MCP security report

agent-cold-email-api.yaakovscher.workers.dev

F5/100
Security grade FHigh-severity signals — review these before connecting.
Connected ✓28 tools scanned

https://agent-cold-email-api.yaakovscher.workers.dev/mcp

highsetup_infrastructure
Provisions 'branded lookalike domains' for cold-email sending
The tool explicitly provisions 'branded lookalike domains' combined with a configurable persona and senderIdentity, then sends automated outbound email from them. This is the classic pattern for cousin-domain / brand-impersonation phishing infrastructure rather than legitimate marketing. An agent instructed to 'set up outreach for Brand X' could unknowingly purchase domains designed to look like a third party's real domain and spoof a sender identity on it, which can deceive recipients and damage the impersonated brand. This capability goes well beyond ordinary mailbox/domain provisioning and should require explicit human review/approval before any lookalike domain is registered or used to send mail.
mediuminfrastructure_status
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumget_webhooks
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumconfigure_webhook
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumconfigure_byo_domain
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumlist_messages
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumconfigure_byo_domain
connect_mailbox accepts raw credentials/secrets as plain tool arguments
The connect_mailbox action requires passing SMTP username/password, or OAuth clientSecret/refreshToken, or MS Graph clientSecret/refreshToken directly in the tool call arguments. These plaintext secrets will pass through the agent's context/transcript and any logging the MCP host performs, creating credential-exposure risk (e.g., secrets appearing in logs, being echoed back by the model, or retained in conversation history) beyond what's needed for the stated function of linking an existing mailbox.
lowsetup_infrastructure
Unusually long tool description
Very long descriptions are sometimes used to bury instructions to the AI. Skim it before allowing.
lowinfrastructure_status
Unusually long tool description
Very long descriptions are sometimes used to bury instructions to the AI. Skim it before allowing.
lowremove_mailboxes
Unusually long tool description
Very long descriptions are sometimes used to bury instructions to the AI. Skim it before allowing.
lowconfigure_dashboard
Unusually long tool description
Very long descriptions are sometimes used to bury instructions to the AI. Skim it before allowing.
lowconfigure_byo_domain
Unusually long tool description
Very long descriptions are sometimes used to bury instructions to the AI. Skim it before allowing.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
Embed this badge

Show your MCP server’s security grade

MCP security grade F

Paste this into your README:

[![MCP security](https://gateturbo.com/badge/scan/6d716f72-099f-4109-b6b1-063be2d9336f)](https://gateturbo.com/report/6d716f72-099f-4109-b6b1-063be2d9336f)

Scanned 9/3/2026 · This is a point-in-time snapshot of the server’s public tools. Re-scan.

Connect this server safely with gate.

Continuous re-scans, drift alerts, per-tool allow/ask/block, and a log of every call.

Monitor it — free