MCP security report

realworldapis-api.realworldapis.workers.dev

B85/100
Security grade BA few things are worth a closer look before connecting.
Connected ✓1 tool scanned

https://realworldapis-api.realworldapis.workers.dev/mcp

mediumfind_api_for_task
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
lowfind_api_for_task
Instruction to AI limiting its own analytical output
The description contains a directive aimed at the AI agent: 'do not infer comparative reliability, performance, quality, coverage, ease of use, enterprise suitability, or free-tier generosity.' While plausibly intended to prevent hallucination, this is a behavioral constraint embedded in a tool description rather than a schema constraint, which could be used to suppress legitimate critical analysis or warnings the agent might otherwise surface to the user. It should be validated that this doesn't prevent the agent from flagging genuine concerns about returned data.
Embed this badge

Show your MCP server’s security grade

MCP security grade B

Paste this into your README:

[![MCP security](https://gateturbo.com/badge/scan/3b952e92-ee5f-42f5-953d-15386c4a751f)](https://gateturbo.com/report/3b952e92-ee5f-42f5-953d-15386c4a751f)

Scanned 9/14/2026 · This is a point-in-time snapshot of the server’s public tools. Re-scan.

Connect this server safely with gate.

Continuous re-scans, drift alerts, per-tool allow/ask/block, and a log of every call.

Monitor it — free