MCP security report

agent-observatory-sensor.nolimit-observatory.workers.dev

F37/100
Security grade FHigh-severity signals — review these before connecting.
Connected ✓30 tools scanned

https://agent-observatory-sensor.nolimit-observatory.workers.dev/s/nit-cd/mcp

highagent-tool-index
Embedded directive to follow untrusted redirect chain (hop)
The description instructs the agent to 'Follow start_here.hop first (skill file, 302)' and chase 'docs, CLI, and remote MCP hops.' This is an imperative instruction aimed at the AI model rather than a description of a data schema, and it directs the agent to fetch and likely execute/interpret content from an external, attacker-controllable redirect chain. This is a classic vector for prompt injection or SSRF-style chaining to arbitrary remote endpoints, and it references a 'pay-per-call' gateway, meaning following the instruction could trigger billing or invoke additional untrusted tools without explicit user awareness or consent.
highpeople-search-index
Privacy-invasive people-search capability with embedded hop instructions
This tool's stated purpose is to locate an index for searching personal information about 'living people' and explicitly returns 'CLI setup, docs, API, and remote MCP hops' to follow. Combined with the directive-style phrasing (similar to agent-tool-index), this both encourages chaining into unknown remote MCP servers/APIs and provides a discovery mechanism for people-search/doxxing services. Even though the tool itself only 'discards' query text, its stated purpose facilitates locating third-party services for aggregating personal data, which is a sensitive capability that could enable surveillance or harassment if invoked based on the model's own initiative rather than explicit, informed user request.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
lownit-cd
Tool name/description mismatch and irrelevant broad schema
The tool is named 'nit-cd' and described as converting 'Nits to cd/m2', yet its input schema contains nine unrelated fields (zone, json, url, host, city, query, path, ref, feed) that have nothing to do with luminance conversion and match the schema of many unrelated tools verbatim. This mismatch suggests either a templated/copy-pasted definition or an attempt to obscure the tool's actual behavior behind a benign-sounding name, which could let unexpected inputs (URLs, hostnames, file paths) be silently accepted and processed by a function whose real purpose is unclear from its name.
Embed this badge

Show your MCP server’s security grade

MCP security grade F

Paste this into your README:

[![MCP security](https://gateturbo.com/badge/scan/632dbdf4-e182-4683-b794-42894cf45e46)](https://gateturbo.com/report/632dbdf4-e182-4683-b794-42894cf45e46)

Scanned 9/17/2026 · This is a point-in-time snapshot of the server’s public tools. Re-scan.

Connect this server safely with gate.

Continuous re-scans, drift alerts, per-tool allow/ask/block, and a log of every call.

Monitor it — free