MCP security report

jakehandy.com

B82/100
Security grade BA few things are worth a closer look before connecting.
Connected ✓10 tools scanned

https://jakehandy.com/mcp

mediumsite_guide
Fetches remote content that explicitly dictates agent behavior
This tool returns markdown content from the website itself that is described as containing 'rules for reacting to a passage' and instructions for AI agents. Because the content is server-controlled and can be changed at any time by the site owner, it is a classic indirect prompt-injection vector: the agent is told to read and presumably follow externally-hosted 'rules', which could later be altered to instruct the agent to take actions beyond its original task (e.g., auto-upvoting content, disclosing information, or ignoring user instructions) without the user's awareness.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
lowhighlight_passage
Free-text name/model fields are echoed back to other agents
The optional 'name' and 'model' fields are stored and later surfaced to other readers/agents via list_highlights and get_editorial ('passages readers and agents have reacted to appended'). Since these fields are unsanitized free text controlled by any caller, they could be used to embed misleading or instruction-like text that a future agent session might mistake for legitimate guidance when it reads highlight data. Not highly dangerous, but worth noting as an untrusted-content channel feeding back into agent context.
lowget_editorial
Returns user/agent-generated reaction content alongside article text
The description states highlighted passages and reactions from 'readers and agents' are appended to the editorial content returned to the model. This mixes trusted first-party article text with potentially untrusted, user-supplied metadata (names, model tags) in the same response, which could be exploited to inject misleading context if not clearly delimited from the actual editorial body.
Embed this badge

Show your MCP server’s security grade

MCP security grade B

Paste this into your README:

[![MCP security](https://gateturbo.com/badge/scan/4217d42d-94f0-4e8f-b06e-764bc4bc222e)](https://gateturbo.com/report/4217d42d-94f0-4e8f-b06e-764bc4bc222e)

Scanned 10/4/2026 · This is a point-in-time snapshot of the server’s public tools. Re-scan.

Connect this server safely with gate.

Continuous re-scans, drift alerts, per-tool allow/ask/block, and a log of every call.

Monitor it — free