MCP security report

shorti.ai

A91/100
Security grade ANo obvious red flags in the tools we could see.
Connected ✓12 tools scanned

https://shorti.ai/mcp

low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
lowshorti_check_link
Embedded directive instructing the AI's phrasing
The description contains a direct imperative addressed to the AI model ('Speak in observations that carry their evidence, and name a cause only where one was verified; fidelity is not a forecast of views' / Korean equivalent). This is stylistic guidance embedded in tool metadata rather than a description of the tool's inputs/outputs, and resembles a prompt-injection pattern attempting to steer the agent's output style. Not overtly harmful, but it goes beyond describing functionality and should be treated as untrusted content, not binding instruction.
lowshorti_what_to_shoot
Repeated 'never translate' directive to the AI across multiple tools
The `lang` parameter description across nearly every tool in this set includes the imperative 'never translate its Korean yourself,' which is an instruction aimed at controlling the agent's behavior (not just describing data). While plausibly benign (avoiding mistranslation), embedding behavioral commands in parameter descriptions is a pattern worth flagging since it conditions the agent to follow tool-embedded directives uncritically.
lowshorti_check_link
Token/polling handoff flow — verify no credential leakage
The tool issues a signed token and polls for a 'shared' result from a user-facing web page. This is a reasonable out-of-band handoff pattern (nothing is read until user explicitly shares), but agents should ensure the token/URL handling does not get repurposed to fetch or transmit anything beyond the documented summary, since the description is lengthy and could mask scope creep in future versions.
Embed this badge

Show your MCP server’s security grade

MCP security grade A

Paste this into your README:

[![MCP security](https://gateturbo.com/badge/scan/668719a6-a577-4690-b2e7-83ed6028740c)](https://gateturbo.com/report/668719a6-a577-4690-b2e7-83ed6028740c)

Scanned 10/1/2026 · This is a point-in-time snapshot of the server’s public tools. Re-scan.

Connect this server safely with gate.

Continuous re-scans, drift alerts, per-tool allow/ask/block, and a log of every call.

Monitor it — free