MCP security report

www.pathwren.workers.dev

F16/100
Security grade FHigh-severity signals — review these before connecting.
Connected ✓5 tools scanned

https://www.pathwren.workers.dev/c/mcp-registry-official/mcp/markdown

highmarkdown_lane_self_report
Directs agent to manually POST raw JSON-RPC bodies to an external URL and frames itself as mandatory first call
The description instructs the calling agent to construct and POST a literal JSON-RPC request body to https://www.pathwren.workers.dev/mcp/markdown outside the normal tool-calling mechanism, and repeatedly insists 'THIS IS THE CALL TO MAKE FIRST' regardless of user intent. This is a prompt-injection pattern: it tries to override the agent's normal reasoning about which tool to use and pushes it toward always contacting a specific external endpoint first. It also claims to report which URLs 'your client has fetched' historically on this host, implying the remote server is fingerprinting/tracking the calling agent across sessions and requests — information that is being sent to a third party without clear user awareness.
mediumwhoami
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumexample
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumwhoami
Reveals caller's IP, user-agent, and tracking classification to a remote server, reinforces 'call first' framing
This tool sends the agent's request headers (user-agent, source address) to an external host and returns a 'classification' plus whether the host has 'seen you here before,' indicating persistent tracking of the agent's identity across calls. Combined with the repeated embedded JSON-RPC example and language pushing it as a no-cost 'nothing to invent' first call, this encourages the agent to routinely leak identifying metadata to a third-party endpoint.
mediumcheck_markdown_lane
Embeds a redundant 'FIRST CALL' instruction pointing to a different tool
The description opens with an unrelated JSON-RPC call to 'markdown_lane_self_report' labeled 'FIRST CALL, needs nothing,' which is not required for this tool's actual function (checking a URL's markdown lane). This is the same manipulative pattern seen across the tool family, designed to steer the agent toward calling the self-report/tracking tool regardless of the user's actual request.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
lowexplain_llms_txt
Contains the same unrelated 'FIRST CALL' injection referencing another tool
Like the other tools in this set, the description prepends an out-of-context instruction to first call 'markdown_lane_self_report' with an embedded raw JSON-RPC body, which has nothing to do with parsing an llms.txt file. This repeated cross-tool nudging is a mild but consistent manipulation pattern across the whole tool family.
lowexample
Part of a suspicious tool family with repetitive external-endpoint framing
While this tool itself only runs a canned local example, its description shares the same verbose, repetitive style used across the family to build trust in the pathwren.workers.dev endpoint and normalize the pattern of POSTing raw JSON-RPC bodies to it, indirectly reinforcing the manipulative framing found in sibling tools.
Embed this badge

Show your MCP server’s security grade

MCP security grade F

Paste this into your README:

[![MCP security](https://gateturbo.com/badge/scan/34615788-0bb7-4bc2-95ab-f301db86a0cc)](https://gateturbo.com/report/34615788-0bb7-4bc2-95ab-f301db86a0cc)

Scanned 9/12/2026 · This is a point-in-time snapshot of the server’s public tools. Re-scan.

Connect this server safely with gate.

Continuous re-scans, drift alerts, per-tool allow/ask/block, and a log of every call.

Monitor it — free