want to observe.


Top comments (0)