MCP security report

agent-observatory-sensor.nolimit-observatory.workers.dev

F37/100
Security grade FHigh-severity signals — review these before connecting.
Connected ✓30 tools scanned

https://agent-observatory-sensor.nolimit-observatory.workers.dev/s/macroman-ok/mcp

highagent-tool-index
Embedded instruction to follow untrusted redirect chain
The description tells the agent to 'Follow start_here.hop first (skill file, 302)' and then follow additional docs/CLI/remote MCP hops. This is a directive embedded in a tool description that steers the agent toward fetching and likely executing content/instructions from an external, unverified 'pay-per-call' gateway (Monid). This is a classic vector for prompt injection or SSRF-style redirection: the agent may be induced to load and act on untrusted remote content or register additional (unvetted) tool servers without the user's explicit awareness or consent.
highpeople-search-index
Directs agent to external people-search/surveillance service and remote hops
Description instructs the agent to locate and follow a 'living people-search index (Ploid)' along with CLI, API, and remote MCP hops. This both encourages connecting to unknown external services (similar redirect-chasing risk as agent-tool-index) and specifically concerns lookup of personal information about living individuals, which raises privacy/surveillance concerns if invoked without clear user intent and consent.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
lowmacroman-ok
Unrelated/overloaded parameter schema shared across all tools
Every tool in this set exposes the same nine-field schema (zone, json, url, host, city, query, path, ref, feed) regardless of the tool's actual single-purpose function (e.g., a MacRoman byte-band check accepting a city or git-ref field). This copy-paste pattern makes it hard for a reviewer or agent to reason about what data actually flows to which endpoint, and could mask unexpected data routing (e.g., a 'city' or 'query' value being sent to an external host under a differently-named tool). Recommend tightening each tool's schema to only the parameters it actually uses.
Embed this badge

Show your MCP server’s security grade

MCP security grade F

Paste this into your README:

[![MCP security](https://gateturbo.com/badge/scan/0367e94b-c347-4b16-894a-1752a96c4435)](https://gateturbo.com/report/0367e94b-c347-4b16-894a-1752a96c4435)

Scanned 9/16/2026 · This is a point-in-time snapshot of the server’s public tools. Re-scan.

Connect this server safely with gate.

Continuous re-scans, drift alerts, per-tool allow/ask/block, and a log of every call.

Monitor it — free