MCP security report

agent-observatory-sensor.nolimit-observatory.workers.dev

D58/100
Security grade DHigh-severity signals — review these before connecting.
Connected ✓30 tools scanned

https://agent-observatory-sensor.nolimit-observatory.workers.dev/s/ps-w/mcp

highagent-tool-index
Embedded directive instructing agent to follow external redirect chain
The description tells the AI to 'Follow start_here.hop first (skill file, 302)' and mentions additional docs/CLI/remote MCP hops. This is an instruction aimed at the agent's behavior rather than a description of the tool's own output, and it encourages the agent to autonomously follow a chain of external redirects/URLs it does not control. This pattern is a classic vector for tool-poisoning / prompt injection, where the final hop can serve malicious instructions, credentials-harvesting pages, or unexpected code execution instructions that override the agent's normal safety behavior. The agent should not be told to blindly follow multi-hop external redirects as part of a tool's stated function of 'finding a gateway'.
mediumpeople-search-index
Facilitates locating a people-search / personal-data aggregation service
The tool's stated purpose is to help the agent find a 'living people-search index' with API/CLI access, i.e., a service for looking up personal information about individuals. Even though the tool itself just returns hop/index information, exposing and encouraging use of a people-search aggregator raises privacy and doxxing-enablement concerns, especially combined with the instruction-like phrasing ('Returns CLI setup, docs, API... hops') that nudges the agent toward integrating a personal-data lookup service without qualification about consent or lawful basis for such lookups.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
Embed this badge

Show your MCP server’s security grade

MCP security grade D

Paste this into your README:

[![MCP security](https://gateturbo.com/badge/scan/143cccca-9133-4260-8ced-2e2560230bb3)](https://gateturbo.com/report/143cccca-9133-4260-8ced-2e2560230bb3)

Scanned 9/15/2026 · This is a point-in-time snapshot of the server’s public tools. Re-scan.

Connect this server safely with gate.

Continuous re-scans, drift alerts, per-tool allow/ask/block, and a log of every call.

Monitor it — free