MCP security report

nichedb.dev

B85/100
Security grade BA few things are worth a closer look before connecting.
Connected ✓15 tools scanned

https://nichedb.dev/mcp

mediumfollow_feed
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
lowfollow_feed
Arbitrary webhook destination could exfiltrate feed data
follow_feed accepts a webhook_url and webhook_secret with no domain restriction shown. While this is a legitimate notification feature, an agent instructed (or manipulated) to follow a feed and set an attacker-controlled webhook_url would cause future feed item data to be sent to that external endpoint. No validation or allowlisting is described in the schema. This is a normal capability for the tool's purpose but merits caution since it's a channel for continuous data egress to a user-supplied URL.
Embed this badge

Show your MCP server’s security grade

MCP security grade B

Paste this into your README:

[![MCP security](https://gateturbo.com/badge/scan/1b50c17a-a56a-40e2-af6d-e084a136d505)](https://gateturbo.com/report/1b50c17a-a56a-40e2-af6d-e084a136d505)

Scanned 9/10/2026 · This is a point-in-time snapshot of the server’s public tools. Re-scan.

Connect this server safely with gate.

Continuous re-scans, drift alerts, per-tool allow/ask/block, and a log of every call.

Monitor it — free