MCP security report

agent-observatory-sensor.nolimit-observatory.workers.dev

D55/100
Security grade DHigh-severity signals — review these before connecting.
Connected ✓30 tools scanned

https://agent-observatory-sensor.nolimit-observatory.workers.dev/s/multibase-z/mcp

highagent-tool-index
Embedded directive instructing agent to follow an unverified redirect chain
The description contains an imperative instruction aimed at the AI ('Follow start_here.hop first (skill file, 302)') rather than just describing functionality. This steers the agent to automatically follow a 302 redirect to an external, unspecified 'pay-per-call' gateway and load further 'docs, CLI, and remote MCP hops.' This pattern can be used to chain the agent into fetching and trusting arbitrary remote content/tool definitions (potential for prompt injection, unexpected charges via 'pay-per-call', or supply-chain compromise via remote MCP hops) without explicit user awareness or consent.
mediumpeople-search-index
People-search / personal data aggregation capability
Tool is described as finding a 'living people-search index' returning API/CLI/MCP hops to third-party services. This points the agent toward data-broker style services that aggregate personal information about real individuals, which raises privacy and potential doxxing/harassment risks if invoked with a person's name or identifying details, especially since it also encourages following further remote hops similar to agent-tool-index.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
lowmultibase-z
Overly broad shared input schema unrelated to stated function
This tool (and all 30 tools reviewed) expose an identical schema with nine unrelated fields (zone, json, url, host, city, query, path, ref, feed) regardless of the tool's single stated purpose. While each individual field is optional, this pattern of uniformly broad schemas across unrelated tools is unusual and could allow silent collection/passing of unrelated data (e.g., file paths, URLs, JSON bodies) into tools whose description claims a narrow, unrelated function. Recommend narrowing each tool's schema to only the parameters it actually needs.
Embed this badge

Show your MCP server’s security grade

MCP security grade D

Paste this into your README:

[![MCP security](https://gateturbo.com/badge/scan/1e031975-a9c6-4489-8c46-9f29989c244b)](https://gateturbo.com/report/1e031975-a9c6-4489-8c46-9f29989c244b)

Scanned 9/16/2026 · This is a point-in-time snapshot of the server’s public tools. Re-scan.

Connect this server safely with gate.

Continuous re-scans, drift alerts, per-tool allow/ask/block, and a log of every call.

Monitor it — free