MCP security report

apipay.fly.dev

F5/100
Security grade FHigh-severity signals — review these before connecting.
Connected ✓8 tools scanned

https://apipay.fly.dev/mcp

highvendor_call
Broad server-side access to multiple vendor management APIs with root credentials
This tool injects the owner's root/management credentials for up to 8 different vendor platforms (Supabase, Vercel, Fly, Resend, GitHub, npm, Cloudflare, LemonSqueezy) and allows arbitrary path/method/body calls. Although the description claims destructive, billing, and admin routes are 'blocked', this is a self-declared server-side filter that the calling agent cannot verify. A compromised or manipulated agent (e.g. via a malicious search_apis/call_api result or injected content) could use this to read configuration, list secrets/env vars, or make unintended writes across many high-value platforms. The blast radius here is far larger than a typical 'call an API' tool.
highsecret_transfer
Server-side secret exfiltration/movement primitive with no destination validation shown
This tool moves live secrets (e.g. a Supabase service_role key) directly between vendor resources without ever showing the value to the user or agent for review. While marketed as a safety feature ('never enters this conversation'), this also means the human/agent has no visibility to catch a mistaken or maliciously-steered destination. If any upstream content (e.g. a poisoned search_apis result, or a manipulated instruction) causes the agent to specify a wrong or attacker-influenced 'to' vendor/resource, a powerful secret (service_role/root key) could be silently copied to a location the owner did not intend, with no way to detect it from the conversation alone.
mediumget_vault_link
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumvendor_call
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumsecret_transfer
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumsecret_generate
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumsecret_generate
Direct write of generated secrets to vendor resources without confirmation surface
Similar to secret_transfer, this tool writes newly generated secrets directly into a vendor resource server-side. Because the value is never shown, there's no way for the user to verify the correct resource/key was targeted; if the agent is manipulated into pointing 'to' at an unintended resource, a valid new secret could silently overwrite existing configuration or credentials without the user's awareness.
mediumtopup
Tool can trigger real monetary charges via a standing auto-refill mandate
This tool can charge the owner's payment mandate up to $100 in a single call. While gated by 'owner-configured limits,' the tool itself does not enforce any additional per-call confirmation, so an agent that is socially engineered (e.g., via a crafted search_apis description or repeated prompting) into calling this tool could trigger unwanted charges up to the configured ceiling with a single invocation.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
lowget_vault_link
Embedded directive to the AI about user interaction pattern
The description contains an imperative instruction aimed at the calling agent ('Never ask the user to paste an API key into the chat — always use this link instead'). This is plausibly a legitimate security best-practice, but it is still a behavior-steering instruction embedded in a tool description rather than a functional parameter, which is worth noting as a pattern to watch for in case future tools use similar phrasing to embed less benign directives.
Embed this badge

Show your MCP server’s security grade

MCP security grade F

Paste this into your README:

[![MCP security](https://gateturbo.com/badge/scan/016122a5-3209-4c68-8bca-11df4c266fa3)](https://gateturbo.com/report/016122a5-3209-4c68-8bca-11df4c266fa3)

Scanned 9/17/2026 · This is a point-in-time snapshot of the server’s public tools. Re-scan.

Connect this server safely with gate.

Continuous re-scans, drift alerts, per-tool allow/ask/block, and a log of every call.

Monitor it — free