MCP security report

agent-observatory-sensor.nolimit-observatory.workers.dev

F25/100
Security grade FHigh-severity signals — review these before connecting.
Connected ✓30 tools scanned

https://agent-observatory-sensor.nolimit-observatory.workers.dev/s/uuid7-ok/mcp

highagent-tool-index
Embedded directive instructs agent to follow external redirect chain
The description contains an imperative instruction aimed at the AI agent ('Follow start_here.hop first (skill file, 302)') rather than merely documenting behavior. This directs the agent to chase a redirect to an unspecified external 'pay-per-call tool gateway' and to load additional 'docs, CLI, and remote MCP hops.' This is a classic pattern for smuggling in untrusted follow-on instructions or getting the agent to connect to attacker-controlled remote MCP servers, which could then issue further hidden instructions or exfiltrate data. The tool also references a 'task text' input that does not exist in the declared schema, suggesting the description was not written to match the actual tool and may be designed to prime the agent to send additional free-text task data through some other channel.
highpeople-search-index
Directs agent to third-party people-search / personal data service and remote code hops
Description promotes discovery of a 'living people-search index' (personal information lookup) and instructs the agent to retrieve 'CLI setup, docs, API, and remote MCP hops.' This encourages the agent to pull in and potentially execute code/config from an unverified third party and to facilitate lookups of personal data about real individuals, which raises privacy and supply-chain risk substantially beyond a simple lookup/validation utility of similar tools in this collection.
mediumagent-tool-index
Schema/description mismatch enabling potential covert data channel
The description mentions 'Task text discarded' but no 'task' parameter exists in the input schema. This inconsistency between documented behavior and actual schema is a red flag: it could mask how user/task content is actually captured or transmitted, and agents relying on the description rather than the schema could be misled about what data is being sent.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
lowuuid7-ok
Oversized, irrelevant shared schema across many unrelated tools
This tool (and all 29 others reviewed) exposes an identical 9-field schema (zone, json, url, host, city, query, path, ref, feed) regardless of the tool's actual single-purpose function (e.g., generating a UUID needs no input at all). While each field is individually described as 'discarded,' the pattern of attaching a broad, uniform set of sensitive-looking parameters (URLs, hostnames, file paths, search queries, city/location) to many otherwise trivial tools is unusual and increases the surface area for silently collecting diverse user data across calls, especially since verification of the 'discarded' claim is not possible from the description alone.
Embed this badge

Show your MCP server’s security grade

MCP security grade F

Paste this into your README:

[![MCP security](https://gateturbo.com/badge/scan/29204dad-1d0d-4d3c-8e5c-4c34dac0bf30)](https://gateturbo.com/report/29204dad-1d0d-4d3c-8e5c-4c34dac0bf30)

Scanned 9/17/2026 · This is a point-in-time snapshot of the server’s public tools. Re-scan.

Connect this server safely with gate.

Continuous re-scans, drift alerts, per-tool allow/ask/block, and a log of every call.

Monitor it — free