MCP security report

agentwares-agentcheck.vercel.app

F5/100
Security grade FA few things are worth a closer look before connecting.
Connected ✓8 tools scanned

https://agentwares-agentcheck.vercel.app/api/mcp

mediumagentcheck_get_status
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumagentcheck_get_pricing
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumagentcheck_create_target
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumagentcheck_add_check
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumagentcheck_run_now
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumagentcheck_record
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumagentcheck_promote_trace
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumagentcheck_list_incidents
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
lowagentcheck_create_target
Unusually long tool description
Very long descriptions are sometimes used to bury instructions to the AI. Skim it before allowing.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
lowagentcheck_create_target
Accepts credentials/secrets for target authentication
The 'auth' field allows passing bearer tokens or arbitrary header values to be stored server-side and used against monitored endpoints. This is a reasonable feature for a monitoring tool but does mean the agent may be prompted to supply real API tokens/credentials into this tool's storage; ensure the agent only does so with explicit user awareness/consent, since these secrets are sent to and retained by a third-party service (agentwares-agentcheck.vercel.app).item
lowagentcheck_create_target
packageSpec allows arbitrary local command execution spec (npx/uvx)
The 'packageSpec' field lets the target run 'npx @org/server' or 'uvx server' style package specs on the mcpcheck runner. While scoped to a monitoring runner rather than the user's own machine, this is a broad capability (arbitrary package execution) worth flagging so the agent doesn't pass untrusted or malicious package specs without user confirmation.
lowagentcheck_record
Sends production interaction data (prompts, answers, tool calls) to external service
This tool is designed to capture full production traces of the agent's interactions, including user prompts and final answers, and send them to the agentcheck external service. This is disclosed and purpose-built for the tool's monitoring function, but agents/users should be aware sensitive user data could be transmitted externally when this is invoked automatically 'from a proxy in front of it after each task.'
Embed this badge

Show your MCP server’s security grade

MCP security grade F

Paste this into your README:

[![MCP security](https://gateturbo.com/badge/scan/304b0cf0-afc3-4f03-8945-715a90e1a127)](https://gateturbo.com/report/304b0cf0-afc3-4f03-8945-715a90e1a127)

Scanned 9/9/2026 · This is a point-in-time snapshot of the server’s public tools. Re-scan.

Connect this server safely with gate.

Continuous re-scans, drift alerts, per-tool allow/ask/block, and a log of every call.

Monitor it — free