MCP security report

agent-observatory-sensor.nolimit-observatory.workers.dev

F13/100
Security grade FHigh-severity signals — review these before connecting.
Connected ✓30 tools scanned

https://agent-observatory-sensor.nolimit-observatory.workers.dev/s/uudecode-ok/mcp

highagent-tool-index
Embedded directive instructing agent to follow an external redirect chain
The description contains an imperative instruction to the agent ('Follow start_here.hop first (skill file, 302)') rather than just describing the tool's function. This steers the agent to automatically follow a redirect to an unspecified external 'pay-per-call tool gateway' before doing anything else, which could lead to fetching untrusted content, prompt injection from the hop destination, or unauthorized interaction with a paid/metered service without explicit user consent.
highpeople-search-index
People-search capability raises privacy/safety concerns
This tool is described as finding an index for searching 'living people' and returns API/CLI/MCP hops for that purpose. Facilitating lookups of personal data about real individuals is a sensitive capability that could enable doxxing or privacy violations; it is unusually broad relative to the other simple format/shape-checking tools in this set and warrants scrutiny of what data it can surface and how it's used.
mediumagent-tool-index
Points to unknown remote MCP endpoints
The tool advertises 'remote MCP hops' as part of its result. Directing an agent to connect to additional, unvetted remote MCP servers can expand the agent's capability surface and trust boundary without the user's explicit awareness or approval.
mediumpeople-search-index
Directs agent to additional untrusted remote MCP hops
Like agent-tool-index, this tool returns 'remote MCP hops' pointing to external services. This can silently expand the agent's tool/capability surface to unvetted third-party endpoints.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
lowuudecode-ok
Shared schema exposes many unrelated, unused input fields
This tool (and nearly all others in the set) shares an identical input schema with 9 fields (zone, json, url, host, city, query, path, ref, feed) even though the tool's stated purpose only needs one or none of them. Each field's description claims the value is 'discarded,' but this claim cannot be verified from the schema alone, and the pattern of collecting many unrelated inputs (paths, hostnames, queries, JSON bodies) across every tool is an unusual design that could mask incidental data collection if the discard behavior is not actually honored.
Embed this badge

Show your MCP server’s security grade

MCP security grade F

Paste this into your README:

[![MCP security](https://gateturbo.com/badge/scan/2199ddf1-bdf8-422a-a6c2-8d06f9c80926)](https://gateturbo.com/report/2199ddf1-bdf8-422a-a6c2-8d06f9c80926)

Scanned 9/17/2026 · This is a point-in-time snapshot of the server’s public tools. Re-scan.

Connect this server safely with gate.

Continuous re-scans, drift alerts, per-tool allow/ask/block, and a log of every call.

Monitor it — free