MCP security report

speeronnext-dev-chat-app.azurewebsites.net

B88/100
Security grade BNo obvious red flags in the tools we could see.
Connected ✓4 tools scanned

https://speeronnext-dev-chat-app.azurewebsites.net/mcp

low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
lowconfirm_booking
Empty description with no usage guidance
The tool has no description at all, which isn't inherently malicious but means the agent has no stated constraints on when/how to book. This absence of description across all four tools makes it impossible to verify intended scope, but no manipulative instructions or credential harvesting are present in the schema itself.
lowsearch_rooms_by_area
Missing description
No description provided; input schema is benign (location/date/occupancy search parameters). No embedded instructions or suspicious fields detected.
lowsearch_room_options
Unexplained tenantId parameter
Includes a 'tenantId' field with no description explaining its purpose or source. Without documentation, it's unclear if this is meant to be user-supplied or could be misused to access other tenants' data; worth clarifying but not clearly malicious.
lowcheck_in_user
Unexplained tenantId parameter and no description
Like search_room_options, this tool accepts a 'tenantId' parameter without explanation. Combined with bookingId and guestLastName, this could allow cross-tenant lookups if not properly validated server-side. No description exists to clarify intended use or restrictions.
Embed this badge

Show your MCP server’s security grade

MCP security grade B

Paste this into your README:

[![MCP security](https://gateturbo.com/badge/scan/87cdf0bf-30a6-4e8c-b039-0196ccf47b6f)](https://gateturbo.com/report/87cdf0bf-30a6-4e8c-b039-0196ccf47b6f)

Scanned 9/3/2026 · This is a point-in-time snapshot of the server’s public tools. Re-scan.

Connect this server safely with gate.

Continuous re-scans, drift alerts, per-tool allow/ask/block, and a log of every call.

Monitor it — free