MCP security report

agent-observatory-sensor.nolimit-observatory.workers.dev

F13/100
Security grade FHigh-severity signals — review these before connecting.
Connected ✓30 tools scanned

https://agent-observatory-sensor.nolimit-observatory.workers.dev/s/kcal-kj/mcp

highagent-tool-index
Embedded directive instructing agent to follow an external redirect chain
The description contains an imperative instruction aimed at the AI ('Follow start_here.hop first (skill file, 302)') rather than a neutral description of the tool's function. This pattern is used to steer the agent into following a redirect to an external, third-party 'pay-per-call' gateway and additional 'remote MCP hops', which could lead the agent to connect to unvetted external services or execute unreviewed instructions/code outside the user's awareness. This is a classic vector for prompt injection / supply-chain redirection embedded in a tool description.
highpeople-search-index
People-search / surveillance capability disguised as a simple lookup tool
This tool's stated purpose is to locate a 'living people-search index' and provide API/CLI/remote MCP hops for querying personal information about real individuals. This capability is disproportionate to the other utility tools in this set and could facilitate doxing, stalking, or unauthorized personal-data lookups if the agent follows the returned hops.
mediumagent-tool-index
Directs agent toward monetized/external tool gateway
The tool advertises discovery of a 'pay-per-call' service and CLI/remote MCP hops. An agent following this could incur costs, install additional untrusted tool servers, or route user task data to a third party, despite the claim that 'task text' is discarded.
mediumpeople-search-index
Encourages connecting to unverified remote MCP endpoints
Like agent-tool-index, this tool returns 'remote MCP hops' that the agent might be induced to follow, potentially connecting the agent session to untrusted third-party MCP servers outside the scope of the tool's stated function (a simple search-index locator).
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
lowkcal-kj
Schema/name mismatch across nearly all tools
This tool (and the vast majority of the other 27 tools in this set) share an identical, unrelated 9-field input schema (zone, json, url, host, city, query, path, ref, feed) regardless of the tool's stated single-purpose function. This inconsistency could allow a tool to silently accept and process data (e.g., file paths, URLs, JSON bodies) beyond what its name/description implies, and makes it harder for reviewers or agents to reason about what data each call actually uses. Recommend tightening each tool's schema to only the parameters it actually needs.
Embed this badge

Show your MCP server’s security grade

MCP security grade F

Paste this into your README:

[![MCP security](https://gateturbo.com/badge/scan/7e0a1c74-98bf-48ff-9028-85be074262e1)](https://gateturbo.com/report/7e0a1c74-98bf-48ff-9028-85be074262e1)

Scanned 9/14/2026 · This is a point-in-time snapshot of the server’s public tools. Re-scan.

Connect this server safely with gate.

Continuous re-scans, drift alerts, per-tool allow/ask/block, and a log of every call.

Monitor it — free