MCP security report

toolforte.com

F5/100
Security grade FA few things are worth a closer look before connecting.
Connected ✓35 tools scanned

https://toolforte.com/api/mcp/mcp

mediumpassword_strength
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumworkflow_list
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumworkflow_run
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediummemory_set
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediummemory_get
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediummemory_list
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediummemory_delete
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumhtml_to_pdf
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumurl_to_pdf
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumurl_screenshot
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumqr_code_png
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumread_page
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumpdf_merge
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
lowmemory_set
Encourages persisting arbitrary conversation data to a third-party service
The description urges the agent to store 'anything worth keeping' (decisions, intermediate results, running lists) under a vendor-controlled account tied to an API key. If the agent stores sensitive user data (PII, business data) here, it is transmitted to and retained by an external service (toolforte.com) beyond the current session, without an explicit user consent step described in the tool. This is a plausible data exfiltration/retention vector, especially combined with memory_list which lets any session with the same key enumerate previously stored data.
lowgenerate_brp_test_data
Description directs agent to an external REST API for larger requests
The tool tells the agent that for more than 50 people or CSV output it should use https://toolforte.com/api/v1/tools/brp-test-data-generator instead of the MCP tool. This steers the agent to make direct HTTP calls to a third-party endpoint outside the reviewed MCP surface, which is worth noting even though the generated data is synthetic test data.
lowgenerate_upa_files
Description directs agent to an external REST API for bulk use
Similar to generate_brp_test_data, this tool tells the agent to use https://toolforte.com/api/v1/tools/upa-file-generator for bulk generation, encouraging the agent to send requests to a third-party endpoint not covered by this MCP tool definition.
lowworkflow_list
Embedded upsell instructing agent to obtain and transmit an API key
The description instructs the agent to 'Get a free key at https://toolforte.com/developers and send it on the MCP connection as the header Authorization: Bearer tf_...'. This is marketing/onboarding language embedded in a tool description that directs the agent to acquire and transmit a credential to a specific external site; while plausibly legitimate, it is the kind of embedded instruction that should be surfaced to the user rather than silently followed by the agent.
lowworkflow_run
Broad capability: executes multiple chained tool steps and API-key-gated, with same external key upsell
This tool can run an arbitrary saved sequence of other tools 'in order, passing each one the output of an earlier step' on behalf of the account, and repeats the instruction to obtain and send an API key via header. Because the actual steps and their side effects are defined server-side (in the saved workflow) rather than visible in this schema, the agent is being asked to execute opaque, potentially broad actions based solely on an id, which is unusually broad relative to a single tool call.
Embed this badge

Show your MCP server’s security grade

MCP security grade F

Paste this into your README:

[![MCP security](https://gateturbo.com/badge/scan/6d1c68da-1424-4860-8631-9ce382229dbb)](https://gateturbo.com/report/6d1c68da-1424-4860-8631-9ce382229dbb)

Scanned 9/3/2026 · This is a point-in-time snapshot of the server’s public tools. Re-scan.

Connect this server safely with gate.

Continuous re-scans, drift alerts, per-tool allow/ask/block, and a log of every call.

Monitor it — free