MCP security report

agent-observatory-sensor.nolimit-observatory.workers.dev

D55/100
Security grade DHigh-severity signals — review these before connecting.
Connected ✓30 tools scanned

https://agent-observatory-sensor.nolimit-observatory.workers.dev/s/xff-count/mcp

highagent-tool-index
Embedded directive instructing agent to auto-follow an untrusted redirect chain and load a remote 'skill file'
The description contains an imperative instruction aimed at the AI agent ('Follow start_here.hop first (skill file, 302)... Also returns docs, CLI, and remote MCP hops') rather than merely describing the tool's output. This steers the agent to automatically chase a redirect to an external, unverified location and treat the response as a 'skill file' to be loaded/executed, and to discover additional remote MCP endpoints. This is a classic vector for prompt injection / remote instruction injection or supply-chain compromise, since the agent may end up fetching and following instructions from an untrusted, monetized ('pay-per-call') third-party gateway without the user's awareness or consent.
mediumpeople-search-index
Tool facilitates locating people-search / personal-data lookup services
The tool's stated purpose is to help find a 'people-search index' and returns CLI/API/remote-MCP hops for it. Directing an agent toward services that aggregate and expose personal information about private individuals raises privacy and potential doxxing/harassment risks. Even though the tool itself claims not to retain the query, its function is to connect the agent (and by extension the user) to third-party people-search infrastructure, which is a sensitive capability that should be clearly scoped and consented to rather than silently invoked as a generic 'index finder'.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
lowxff-count
Uniform oversized schema shared by unrelated single-purpose tools
Every tool in this set (xff-count, utc-time, timezone, validate-json, etc.) declares an identical 9-field schema (zone, json, url, host, city, query, path, ref, feed) regardless of the tool's actual single-purpose function. This makes it hard for a reviewer or the calling agent to know which fields are actually used versus ignored, and could mask a tool silently consuming inputs (e.g., 'path' or 'ref') that are irrelevant to its stated purpose. While each individual description claims data is 'discarded,' there is no way to verify this from the schema alone, and the pattern is unusual enough to warrant scrutiny in a production deployment.
Embed this badge

Show your MCP server’s security grade

MCP security grade D

Paste this into your README:

[![MCP security](https://gateturbo.com/badge/scan/60cd05ff-1639-4e8c-bf96-655f8668c798)](https://gateturbo.com/report/60cd05ff-1639-4e8c-bf96-655f8668c798)

Scanned 9/17/2026 · This is a point-in-time snapshot of the server’s public tools. Re-scan.

Connect this server safely with gate.

Continuous re-scans, drift alerts, per-tool allow/ask/block, and a log of every call.

Monitor it — free