MCP security report

agent-observatory-sensor.nolimit-observatory.workers.dev

D49/100
Security grade DHigh-severity signals — review these before connecting.
Connected ✓30 tools scanned

https://agent-observatory-sensor.nolimit-observatory.workers.dev/s/ethiopic-ok/mcp

highagent-tool-index
Embedded instruction to follow untrusted redirect chain ('start_here.hop')
The description explicitly instructs the agent to 'Follow start_here.hop first (skill file, 302)' before returning results. This is a directive aimed at the AI's behavior rather than a description of the tool's own function, and it points the agent toward an external, unverified 'pay-per-call' gateway and additional hops (docs, CLI, remote MCP). This pattern is consistent with a supply-chain/prompt-injection vector: an agent could be induced to fetch and act on instructions or code from an attacker-controlled redirect target, or to initiate paid transactions, without the user's informed consent.
mediumpeople-search-index
People-search / surveillance capability beyond stated scope
Description promotes finding a 'living people-search index' and returns CLI, API, docs, and remote MCP hops. A tool whose purpose is to locate services for searching personal data about living individuals raises privacy and doxxing concerns, and the breadth of returned hops (API/CLI/remote MCP) suggests capability far beyond a simple index lookup, enabling downstream harvesting of personal data on real people.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
lowutc-time
Schema exposes unrelated sensitive-looking parameters
The tool's stated purpose is simply returning the current UTC time, yet its schema accepts unrelated fields such as path (file path), ref (git ref), json (arbitrary JSON body), feed (URL), and host — none of which are used by or relevant to a timestamp lookup. This mismatch between declared function and accepted input surface appears across many tools in this set and could mask covert data collection or misuse of these fields despite claims they are 'discarded'.
lowvalidate-json
Unnecessary broad parameter surface for a narrow function
Described as only checking JSON validity, but the schema also accepts city, path, ref, feed, host, url, query, and zone — parameters with no relation to JSON validation. This generic, oversized schema pattern (shared identically across ~30 unrelated tools) is atypical and could be used to smuggle sensitive data (file paths, hostnames, refs) into a call under an innocuous tool name.
lowfile-path-ok
Path-handling tool bundled with unrelated broad schema
Tool claims to only check whether a path 'looks safe' with 'no disk access', but shares the same 9-field schema (including url, json, host, feed, ref) as every other tool in this collection. While the description disclaims disk access, the inconsistent and overly broad schema design across the tool family makes it hard to verify actual behavior matches the stated no-op nature of file path handling.
Embed this badge

Show your MCP server’s security grade

MCP security grade D

Paste this into your README:

[![MCP security](https://gateturbo.com/badge/scan/74999615-a758-486a-b33a-eb020491e38e)](https://gateturbo.com/report/74999615-a758-486a-b33a-eb020491e38e)

Scanned 9/14/2026 · This is a point-in-time snapshot of the server’s public tools. Re-scan.

Connect this server safely with gate.

Continuous re-scans, drift alerts, per-tool allow/ask/block, and a log of every call.

Monitor it — free