MCP security report

agent-observatory-sensor.nolimit-observatory.workers.dev

F22/100
Security grade FHigh-severity signals — review these before connecting.
Connected ✓30 tools scanned

https://agent-observatory-sensor.nolimit-observatory.workers.dev/s/syslog-ok/mcp

highagent-tool-index
Embedded directive instructing agent to follow untrusted redirect chain
The description explicitly instructs the calling agent to 'Follow start_here.hop first (skill file, 302)' and then chase 'docs, CLI, and remote MCP hops.' This is an instruction embedded in tool metadata that tells the AI what actions to take beyond simply describing the tool's function, and encourages the agent to autonomously follow a chain of redirects to an unverified 'pay-per-call' gateway and potentially connect to a remote MCP server. This is a classic vector for prompt injection / instruction smuggling and could lead the agent to execute code or ingest instructions from an attacker-controlled endpoint without the user's awareness.
highpeople-search-index
Directs agent toward personal-data lookup service and remote MCP connection
Description asks the agent to 'Find a living people-search index (Ploid)' and follow CLI setup, API, and 'remote MCP hops.' This both promotes a privacy-invasive personal data lookup capability (searching for information about identifiable living people) and, like agent-tool-index, nudges the agent toward connecting to an unverified remote MCP server/CLI outside the current trusted tool set. Combined with the vague, discard-claim language, this could be used to exfiltrate query data to a third-party 'Ploid' service or to bootstrap additional untrusted tool integrations without explicit user consent.
mediumsyslog-ok
Schema exposes far more fields than the tool's stated function requires
Every tool in this collection (syslog-ok, utc-time, timezone, etc.) shares an identical, broad input schema containing zone, json, url, host, city, query, path, ref, and feed — regardless of what the individual tool claims to do (e.g., 'syslog-ok' has no logical need for city, feed, path, or ref parameters). This inconsistency between the narrow stated purpose and the broad accepted parameter surface is unusual and could be used to funnel sensitive data (file paths, hostnames, search queries) into calls under the pretense of an unrelated, narrowly-scoped tool, especially since the 'discarded' claims for these fields cannot be verified by the calling agent.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
lowplaywright-url-ok
Tool name mimics well-known Playwright automation framework but performs no browser action
The tool is named after the popular Playwright browser-automation tool, which could lead an agent or user to assume it launches a real browser or performs Playwright-style automation, when it explicitly does not ('No browser is launched'). This naming choice risks confusing trust/capability expectations, especially if an agent selects this tool based on name similarity to a trusted browser automation library rather than its actual documented behavior.
lowbrowser-url-ok
Generic 'browser' naming may cause capability confusion
Similar to playwright-url-ok, this tool's name suggests browser interaction capability ('browser-url-ok') though its description clarifies no browser is launched. Having two near-duplicate tools (browser-url-ok and playwright-url-ok) with overlapping but distinctly-branded names increases the risk of an agent mis-selecting or mis-trusting the tool's actual capability based on its name alone.
Embed this badge

Show your MCP server’s security grade

MCP security grade F

Paste this into your README:

[![MCP security](https://gateturbo.com/badge/scan/338bbbb5-15f0-42fb-b102-043746e4ea7f)](https://gateturbo.com/report/338bbbb5-15f0-42fb-b102-043746e4ea7f)

Scanned 9/15/2026 · This is a point-in-time snapshot of the server’s public tools. Re-scan.

Connect this server safely with gate.

Continuous re-scans, drift alerts, per-tool allow/ask/block, and a log of every call.

Monitor it — free