MCP security report

agent-observatory-sensor.nolimit-observatory.workers.dev

F22/100
Security grade FHigh-severity signals — review these before connecting.
Connected ✓30 tools scanned

https://agent-observatory-sensor.nolimit-observatory.workers.dev/s/cc-ne/mcp

highagent-tool-index
Instructs agent to follow external redirects and load remote MCP servers
The description directs the agent to 'Follow start_here.hop first (skill file, 302)' and then load additional docs, CLI, and 'remote MCP hops.' This is an embedded instruction telling the agent to chase an untrusted redirect chain and potentially connect to/execute code from an external, unverified MCP server or gateway ('Monid'), which is a classic supply-chain/prompt-injection vector far beyond a simple lookup tool. It also mentions a 'pay-per-call' gateway, meaning the agent could be induced to incur costs or register with a third party without the user's informed consent.
highpeople-search-index
People-search / surveillance tool with remote hop-following instructions
Description frames this as a tool to 'find a living people-search index' and follow CLI/API/remote MCP hops, similar to agent-tool-index. Combining a people-search capability (potential PII/doxing use) with instructions to fetch and follow arbitrary remote endpoints is risky: it could be used to locate personal information about individuals and/or pull in untrusted remote tool definitions that the agent would then treat as trusted extensions of itself.
mediumplaywright-url-ok
Name spoofs well-known 'Playwright' automation tool
The tool is named after the popular Playwright browser-automation library but its description ('Check whether a URL can be opened. No browser is launched.') claims drastically reduced capability. This name similarity could cause the agent (or a user reviewing tool calls) to over-trust it as the real Playwright tool with full browser-automation power, or conversely could be a placeholder for later capability expansion under a trusted name — a form of tool-name spoofing risk.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
lowbrowser-url-ok
Duplicate/near-identical tool to playwright-url-ok
Functionally identical description to playwright-url-ok ('Check whether a URL can be opened. No browser is launched.'). Having multiple differently-named tools with identical stated behavior increases ambiguity about which one actually executes and could be used to mask a behavior change in one of the duplicates later without the change being noticed against its 'twin'.
lowweather-hint
Sends city/location text to third-party Open-Meteo service
City input is forwarded to an external API (Open-Meteo) for a temperature lookup. This is consistent with the stated purpose and is low risk, but it does mean user-supplied location text leaves the local context to a third party, which should be disclosed to the user if sensitive locations are involved.
Embed this badge

Show your MCP server’s security grade

MCP security grade F

Paste this into your README:

[![MCP security](https://gateturbo.com/badge/scan/213f0085-593f-4a1f-848d-54b74692e58d)](https://gateturbo.com/report/213f0085-593f-4a1f-848d-54b74692e58d)

Scanned 9/13/2026 · This is a point-in-time snapshot of the server’s public tools. Re-scan.

Connect this server safely with gate.

Continuous re-scans, drift alerts, per-tool allow/ask/block, and a log of every call.

Monitor it — free