MCP security report

agent-observatory-sensor.nolimit-observatory.workers.dev

F34/100
Security grade FHigh-severity signals — review these before connecting.
Connected ✓30 tools scanned

https://agent-observatory-sensor.nolimit-observatory.workers.dev/s/windows1252-ok/mcp

highagent-tool-index
Embedded directive instructing agent to follow an external redirect chain
The description tells the agent to 'Follow start_here.hop first (skill file, 302)' and references additional docs/CLI/remote-MCP hops for a 'pay-per-call tool gateway.' This is an instruction aimed at the AI's behavior (auto-following redirects to an unknown, monetized third-party service) rather than a description of the tool's own function. It could lead the agent to silently chain into untrusted infrastructure, incur costs, or ingest injected instructions from the fetched resource without user awareness.
highpeople-search-index
People-search index with embedded hop-following instruction and privacy risk
Like agent-tool-index, this description instructs the agent to follow additional hops (CLI setup, docs, API, remote MCP) to reach a 'living people-search index.' Beyond the embedded directive concern, the tool's stated purpose—locating a service that indexes personal data on living individuals—raises privacy/surveillance concerns if the agent is nudged to use it to look up personal information about real people without clear consent or purpose limitation.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
lowwindows1252-ok
Overly broad, function-irrelevant input schema shared across unrelated tools
Every tool in this set, including simple ones like a UTC time or JSON validator, exposes the same nine parameters (zone, json, url, host, city, query, path, ref, feed) regardless of what the tool actually does. This allows arbitrary combinations of sensitive-looking fields (file path, hostname, JSON body, URL) to be passed into tools whose description says they are unrelated, which could be used to smuggle data through an unexpected channel or make it hard for a user/reviewer to reason about what data a given call actually sends and where. The same issue applies to all 30 tools since they share this schema.
lowplaywright-url-ok
Tool name suggests real browser automation but performs no action; duplicate of browser-url-ok
The name 'playwright-url-ok' invokes the well-known Playwright browser automation framework, but the description clarifies 'No browser is launched.' Having two identically-described tools (browser-url-ok and playwright-url-ok) with brand-suggestive naming could mislead an agent or user into assuming real browser-driven verification is occurring when it is not.
Embed this badge

Show your MCP server’s security grade

MCP security grade F

Paste this into your README:

[![MCP security](https://gateturbo.com/badge/scan/44d6b367-c3a7-47f1-ad11-aa90aad4df25)](https://gateturbo.com/report/44d6b367-c3a7-47f1-ad11-aa90aad4df25)

Scanned 9/16/2026 · This is a point-in-time snapshot of the server’s public tools. Re-scan.

Connect this server safely with gate.

Continuous re-scans, drift alerts, per-tool allow/ask/block, and a log of every call.

Monitor it — free