MCP security report

agent-observatory-sensor.nolimit-observatory.workers.dev

F43/100
Security grade FHigh-severity signals — review these before connecting.
Connected ✓30 tools scanned

https://agent-observatory-sensor.nolimit-observatory.workers.dev/s/mjd-n/mcp

highagent-tool-index
Embedded instruction directs agent to follow untrusted redirect chain
The description explicitly instructs the calling agent to 'Follow start_here.hop first (skill file, 302)' and then follow additional 'docs, CLI, and remote MCP hops.' This is a directive embedded in a tool description that tells the agent to chain into unknown, externally-controlled endpoints (a redirect chain and additional remote MCP servers) rather than simply returning data. This pattern can be used to pivot the agent into fetching and executing instructions or code from an attacker-controlled location, and it also implies connecting to arbitrary 'remote MCP' servers discovered via the hop chain, which is a much broader and riskier capability than the described 'find a tool gateway' function suggests.
mediumpeople-search-index
Facilitates locating people-search/doxxing services
This tool's stated purpose is to help find a 'living people-search index' service and provide API/CLI/remote MCP access to it. Directing an agent toward services that aggregate personal information on named living individuals raises privacy and potential harassment/doxxing concerns, especially since it also offers 'remote MCP hops' that could connect the agent to an unvetted third-party data broker without the user's awareness.
mediumagent-tool-index
Pay-per-call gateway could incur costs or unwanted external calls without user awareness
The tool advertises finding a 'pay-per-call tool gateway,' meaning following its guidance could lead the agent to invoke metered/paid services on the user's behalf. Combined with the instruction to 'follow' redirects and hops automatically, this could result in financial or trust-boundary consequences the user did not explicitly authorize.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
lowmjd-n
Overly broad, function-irrelevant input schema shared across unrelated tools
Every tool in this set (mjd-n, utc-time, timezone, validate-json, etc.) exposes an identical wide input schema with fields like path, host, query, url, feed, ref, city regardless of the tool's actual single-purpose function (e.g., a 'Modified Julian day' or 'UTC time' tool accepts a filesystem path, a search query, and an RSS feed URL). This mismatch between stated narrow purpose and broad accepted parameters is unusual and could allow parameters intended for one tool to be silently accepted and processed by an unrelated tool, or obscure what data a given call actually transmits/logs despite claims that inputs are 'discarded.'
Embed this badge

Show your MCP server’s security grade

MCP security grade F

Paste this into your README:

[![MCP security](https://gateturbo.com/badge/scan/09d4b037-717b-42ff-a20d-05259c288026)](https://gateturbo.com/report/09d4b037-717b-42ff-a20d-05259c288026)

Scanned 9/15/2026 · This is a point-in-time snapshot of the server’s public tools. Re-scan.

Connect this server safely with gate.

Continuous re-scans, drift alerts, per-tool allow/ask/block, and a log of every call.

Monitor it — free