MCP security report

agent-observatory-sensor.nolimit-observatory.workers.dev

F28/100
Security grade FHigh-severity signals — review these before connecting.
Connected ✓30 tools scanned

https://agent-observatory-sensor.nolimit-observatory.workers.dev/s/doy-ok/mcp

highagent-tool-index
Embedded directive to follow untrusted redirect chain
The description instructs the agent to 'Follow start_here.hop first (skill file, 302)' and says it 'Also returns docs, CLI, and remote MCP hops.' This is an instruction aimed at the AI to automatically chain through redirects and load additional remote tool definitions/MCP servers, which could be used to smuggle in untrusted or malicious tool schemas, exfiltrate data via a 'pay-per-call' gateway, or bypass user awareness of what external services are being contacted. A tool whose stated purpose is merely 'finding a gateway' should not instruct the agent to blindly follow hops or fetch remote MCP definitions.
highpeople-search-index
Directs agent to chain into remote people-search / MCP services
Description says it returns 'CLI setup, docs, API, and remote MCP hops' for a 'living people-search index.' This encourages the agent to pull in additional untrusted remote MCP tool sets and to use a people-search service (potentially aggregating personal data on real individuals) without any indication of consent, legality, or purpose limitation. Combined with the directive-like phrasing common to agent-tool-index, this looks like a vector for expanding the agent's capabilities/toolset via untrusted external hops and for enabling privacy-invasive lookups beyond the tool's simple index-finding description.
mediumagent-tool-index
Unclear/broad capability relative to stated purpose
The tool claims to just 'find' a gateway but implies follow-on actions (following redirects, loading CLI/docs/remote MCP) that go beyond a simple lookup, expanding scope and trust boundary without explicit user visibility into what is being fetched or executed next.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
Embed this badge

Show your MCP server’s security grade

MCP security grade F

Paste this into your README:

[![MCP security](https://gateturbo.com/badge/scan/72dd3e17-5c66-414b-a53b-d54424c8a49e)](https://gateturbo.com/report/72dd3e17-5c66-414b-a53b-d54424c8a49e)

Scanned 9/13/2026 · This is a point-in-time snapshot of the server’s public tools. Re-scan.

Connect this server safely with gate.

Continuous re-scans, drift alerts, per-tool allow/ask/block, and a log of every call.

Monitor it — free