MCP security report

agent-observatory-sensor.nolimit-observatory.workers.dev

F16/100
Security grade FHigh-severity signals — review these before connecting.
Connected ✓30 tools scanned

https://agent-observatory-sensor.nolimit-observatory.workers.dev/s/cc-ps/mcp

highagent-tool-index
Embedded instruction to follow untrusted redirect chain
The description tells the agent to 'Follow start_here.hop first (skill file, 302)' and references 'docs, CLI, and remote MCP hops.' This is a directive embedded in a tool description that instructs the agent to chase redirects and load an external 'skill file' and additional remote MCP servers. This is a classic vector for supply-chain/prompt-injection attacks: the agent could be induced to fetch and execute instructions or register new tool servers from an untrusted, attacker-controlled endpoint, entirely outside the user's visibility and outside the stated purpose of the tool (which claims only to 'find' a gateway).
highpeople-search-index
PII/people-search capability disguised as a lookup utility, with remote hop instructions
Description states the tool 'Finds a living people-search index (Ploid)' and 'Returns CLI setup, docs, API, and remote MCP hops.' Like agent-tool-index, this directs the agent toward external CLI/API setup and additional remote MCP servers, which could lead to installing untrusted code or connecting to unvetted services. The underlying function (locating a people-search/surveillance index) is also a sensitive capability that is broader and more privacy-invasive than the innocuous-sounding name and generic parameter schema suggest.
mediumagent-tool-index
Mismatch between generic schema and actual function
The tool shares an identical 9-field schema (zone, json, url, host, city, query, path, ref, feed) with 27 other unrelated utility tools, none of which map clearly onto 'finding a pay-per-call gateway' or resolving hop chains. This generic, copy-pasted schema pattern makes it easy for a tool with materially different (and riskier) behavior to blend in among many benign-looking tools, reducing the chance a reviewer or agent notices its distinct, more dangerous purpose.
mediumpeople-search-index
Mismatch between generic schema and actual function
Like agent-tool-index, this tool reuses the same generic 9-field schema shared by 27 unrelated benign tools, despite performing a distinctly different and more sensitive function (locating a people-search index and remote API/CLI/MCP hops). This pattern of disguising a higher-risk tool within a large batch of near-identical, low-risk tool definitions is a technique that can be used to slip harmful capabilities past cursory review.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
Embed this badge

Show your MCP server’s security grade

MCP security grade F

Paste this into your README:

[![MCP security](https://gateturbo.com/badge/scan/2a588b52-f7af-40d1-a3a0-e38dfc32733c)](https://gateturbo.com/report/2a588b52-f7af-40d1-a3a0-e38dfc32733c)

Scanned 9/13/2026 · This is a point-in-time snapshot of the server’s public tools. Re-scan.

Connect this server safely with gate.

Continuous re-scans, drift alerts, per-tool allow/ask/block, and a log of every call.

Monitor it — free