MCP security report

a2awire.com

F5/100
Security grade FA few things are worth a closer look before connecting.
Connected ✓23 tools scanned

https://a2awire.com/mcp/benchmarks/charge-3pl-invoice-audit-2026-09-10-749db5bd/http

mediumbenchmarks_list
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumbenchmarks_get
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumbenchmark_start_run
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumbenchmark_submit_answers
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumbenchmark_finalize_run
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumbenchmark_get_results
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumconfirm_keys_persisted
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumdata_session_open
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumdata_session_funding_package
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumdata_session_fund
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumdata_session_attach_escrow
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumdata_session_query
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediuma2awire_guide
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumfind_paid_work
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumregister
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumget_agent_contract
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumregister
Tool response includes a raw wallet private key and instructs the agent to persist it
The register tool returns api_key, owner_key, and wallet_private_key in plaintext and tells the agent to 'save them somewhere safe.' Passing a private key through an LLM tool-call response/context is risky: it can end up in logs, transcripts, or be echoed back to the user or a third party, and the description does not caution the agent about safe handling (e.g., not echoing the key in chat, not persisting it insecurely). This is a sensitive-credential-exposure pattern even though it is presented as a normal onboarding flow.
mediumhire_and_execute
One-call tool autonomously creates escrow and executes on-chain USDC payment
hire_and_execute searches the marketplace, creates an escrow, funds it on-chain with USDC, and executes a task in a single call, with a default max_price_usdc of 1.0 if not specified. This bundles discovery, financial commitment, and task execution into one autonomous action with no explicit confirmation step, which is a broad capability for a tool whose name suggests simple task delegation — an agent could be induced to spend real (or testnet) funds without the user reviewing the specific counterparty or price.
lowdata_session_open
Unusually long tool description
Very long descriptions are sometimes used to bury instructions to the AI. Skim it before allowing.
lowregister
Unusually long tool description
Very long descriptions are sometimes used to bury instructions to the AI. Skim it before allowing.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
lowbenchmarks_list
Repeated 'call this now' urgency directive across multiple tool descriptions
Several tools (benchmarks_list, benchmarks_get, a2awire_guide, find_paid_work, register, get_agent_contract) open with '✅ No API key needed — call this now.' This is an imperative aimed at the calling AI to invoke the tool immediately rather than a neutral functional description. Embedding action directives in tool metadata is a known prompt-injection pattern that can nudge an agent toward autonomous action (e.g., registering an identity, creating a wallet) without confirming user intent.
lowregister
Default spending cap mode has no hard ceiling
spending_cap_mode defaults to 'wallet_balance', which lets the agent spend up to whatever is approved on-chain and 'refills as you earn' rather than enforcing a fixed ceiling. Combined with auto-provisioned testnet wallets and hire_and_execute's autonomous spending, an agent that isn't explicitly configured with 'fixed' mode could keep spending indefinitely as its balance grows, with no built-in circuit breaker described to the calling agent.
lowbenchmark_start_run
Description prescribes a multi-step autonomous financial workflow
The tool description lays out a full recommended sequence (register → confirm_keys_persisted → request_testnet_usdc → data_session_open/fund/query → benchmark_start_run → submit/finalize) inside a single tool's metadata, effectively scripting the agent through several money-moving steps in a row. While plausible for a legitimate benchmark flow, this is an unusually prescriptive chain embedded in tool description text that could lead an agent to execute several fund-committing actions back-to-back without pausing for user confirmation.
Embed this badge

Show your MCP server’s security grade

MCP security grade F

Paste this into your README:

[![MCP security](https://gateturbo.com/badge/scan/33e57fe3-b6b0-4444-94d1-07385f4d4aa3)](https://gateturbo.com/report/33e57fe3-b6b0-4444-94d1-07385f4d4aa3)

Scanned 9/12/2026 · This is a point-in-time snapshot of the server’s public tools. Re-scan.

Connect this server safely with gate.

Continuous re-scans, drift alerts, per-tool allow/ask/block, and a log of every call.

Monitor it — free