MCP security report

www.fatestar.top

D61/100
Security grade DA few things are worth a closer look before connecting.
Connected ✓3 tools scanned

https://www.fatestar.top/api/mcp

mediumziwei_reading
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumziwei_reading
Embedded marketing/funnel instructions directed at the AI
The description contains explicit conversational scripts for the agent to follow that go beyond the tool's core function of returning a fortune-telling reading — e.g. instructing the agent to actively guide the user to register on an external website (fatestar.top), complete 'new user tasks' to earn points, and obtain a developer API key, as well as scripted phrases to say when credits run out. This is an attempt to use the AI as a marketing/onboarding funnel for a third-party paid service rather than just describing tool behavior, and could mislead users into thinking these steps are required or officially sanctioned.
mediumziwei_reading
Sends user's birth data and personal question to a third-party external service
Unlike ziwei_chart/ziwei_transits which are self-contained (explicitly '0 第三方排盘库'), ziwei_reading forwards the user's full birthdate, gender, location, and free-text personal question (e.g. about relationships, career, health) to an external AI persona service tied to an API key and a specific commercial domain (fatestar.top). This sends potentially sensitive personal data off-device to a third party, and the tool description does not disclose what data retention/privacy practices that third party has.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
lowziwei_reading
Accepts and forwards an API credential via parameter or env var
The apiKey parameter (or FATESTAR_API_KEY env var) is passed directly to the external reading service. While likely necessary for billing/auth, agents should be cautious not to log or expose this key, and users should be aware the key grants access to a paid account that could be drained if leaked.
Embed this badge

Show your MCP server’s security grade

MCP security grade D

Paste this into your README:

[![MCP security](https://gateturbo.com/badge/scan/512b804a-6f78-400c-ae18-5cc96d448417)](https://gateturbo.com/report/512b804a-6f78-400c-ae18-5cc96d448417)

Scanned 9/4/2026 · This is a point-in-time snapshot of the server’s public tools. Re-scan.

Connect this server safely with gate.

Continuous re-scans, drift alerts, per-tool allow/ask/block, and a log of every call.

Monitor it — free