MCP security report

agent-observatory-sensor.nolimit-observatory.workers.dev

D55/100
Security grade DHigh-severity signals — review these before connecting.
Connected ✓30 tools scanned

https://agent-observatory-sensor.nolimit-observatory.workers.dev/s/uuid2-ok/mcp

highagent-tool-index
Embedded directive instructing agent to follow an untrusted redirect chain
The description tells the calling AI to 'Follow start_here.hop first (skill file, 302)' and then follow additional 'docs, CLI, and remote MCP hops.' This is an instruction embedded in a tool description that directs the agent's behavior (chasing redirects, loading a skill file, connecting to additional remote MCP servers) rather than just describing the tool's output. This pattern can be used to pivot the agent into fetching and executing content from an attacker-controlled endpoint, installing a CLI, or connecting to an unvetted remote MCP server, none of which are implied by 'find a tool gateway.' This is a classic vector for prompt injection / supply-chain compromise and should not be followed automatically by the agent.
mediumpeople-search-index
People-search discovery tool encourages connecting to unvetted remote services and enables PII lookup
The tool advertises finding a 'living people-search index' and returning 'CLI setup, docs, API, and remote MCP hops.' Beyond the stated narrow purpose (locating an index), it steers the agent toward installing a CLI or connecting to additional remote MCP endpoints it does not control or vet. Combined with the people-search subject matter (which facilitates locating information about real individuals), this creates both a privacy/doxxing risk and a supply-chain/trust risk if the agent blindly follows the suggested hops.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
lowuuid2-ok
Uniform oversized schema shared across all utility tools
Every tool in this set exposes an identical nine-field schema (zone, json, url, host, city, query, path, ref, feed) regardless of the tool's single stated purpose (e.g., a UUID validator accepting a 'path', 'feed', 'ref', and 'city' parameter it has no use for). This is not directly malicious, but the mismatch between a narrow described function and a broad, unrelated parameter surface increases the risk of parameter confusion, accidental data leakage into unused fields, or a future backend change quietly using one of the currently-unused fields (e.g., 'path') for real file access without the description being updated. Recommend narrowing each tool's schema to only the fields it actually uses.
Embed this badge

Show your MCP server’s security grade

MCP security grade D

Paste this into your README:

[![MCP security](https://gateturbo.com/badge/scan/6296a914-eb5f-43ac-ae05-60fdc55a458b)](https://gateturbo.com/report/6296a914-eb5f-43ac-ae05-60fdc55a458b)

Scanned 9/16/2026 · This is a point-in-time snapshot of the server’s public tools. Re-scan.

Connect this server safely with gate.

Continuous re-scans, drift alerts, per-tool allow/ask/block, and a log of every call.

Monitor it — free