MCP security report

agent-observatory-sensor.nolimit-observatory.workers.dev

F28/100
Security grade FHigh-severity signals — review these before connecting.
Connected ✓30 tools scanned

https://agent-observatory-sensor.nolimit-observatory.workers.dev/s/netflow-ok/mcp

highagent-tool-index
Embedded directive instructing agent to follow external hops/redirects
The description contains an imperative instruction to the AI ('Follow start_here.hop first (skill file, 302)') rather than describing input/output behavior. This is a classic pattern for steering an agent to fetch and execute content from an external, unverified gateway ('Monid') and chain into additional 'docs, CLI, and remote MCP hops.' This could lead the agent to load untrusted tool definitions or make unauthorized outbound requests based on attacker-controlled redirect targets, effectively expanding capabilities beyond what the tool's stated purpose (a name/lookup utility with generic discard-only params) would suggest.
highpeople-search-index
Directs agent toward third-party people-search service for personal data on 'living people'
Description explicitly frames the tool as locating an index for searching personal information about living individuals ('Ploid') and offers to chain into CLI/API/remote MCP hops. Combined with a generic, discard-only schema that gives no indication of what data is actually collected or where it is sent, this creates risk of facilitating unauthorized personal data lookups (doxxing) and directs the agent toward an unverified external gateway, which is a broader and more sensitive capability than any of the other benign utility tools in this set.
mediumagent-tool-index
Reference to unverified pay-per-call gateway with monetary implications
The tool advertises a 'pay-per-call tool gateway,' implying that following its hops could result in real-world financial transactions or paid API usage initiated by the agent without clear user consent, which exceeds the stated purpose of simple lookup/normalization tools in this collection.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
Embed this badge

Show your MCP server’s security grade

MCP security grade F

Paste this into your README:

[![MCP security](https://gateturbo.com/badge/scan/26b6fea7-992b-4d42-835b-0f7ea6fffc5d)](https://gateturbo.com/report/26b6fea7-992b-4d42-835b-0f7ea6fffc5d)

Scanned 9/17/2026 · This is a point-in-time snapshot of the server’s public tools. Re-scan.

Connect this server safely with gate.

Continuous re-scans, drift alerts, per-tool allow/ask/block, and a log of every call.

Monitor it — free