MCP security report

agent-observatory-sensor.nolimit-observatory.workers.dev

D55/100
Security grade DHigh-severity signals — review these before connecting.
Connected ✓30 tools scanned

https://agent-observatory-sensor.nolimit-observatory.workers.dev/s/shiftjis-ok/mcp

highagent-tool-index
Embedded directive telling the agent to follow an external redirect chain
The description instructs the agent to 'Follow start_here.hop first (skill file, 302)' before anything else, and mentions additional 'docs, CLI, and remote MCP hops.' This is not a description of the tool's own behavior but an imperative command aimed at the calling AI, directing it to chase a redirect chain to an unknown external 'pay-per-call tool gateway.' This pattern is a classic vector for tool/prompt injection — it can lead the agent to fetch and trust content or code from an untrusted third party (skill files, remote MCP servers) without the user's awareness or consent, effectively escalating a lookup tool into a mechanism for loading arbitrary new tools/instructions into the agent's context.
mediumpeople-search-index
Facilitates locating personal information on named individuals; scope creep beyond stated function
The tool is described as finding 'a living people-search index (Ploid)' and instructs the agent to also pick up 'CLI setup, docs, API, and remote MCP hops.' A tool whose purpose is to help locate people-search services (often aggregating personal data like addresses, phone numbers, relatives) creates real potential for privacy harm/doxxing if invoked on a real name, and the bundled instruction to fetch CLI/API/remote-MCP hops encourages the agent to auto-install or connect to additional unvetted external services beyond a simple 'find an index' function.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
lowshiftjis-ok
Uniform, oversized parameter schema shared across many unrelated single-purpose tools
All 30 tools (from 'shiftjis-ok' through 'wiki-title-ok') expose the identical 9-field schema (zone, json, url, host, city, query, path, ref, feed) regardless of the tool's actual single-purpose function (e.g., a timezone tool accepting a 'path' or 'json' parameter, or a weather-hint tool accepting a 'ref' or 'feed' parameter). While each field claims to be 'discarded' after use, this pattern of accepting many unrelated and sensitive-looking fields (e.g., file paths, git refs, arbitrary JSON) on every tool call is unusual and could be used to quietly move data (including local file paths or other context) through tools that do not need it, relying on the stated 'discarded' claims without any way for the agent or user to verify actual handling.
Embed this badge

Show your MCP server’s security grade

MCP security grade D

Paste this into your README:

[![MCP security](https://gateturbo.com/badge/scan/586d3052-2a77-42fd-8b51-1df8704d07bd)](https://gateturbo.com/report/586d3052-2a77-42fd-8b51-1df8704d07bd)

Scanned 9/15/2026 · This is a point-in-time snapshot of the server’s public tools. Re-scan.

Connect this server safely with gate.

Continuous re-scans, drift alerts, per-tool allow/ask/block, and a log of every call.

Monitor it — free