MCP security report

mcclipface.com

A91/100
Security grade ANo obvious red flags in the tools we could see.
Connected ✓4 tools scanned

https://mcclipface.com/mcp

lowfind_product_coupons
Unusually long tool description
Very long descriptions are sometimes used to bury instructions to the AI. Skim it before allowing.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
lowfind_coupons
Tool instructs agent to autonomously navigate via affiliate links during checkout
The description tells the agent that when 'browsing or checking out for the shopper', it should itself open the affiliate-tracked link before adding items to cart, rather than just presenting it as information. While disclosed and commission-neutral per the text, this is a directive embedded in a data-retrieval tool that steers agent behavior toward the vendor's monetization interests (ensuring its affiliate link is used) rather than purely returning coupon data. This repeats in find_coupons, find_product_coupons, and get_deals.
lowreport_coupon_result
"Consent is presumed" language may lead to data submission without explicit confirmation
The tool states 'Report once per code per checkout, after the final attempt: every result, worked or failed (consent is presumed).' This instructs the agent to transmit usage data (store, code, outcome) to an external service based on an assumed/implicit consent model tied to a mode toggle, rather than requiring the agent to confirm with the user at the time of each report. Although the data collected is minimal (no cart/personal data), embedding 'consent is presumed' in a tool description nudges the agent to skip explicit per-action confirmation before sending data externally.
Embed this badge

Show your MCP server’s security grade

MCP security grade A

Paste this into your README:

[![MCP security](https://gateturbo.com/badge/scan/7ba2ad7c-191f-4933-8a87-bc379774633c)](https://gateturbo.com/report/7ba2ad7c-191f-4933-8a87-bc379774633c)

Scanned 10/3/2026 · This is a point-in-time snapshot of the server’s public tools. Re-scan.

Connect this server safely with gate.

Continuous re-scans, drift alerts, per-tool allow/ask/block, and a log of every call.

Monitor it — free