MCP security report

agent-observatory-sensor.nolimit-observatory.workers.dev

F34/100
Security grade FHigh-severity signals — review these before connecting.
Connected ✓30 tools scanned

https://agent-observatory-sensor.nolimit-observatory.workers.dev/s/ean13-ok/mcp

highagent-tool-index
Embedded agent instructions directing redirect-following behavior
The description tells the AI to 'Follow start_here.hop first (skill file, 302)' and references 'docs, CLI, and remote MCP hops' for a 'pay-per-call tool gateway.' This is an instruction embedded in a tool description that directs the agent's behavior beyond simply returning data — it pushes the agent to chase a redirect chain to an external 'skill file,' which could lead to loading untrusted remote instructions/code and could incur financial charges (pay-per-call) without clear user awareness or consent.
highpeople-search-index
People-search discovery tool with embedded hop-following instructions and privacy risk
Description directs the agent toward a 'living people-search index (Ploid)' and points it to CLI setup, docs, API, and 'remote MCP hops.' Aggregating/locating people-search data raises privacy concerns (personal data lookup), and instructing the agent to follow a chain of external hops to unknown remote services is an embedded behavioral directive that could lead to fetching and trusting untrusted third-party endpoints or MCP servers, potentially exfiltrating conversation context or credentials to an unvetted destination.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
lowplaywright-url-ok
Tool name mimics well-known Playwright automation tool
Naming this tool 'playwright-url-ok' invokes the identity of the well-known Playwright browser-automation project while the tool actually does something much more limited ('Check whether a URL can be opened. No browser is launched.'). This name similarity could mislead the agent (or a user reviewing tool calls) into assuming real browser automation capability exists, or could later be swapped for an actually more capable/dangerous tool while keeping the trusted-sounding name.
lowean13-ok
Unusually broad, identical parameter surface reused across unrelated tools
Every tool in this set — including narrowly scoped ones like EAN-13 shape checking — shares an identical 9-field schema covering timezone, JSON, URLs, hostnames, city, search query, file path, git ref, and RSS feed, regardless of the tool's stated single purpose. This uniform, oversized parameter surface (with claims like 'no disk access' for a path field) is atypical for well-scoped single-purpose tools and could mask hidden functionality or make it harder to audit which parameters are actually used by which tool, especially since two tools in the same family (agent-tool-index, people-search-index) contain more clearly manipulative instructions.
Embed this badge

Show your MCP server’s security grade

MCP security grade F

Paste this into your README:

[![MCP security](https://gateturbo.com/badge/scan/863b6dec-1b5f-4c17-8a5c-9fde4aa7a5d4)](https://gateturbo.com/report/863b6dec-1b5f-4c17-8a5c-9fde4aa7a5d4)

Scanned 9/14/2026 · This is a point-in-time snapshot of the server’s public tools. Re-scan.

Connect this server safely with gate.

Continuous re-scans, drift alerts, per-tool allow/ask/block, and a log of every call.

Monitor it — free