MCP security report

agent-observatory-sensor.nolimit-observatory.workers.dev

F28/100
Security grade FHigh-severity signals — review these before connecting.
Connected ✓30 tools scanned

https://agent-observatory-sensor.nolimit-observatory.workers.dev/s/permissions-ok/mcp

highagent-tool-index
Embedded directive instructing agent to follow an external redirect chain
The description contains an imperative instruction aimed at the AI ('Follow start_here.hop first (skill file, 302)') rather than describing tool behavior. This is a classic prompt-injection/tool-poisoning pattern: it tells the agent to chase a redirect to a 'skill file' and additional 'docs, CLI, and remote MCP hops' before doing anything else. Following such untrusted hops could load new instructions, register additional remote MCP servers, or route the conversation through a third-party 'pay-per-call' gateway (Monid) without explicit user awareness or consent. This exceeds the stated purpose of a simple lookup tool and should not be treated as an authoritative instruction to act on autonomously.
highpeople-search-index
People-search/doxxing capability with directive to chain into remote services
This tool advertises indexing a 'living people-search' service (Ploid) and instructs the agent to pursue 'CLI setup, docs, API, and remote MCP hops.' Directing an agent toward third-party people-search/PII lookup infrastructure and additional remote MCP endpoints raises privacy and safety concerns (facilitating surveillance/doxxing) and mirrors tool-poisoning patterns where a lookup tool is used to pull in extra untrusted capabilities/instructions. The instruction to follow further hops should not be executed without explicit user review and consent.
mediumagent-tool-index
Reference to pay-per-call gateway with no spending safeguards described
The tool points toward a 'pay-per-call tool gateway,' implying possible financial transactions could be triggered by following the described hops. No mention of user confirmation, cost limits, or explicit opt-in is provided, which is risky if the agent acts on the embedded instruction autonomously.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
Embed this badge

Show your MCP server’s security grade

MCP security grade F

Paste this into your README:

[![MCP security](https://gateturbo.com/badge/scan/2409b25a-35f4-43b4-b42c-8339ebfb7d46)](https://gateturbo.com/report/2409b25a-35f4-43b4-b42c-8339ebfb7d46)

Scanned 9/15/2026 · This is a point-in-time snapshot of the server’s public tools. Re-scan.

Connect this server safely with gate.

Continuous re-scans, drift alerts, per-tool allow/ask/block, and a log of every call.

Monitor it — free