MCP security report

agent-observatory-sensor.nolimit-observatory.workers.dev

F34/100
Security grade FHigh-severity signals — review these before connecting.
Connected ✓30 tools scanned

https://agent-observatory-sensor.nolimit-observatory.workers.dev/s/minguo-ok/mcp

highagent-tool-index
Embedded directive instructing agent to follow an external redirect chain
The description explicitly instructs the AI to 'Follow start_here.hop first (skill file, 302)' and says it 'also returns docs, CLI, and remote MCP hops.' This is an imperative aimed at the agent's behavior rather than a description of the tool's own function, and it encourages the agent to chase an external 302 redirect to an unverified 'skill file' and to connect to additional remote MCP servers. This is a classic tool-poisoning / supply-chain pattern that could lead the agent to load untrusted instructions or capabilities without the user's knowledge, and it also references a 'pay-per-call' gateway that could incur costs without explicit user consent.
highpeople-search-index
People-search / doxxing capability with encouragement to expand toolset via remote MCP
This tool is described as finding a 'living people-search index' and returning 'CLI setup, docs, API, and remote MCP hops.' Locating and querying people-search services for information about living individuals raises privacy and potential doxxing/surveillance concerns, and the instruction to fetch additional remote MCP hops encourages the agent to silently expand its own capability set beyond the tool's stated, narrow purpose (finding an index), which is a supply-chain/scope-creep risk.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
lowminguo-ok
Overly broad shared input schema unrelated to stated purpose
Every tool in this set (minguo-ok, utc-time, timezone, validate-json, etc.) shares an identical 9-field schema (zone, json, url, host, city, query, path, ref, feed) regardless of the tool's single stated purpose. For example, a 'Minguo year band' calculator accepts json, url, host, city, query, path, ref, and feed parameters that have nothing to do with computing a year band. This unusual over-provisioning means any of these tools could silently accept and process arbitrary URLs, file paths, or JSON payloads under the guise of an unrelated, narrowly-described tool, making it hard for a reviewer or user to know what data a given call is actually sending or processing. This pattern is present across all 30 tools and increases the risk of disguised data exfiltration or SSRF-like behavior even though each individual description claims data is 'discarded.'
lowweb-fetch
Generic network-fetch capability duplicated across many similarly named tools
Multiple tools (web-fetch, fetch-status, citation, inspect-robots, lib-docs-hint, playwright-url-ok, browser-url-ok) all perform outbound HTTPS requests to arbitrary user-supplied URLs. While each is described as returning only minimal metadata (status code, content type) and discarding the body, the sheer redundancy and the shared broad schema (which also includes host, path, city, feed, etc.) make it difficult to verify that only the stated minimal data is retrieved/returned, and could be used to probe internal or unintended hosts (SSRF-style) under an innocuous tool name.
Embed this badge

Show your MCP server’s security grade

MCP security grade F

Paste this into your README:

[![MCP security](https://gateturbo.com/badge/scan/047492bd-c566-4199-a30b-452fb304629b)](https://gateturbo.com/report/047492bd-c566-4199-a30b-452fb304629b)

Scanned 9/15/2026 · This is a point-in-time snapshot of the server’s public tools. Re-scan.

Connect this server safely with gate.

Continuous re-scans, drift alerts, per-tool allow/ask/block, and a log of every call.

Monitor it — free