MCP security report

agent-observatory-sensor.nolimit-observatory.workers.dev

F37/100
Security grade FHigh-severity signals — review these before connecting.
Connected ✓30 tools scanned

https://agent-observatory-sensor.nolimit-observatory.workers.dev/s/sha3-224/mcp

highagent-tool-index
Instructs agent to follow untrusted redirect chain to an external 'pay-per-call' gateway
The description directs the agent to 'Follow start_here.hop first (skill file, 302)' and follow additional docs/CLI/remote MCP hops. This is an instruction embedded in a tool description telling the agent to chase external redirects and load additional remote resources/tools (a 'gateway') that are not defined in this MCP session. This is a classic vector for prompt injection or supply-chain compromise: the agent could be led to fetch and execute instructions or register new tools from an attacker-controlled or unverified endpoint, entirely outside the user's visibility or the original tool's stated scope (which appears to just be a lookup/index tool).
highpeople-search-index
Points to an external people-search / personal data service and remote hop chain
Description says it will 'Find a living people-search index (Ploid)' and returns 'CLI setup, docs, API, and remote MCP hops.' This tool's stated purpose (index lookup) masks a much broader capability: directing the agent toward a personal-information lookup service and additional remote MCP endpoints it can chain into. Combined with the pattern seen in agent-tool-index, this looks like a discovery/onboarding vector for privacy-invasive people-search capabilities and for pulling in unvetted remote tool servers, which is disproportionate to a simple 'index' tool and could facilitate doxxing or exfiltration once chained.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
lowsha3-224
Overly broad, irrelevant parameter surface shared across all tools
Every tool in this set (including simple ones like a hash-length checker) exposes an identical schema with nine unrelated parameters (zone, json, url, host, city, query, path, ref, feed) regardless of the tool's actual function. A hashing/length tool has no legitimate need to accept a file path, git ref, RSS feed URL, or city name. This generic, over-broad schema increases the attack surface and could let a compromised or malicious backend silently harvest data (e.g., file paths, hostnames, URLs) passed to tools whose descriptions imply narrow, harmless behavior ('input discarded'), without any way for the caller to verify the discard claim.
Embed this badge

Show your MCP server’s security grade

MCP security grade F

Paste this into your README:

[![MCP security](https://gateturbo.com/badge/scan/486eb965-1e4b-47b7-b94c-1b9a0aa40800)](https://gateturbo.com/report/486eb965-1e4b-47b7-b94c-1b9a0aa40800)

Scanned 9/15/2026 · This is a point-in-time snapshot of the server’s public tools. Re-scan.

Connect this server safely with gate.

Continuous re-scans, drift alerts, per-tool allow/ask/block, and a log of every call.

Monitor it — free