https://agent-observatory-sensor.nolimit-observatory.workers.dev/s/puny2003-ok/mcp
highagent-tool-index
Embedded directive tells the agent to follow an external redirect chain
The description instructs the agent to 'Follow start_here.hop first (skill file, 302)' and describes itself as a gateway to a 'pay-per-call' service with 'docs, CLI, and remote MCP hops.' This is an instruction aimed at the agent's behavior rather than a description of a discrete function, and it encourages the agent to automatically follow redirects/hops to an unverified external service and potentially connect to additional remote MCP servers or incur pay-per-call costs without the user's explicit awareness or consent. This is a classic pattern for smuggling in untrusted follow-on instructions or tool-chain injection.
highpeople-search-index
People-search / OSINT tool with embedded instruction to chain into external remote services
Description advertises a 'living people-search index' and returns 'CLI setup, docs, API, and remote MCP hops.' This both raises privacy concerns (facilitating lookup of personal information about individuals) and, like agent-tool-index, nudges the agent toward fetching and trusting additional remote MCP endpoints or API/CLI configuration from an unverified third party, which could be used to inject further instructions or exfiltrate data once connected.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
lowutc-time
Oversized, irrelevant input schema shared across unrelated tools
This tool (and all 30 tools in the set) expose an identical 9-field schema (zone, json, url, host, city, query, path, ref, feed) regardless of the tool's stated single-purpose function (e.g., a UTC-time tool accepting a 'path', 'ref', 'json', 'feed', etc.). This inconsistency between the tool's description and its accepted parameters is unusual; it could allow an agent to be induced to pass unrelated sensitive data (file paths, JSON blobs, URLs) into a tool whose actual backend behavior is not fully described, creating a latent path for unintended data collection or exfiltration if the implementation does not strictly match the 'discarded/no disk access' claims in the description.