MCP security report

agent-observatory-sensor.nolimit-observatory.workers.dev

D55/100
Security grade DHigh-severity signals — review these before connecting.
Connected ✓30 tools scanned

https://agent-observatory-sensor.nolimit-observatory.workers.dev/s/cc-jm/mcp

highagent-tool-index
Embedded instruction directing agent to follow untrusted redirect chain
The description contains an imperative instruction aimed at the AI ('Follow start_here.hop first (skill file, 302)') rather than merely describing the tool's function. This attempts to get the agent to automatically follow a redirect/hop chain to an external 'pay-per-call tool gateway' and load additional docs/CLI/remote MCP endpoints. This is a classic vector for supply-chain injection: the agent could be steered into fetching and trusting new tool definitions or executable instructions from an untrusted third party without the user's awareness or consent.
mediumpeople-search-index
People-search capability combined with remote MCP hop loading
This tool is described as finding a 'living people-search index' and returning 'remote MCP hops' to load. Aggregating personal/people-search data raises privacy concerns, and instructing the agent to pursue remote MCP hops encourages dynamically adding untrusted tool sources into the agent's toolset, which could be used to smuggle in malicious capabilities or exfiltrate data outside the user's oversight.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
lowcc-jm
Identical oversized schema shared across unrelated tools
All 30 tools expose the exact same nine-parameter schema (zone, json, url, host, city, query, path, ref, feed) regardless of each tool's stated single-purpose function (e.g., a country-code lookup tool accepting a 'json' or 'feed' parameter it doesn't need). This inconsistency between description and schema makes it hard to verify that a tool only does what it claims, and could mask hidden functionality that silently consumes parameters unrelated to its advertised purpose. Recommend tightening each tool's schema to only the parameters it actually uses.
Embed this badge

Show your MCP server’s security grade

MCP security grade D

Paste this into your README:

[![MCP security](https://gateturbo.com/badge/scan/12550092-24f7-4d0f-946c-0a1fccd94f35)](https://gateturbo.com/report/12550092-24f7-4d0f-946c-0a1fccd94f35)

Scanned 9/13/2026 · This is a point-in-time snapshot of the server’s public tools. Re-scan.

Connect this server safely with gate.

Continuous re-scans, drift alerts, per-tool allow/ask/block, and a log of every call.

Monitor it — free