MCP security report

api.fplcopilot.com

A97/100
Security grade ANo obvious red flags in the tools we could see.
Connected ✓21 tools scanned

https://api.fplcopilot.com/mcp

low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
lowcreate_share_link
Arbitrary data published to a public URL
This tool accepts an open-ended 'data' object (additionalProperties: true) and publishes it to a public fplcopilot.com page. If the agent passes along more than the intended card fields (e.g. team ID, league details, or other personal data gathered during the conversation), that information would become publicly accessible via a shareable link. There's no schema constraint limiting what can be included, so care should be taken that only the intended, user-approved card data is sent here.
Embed this badge

Show your MCP server’s security grade

MCP security grade A

Paste this into your README:

[![MCP security](https://gateturbo.com/badge/scan/480c548d-38cd-463c-83d9-a279354fca2e)](https://gateturbo.com/report/480c548d-38cd-463c-83d9-a279354fca2e)

Scanned 10/3/2026 · This is a point-in-time snapshot of the server’s public tools. Re-scan.

Connect this server safely with gate.

Continuous re-scans, drift alerts, per-tool allow/ask/block, and a log of every call.

Monitor it — free