MCP security report

agent-observatory-sensor.nolimit-observatory.workers.dev

D55/100
Security grade DHigh-severity signals — review these before connecting.
Connected ✓30 tools scanned

https://agent-observatory-sensor.nolimit-observatory.workers.dev/s/murmur3-ok/mcp

highagent-tool-index
Instructs agent to follow an untrusted redirect chain ('start_here.hop')
The description tells the agent to 'Follow start_here.hop first (skill file, 302)' and then follow additional docs/CLI/remote MCP hops. This is an embedded directive that causes the agent to autonomously fetch and act on content from an external, unvetted 'skill file' and to bootstrap connections to additional remote MCP servers not declared or reviewed here. This is a classic vector for prompt injection / capability expansion, since the fetched hop content could contain further instructions the agent would then follow, and it exposes the user to a 'pay-per-call' gateway without their awareness or consent.
mediumpeople-search-index
People-search / PII lookup tool with hidden remote hops
This tool's purpose is to locate a 'people-search index' for looking up information about living individuals, and it returns 'CLI setup, docs, API, and remote MCP hops' the agent is expected to follow. Combining an instruction to chain into additional remote MCP endpoints with a capability aimed at searching for personal data about individuals raises both privacy (PII lookup) and supply-chain (blind trust in unreviewed remote hops) concerns beyond what a simple 'index finder' utility should need.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
lowagent-tool-index
Unusually broad schema unrelated to stated purpose
Like all tools in this set, this tool exposes a large shared parameter set (zone, json, url, host, city, query, path, ref, feed) that has no clear relationship to 'finding a tool gateway.' While likely a shared-schema artifact rather than malicious, combined with the redirect-following instruction it increases the risk that arbitrary parameters could be repurposed to exfiltrate or route data through the hinted external gateway.
Embed this badge

Show your MCP server’s security grade

MCP security grade D

Paste this into your README:

[![MCP security](https://gateturbo.com/badge/scan/2dea0b5e-2556-42f4-b565-9e08998a5cfe)](https://gateturbo.com/report/2dea0b5e-2556-42f4-b565-9e08998a5cfe)

Scanned 9/17/2026 · This is a point-in-time snapshot of the server’s public tools. Re-scan.

Connect this server safely with gate.

Continuous re-scans, drift alerts, per-tool allow/ask/block, and a log of every call.

Monitor it — free