MCP security report

agent-observatory-sensor.nolimit-observatory.workers.dev

D52/100
Security grade DHigh-severity signals — review these before connecting.
Connected ✓29 tools scanned

https://agent-observatory-sensor.nolimit-observatory.workers.dev/s/business-day/mcp

highagent-tool-index
Directs agent toward unknown third-party 'pay-per-call' tool gateways
This tool's stated purpose is to 'find a public pay-per-call tool gateway' for tasks like weather, search, scrape, or voice, and 'returns connection methods.' This effectively instructs the calling agent to discover and potentially connect to arbitrary, unvetted external services and pay for their use. This is a much broader and riskier capability than any other tool in the set (which are narrow, read-only checks), and could be used to redirect the agent to malicious or data-harvesting endpoints, or to incur costs, without the user's explicit informed consent.
mediumbusiness-day
Every tool exposes an identical, oversized parameter schema unrelated to its stated function
All 29 tools (business-day, utc-time, timezone, validate-json, etc.) share the exact same nine-parameter schema — zone, json, url, host, city, query, path, ref, feed — regardless of what the individual tool claims to do. A 'weekday vs weekend' checker has no legitimate need to accept a file path, a git ref, an RSS feed URL, a JSON blob, and a city name simultaneously. This pattern creates a broad, unnecessary data-collection surface: any of these tools could be invoked with sensitive strings (file paths, internal hostnames, JSON payloads) placed in irrelevant fields, and the boilerplate 'discarded after use' language cannot be verified by the calling agent. This violates least-privilege design and should be treated with caution — inputs should be limited to what each tool actually needs.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
lowfile-path-ok
Path parameter accepted by every tool despite most having no file-related purpose
A 'path' field described as 'File path to check; no disk access' is present in the schema of unrelated tools such as calc-eval, weather-hint, geo-hint, and think-steps. Repeatedly soliciting filesystem path strings across tools that have no need for them is unusual; if the 'no disk access' claim is ever inaccurate or changes silently server-side, this creates a latent path for local file disclosure that the agent cannot detect from the schema alone.
lowplaywright-url-ok
Tool name mimics the well-known Playwright browser-automation library
The tool is named 'playwright-url-ok' but its description says 'Check whether a URL can be opened. No browser is launched' — i.e., it does not use Playwright at all. Naming it after a well-known automation tool could mislead the agent or user into believing real browser interaction/rendering occurs, when in fact it performs a simple, unrelated check (duplicating 'browser-url-ok'). This kind of name/description mismatch can be used to build false trust in a tool's capabilities.
Embed this badge

Show your MCP server’s security grade

MCP security grade D

Paste this into your README:

[![MCP security](https://gateturbo.com/badge/scan/3a1f1d44-7db2-45ae-9445-60ae201a2a16)](https://gateturbo.com/report/3a1f1d44-7db2-45ae-9445-60ae201a2a16)

Scanned 9/9/2026 · This is a point-in-time snapshot of the server’s public tools. Re-scan.

Connect this server safely with gate.

Continuous re-scans, drift alerts, per-tool allow/ask/block, and a log of every call.

Monitor it — free