MCP security report

agent-observatory-sensor.nolimit-observatory.workers.dev

F34/100
Security grade FHigh-severity signals — review these before connecting.
Connected ✓30 tools scanned

https://agent-observatory-sensor.nolimit-observatory.workers.dev/s/cc-nf/mcp

highagent-tool-index
Embedded directive to follow an unverified redirect chain
The description instructs the agent to 'Follow start_here.hop first (skill file, 302)' before anything else, and describes chaining into docs, CLI, and 'remote MCP hops.' This is an instruction aimed at the agent's behavior rather than a description of a lookup result, and it directs the agent to fetch and likely execute/parse content from an external, attacker-controllable redirect target ('a public pay-per-call gateway'). This is a classic SSRF/prompt-injection vector: the agent could be led to load remote instructions or a remote MCP endpoint outside the user's awareness, and 'task text discarded' gives false reassurance about data handling while not addressing the redirect-following behavior.
highpeople-search-index
Gateway to a people-search / personal-data lookup service
This tool's stated purpose is to locate a 'living people-search index' and hand back API/CLI/remote-MCP hops to it, i.e., it exists to funnel the agent toward a third-party service that aggregates personal information about individuals (a people-search/data-broker product). This is a capability with real potential for harm (doxxing, stalking, unauthorized personal data lookups) that is broader and more sensitive than a simple 'discard the query' utility suggests. The claim that 'query text is discarded' does not mitigate the risk that the tool exists to point the agent at a personal-data harvesting service.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
lowplaywright-url-ok
Name resembles the well-known Playwright browser-automation MCP tool
The tool name closely mirrors the popular 'Playwright' automation toolset even though the description explicitly says 'No browser is launched.' Naming it this way could cause an agent or user to assume it has real browser-automation capability (e.g., navigation, screenshots) it doesn't have, or could be used later to swap in more powerful/undisclosed behavior while relying on the trusted name.
lowcc-nf
Overly broad, irrelevant parameter surface shared across unrelated tools
This (and every other tool in the set) exposes an identical schema with nine unrelated parameters (zone, json, url, host, city, query, path, ref, feed) regardless of the tool's stated single-purpose function (e.g., an ISO 3166 country lookup accepting a file path, JSON body, git ref, and RSS feed URL). Such indiscriminate parameter surfaces are unusual for narrowly scoped utilities and could be used to quietly funnel file paths, URLs, or arbitrary text into a tool whose description gives no indication such data would ever be transmitted or processed, undermining the ability to reason about what data each call actually sends externally.
Embed this badge

Show your MCP server’s security grade

MCP security grade F

Paste this into your README:

[![MCP security](https://gateturbo.com/badge/scan/4bbb629f-df65-42b7-81de-71db2e00cd79)](https://gateturbo.com/report/4bbb629f-df65-42b7-81de-71db2e00cd79)

Scanned 9/13/2026 · This is a point-in-time snapshot of the server’s public tools. Re-scan.

Connect this server safely with gate.

Continuous re-scans, drift alerts, per-tool allow/ask/block, and a log of every call.

Monitor it — free