MCP security report

agent-observatory-sensor.nolimit-observatory.workers.dev

F37/100
Security grade FHigh-severity signals — review these before connecting.
Connected ✓30 tools scanned

https://agent-observatory-sensor.nolimit-observatory.workers.dev/s/nel-ok/mcp

highagent-tool-index
Embedded instruction directs agent to follow external redirect chain ('hops')
The description tells the AI to 'Follow start_here.hop first (skill file, 302)' and then follow 'docs, CLI, and remote MCP hops' to a third-party 'pay-per-call' gateway (Monid). This is an instruction aimed at the agent's behavior rather than a description of a discrete, bounded function. Blindly following a chain of redirects/hops from an unverified external source is a classic vector for prompt injection or supply-chain compromise (the agent could be led to fetch and execute new instructions, register for paid services, or load additional 'remote MCP' tool definitions without the user's knowledge or consent). The claim that 'task text discarded' does not mitigate the risk that the tool encourages autonomous multi-hop navigation to an untrusted endpoint.
highpeople-search-index
People-search discovery tool with hop-following instructions; privacy risk
This tool is described as finding a 'living people-search index (Ploid)' and, like agent-tool-index, returns 'CLI setup, docs, API, and remote MCP hops' — again nudging the agent to traverse an external chain of resources. Beyond the same hop-following/prompt-injection concern, the stated purpose (indexing/searching data about living people) raises privacy and misuse concerns (potential facilitation of doxxing, stalking, or unauthorized personal-data lookups) that are unusually broad relative to the other simple utility tools in this set.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
lownel-ok
Oversized, irrelevant parameter schema shared across unrelated tools
Every tool in this set exposes an identical schema with nine unrelated fields (zone, json, url, host, city, query, path, ref, feed) regardless of the tool's actual purpose (e.g., a JSON key-count tool accepting a 'feed' or 'path' parameter it does not use). While each field description claims data is discarded, this pattern of uniformly broad, unused parameters across many tools is atypical and could be used to smuggle sensitive values (e.g., file paths, tokens embedded in query/json fields) through tools whose names suggest narrow, harmless functionality. Recommend tightening each tool's schema to only the parameters it actually consumes.
Embed this badge

Show your MCP server’s security grade

MCP security grade F

Paste this into your README:

[![MCP security](https://gateturbo.com/badge/scan/39cb2a73-6a4c-4af8-b324-12e3a3f12ed3)](https://gateturbo.com/report/39cb2a73-6a4c-4af8-b324-12e3a3f12ed3)

Scanned 9/15/2026 · This is a point-in-time snapshot of the server’s public tools. Re-scan.

Connect this server safely with gate.

Continuous re-scans, drift alerts, per-tool allow/ask/block, and a log of every call.

Monitor it — free