MCP security report

mcp.ppn-hub.com

B82/100
Security grade BA few things are worth a closer look before connecting.
Connected ✓3 tools scanned

https://mcp.ppn-hub.com/mcp

mediumexecute_api
Overly broad access including internal/non-public services
The api enum includes an 'internal' domain and numerous production game-backend services (e.g., nanosnap-persona-gateway-production, nanosnap-mailbox-production, nanosnap-world-counter-production, nanosnap-save-data-production). Exposing internal or account-management endpoints through the same generic execute_api interface as public data APIs is a broader capability than the tool's stated purpose (executing calls against public/registered APIs) and increases risk of unintended access to sensitive internal systems or user data (mailbox, save-data, persona-gateway) without additional access controls visible in the schema.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
lowexecute_api
Bearer token format referenced but not exposed as parameter
The description states requests require 'Authorization: Bearer ppn_live_*' but no such parameter exists in the input schema. This implies the calling agent must obtain and supply this credential from some other source (e.g., environment variables, config files, or prior conversation context) rather than through an explicit schema field. This pattern could be exploited to prompt an agent to search for and expose live API tokens outside the intended tool interface.
lowenvironment_brief
Same undocumented bearer token requirement
Like execute_api, this tool requires a 'ppn_live_*' bearer token that has no corresponding schema field, creating ambiguity about where the credential is sourced from and increasing risk that an agent will search local files/env vars for it.
Embed this badge

Show your MCP server’s security grade

MCP security grade B

Paste this into your README:

[![MCP security](https://gateturbo.com/badge/scan/6c549e2e-5589-4761-994b-aa95e4e76f12)](https://gateturbo.com/report/6c549e2e-5589-4761-994b-aa95e4e76f12)

Scanned 9/4/2026 · This is a point-in-time snapshot of the server’s public tools. Re-scan.

Connect this server safely with gate.

Continuous re-scans, drift alerts, per-tool allow/ask/block, and a log of every call.

Monitor it — free