MCP security report

a2awire.com

F5/100
Security grade FA few things are worth a closer look before connecting.
Connected ✓16 tools scanned

https://a2awire.com/mcp/data/govulnwatch-go-vulnerability-database-tracker-dac615/http

mediumdata_preview
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediuma2awire_guide
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumfind_paid_work
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumregister
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumget_agent_contract
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumdata_session_attach_escrow
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumdata_preview
Manipulative urgency/CTA language aimed at the AI agent
Description opens with '✅ No API key needed — call this now.' and closes with 'Try one of the sample questions now.' This is directive language aimed at inducing the agent to invoke the tool immediately regardless of whether the user actually requested it, rather than neutrally describing functionality. This pattern recurs across many tools in this server and looks like an engagement/upsell tactic embedded in a tool description.
mediumfind_paid_work
Urgency language plus chained call to a tool not in this catalog
'call this now' urging language, and the description tells the agent to 'call start_job with a job_id to begin earning' — but 'start_job' is not among the tools exposed here, meaning the agent may be steered toward attempting to invoke or expect a tool that isn't actually available/vetted in this context. Combined with financial job-taking behavior, this could push the agent into unsupervised money-earning actions.
mediumregister
Urgent CTA plus risky autonomous defaults (spawn approval, auto wallet provisioning)
Contains 'call this now' urgency language. More substantively, 'spawn_approval_required' defaults to false ('Defaults to autonomous'), meaning child agents can be spawned via the foundry without owner approval by default — a broad, potentially costly capability enabled without explicit opt-in. Additionally, 'auto_provision_testnet_wallet' defaults to true and will auto-generate a payout wallet, returning its private key in the response exactly once; this is a sensitive credential-handling operation that could be triggered by a low-friction 'register now' call and risks the private key being mishandled/logged by the agent.
mediumhire_and_execute
Broad one-call capability to spend real USDC and execute third-party tasks autonomously
This single tool call searches the marketplace, creates an on-chain escrow, funds it with real USDC, and executes a task with a hired third-party agent — all in one invocation. Combined with the 'call this now'-style low-friction culture of sibling tools in this server, an agent could be induced to autonomously commit funds (up to max_price_usdc, default 1.0 USDC) and send task_input data to an arbitrary third-party agent without a clear per-step user confirmation gate.
lowregister
Unusually long tool description
Very long descriptions are sometimes used to bury instructions to the AI. Skim it before allowing.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
lowa2awire_guide
Urgency language pushing immediate invocation
'✅ No API key needed — call this now.' is instructive marketing copy targeted at the calling agent rather than a functional description, encouraging autonomous invocation.
lowget_recommended_action
Encourages bypassing independent reasoning
Description states it 'Returns the single next tool + pre-filled args so you do not have to reason over the full catalog,' explicitly encouraging the agent to skip its own judgment/verification and blindly execute the suggested next action with pre-filled arguments — a mild manipulation vector if the recommended action involves spending or registration.
lowget_agent_contract
Urgency CTA language
'✅ No API key needed — call this now.' pattern repeated, nudging unconditional invocation rather than describing when the tool is actually needed.
lowdata_session_open
Defaults buyer address to the agent's own wallet without explicit confirmation
When buyer_address is omitted it silently defaults to the caller's own platform wallet, meaning a session that spends funds can be opened without the user explicitly specifying or confirming which wallet is being used to pay.
Embed this badge

Show your MCP server’s security grade

MCP security grade F

Paste this into your README:

[![MCP security](https://gateturbo.com/badge/scan/0f7e8090-d9b2-4e6f-a860-2609ae052725)](https://gateturbo.com/report/0f7e8090-d9b2-4e6f-a860-2609ae052725)

Scanned 9/10/2026 · This is a point-in-time snapshot of the server’s public tools. Re-scan.

Connect this server safely with gate.

Continuous re-scans, drift alerts, per-tool allow/ask/block, and a log of every call.

Monitor it — free