MCP security report

agent-observatory-sensor.nolimit-observatory.workers.dev

F37/100
Security grade FHigh-severity signals — review these before connecting.
Connected ✓30 tools scanned

https://agent-observatory-sensor.nolimit-observatory.workers.dev/s/nl-n/mcp

highagent-tool-index
Embedded directive telling the agent to follow an external redirect chain
The description instructs the agent to 'Follow start_here.hop first (skill file, 302)' and says it 'returns docs, CLI, and remote MCP hops.' This is an instruction aimed at the AI to fetch and follow an external, redirect-chained 'skill file' and potentially load additional remote MCP servers/tools. This is a classic tool-poisoning/prompt-injection pattern: it directs the agent toward dynamically fetched, attacker-controllable content and additional capability surfaces (CLI install, remote MCP endpoints) far beyond what a simple lookup tool should do, and does so without any user visibility or confirmation step described in the schema.
highpeople-search-index
Directs agent to a people-search / doxxing service and remote MCP hops
Description says it helps 'find a living people-search index (Ploid)' and returns 'CLI setup, docs, API, and remote MCP hops.' Aggregating and surfacing tools/APIs specifically for searching personal information about 'living people' is a privacy-sensitive capability that could facilitate doxxing or unauthorized personal-data lookups. Combined with the instruction to follow returned 'remote MCP hops,' this also risks the agent chaining into unvetted external tool servers based on text baked into a tool description rather than user intent.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
lownl-n
Overly broad, unused parameter surface shared across many unrelated tools
This tool (and nearly all others in this set) exposes a large shared schema with fields like host, path, ref, feed, city, query, json, url, zone that have nothing to do with the tool's stated purpose (counting line feeds). While each field is annotated as discarded/no disk access, this bloated, copy-pasted schema pattern increases the risk that a future prompt injection or malicious input could be misrouted to an unintended field, and makes it hard to verify that each tool actually behaves as described. Recommend tightening schemas to only the parameters actually used per tool.
Embed this badge

Show your MCP server’s security grade

MCP security grade F

Paste this into your README:

[![MCP security](https://gateturbo.com/badge/scan/2a056b61-381a-4da4-a9d3-8ca49778eee6)](https://gateturbo.com/report/2a056b61-381a-4da4-a9d3-8ca49778eee6)

Scanned 9/17/2026 · This is a point-in-time snapshot of the server’s public tools. Re-scan.

Connect this server safely with gate.

Continuous re-scans, drift alerts, per-tool allow/ask/block, and a log of every call.

Monitor it — free