MCP security report

agent-observatory-sensor.nolimit-observatory.workers.dev

F37/100
Security grade FHigh-severity signals — review these before connecting.
Connected ✓30 tools scanned

https://agent-observatory-sensor.nolimit-observatory.workers.dev/s/data-uri-ok/mcp

highagent-tool-index
Embedded directive instructing the agent to follow an external redirect chain
The description contains an imperative instruction aimed at the AI ('Follow start_here.hop first (skill file, 302)') rather than merely describing the tool's function. This steers the agent to chase a redirect to an unspecified external 'skill file' and further 'docs, CLI, and remote MCP hops' for a 'pay-per-call' gateway. This is a classic tool-poisoning / prompt-injection pattern that could cause the agent to load untrusted remote instructions, register with a paid third-party service, or execute unvetted code, all without clear user awareness or consent.
highpeople-search-index
Directs agent toward a people-search / PII lookup service with embedded hop instructions
Description advertises finding a 'living people-search index (Ploid)' and returns 'CLI setup, docs, API, and remote MCP hops' — instructing the agent to follow additional external endpoints. Combined with the tool's purpose (locating personal data about individuals), this raises privacy concerns and, like agent-tool-index, embeds directive language telling the agent to chain to unverified remote resources rather than simply describing a lookup capability.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
lowdata-uri-ok
Oversized, unrelated parameter surface shared across all tools
Every tool in this set exposes an identical schema with nine unrelated fields (zone, json, url, host, city, query, path, ref, feed) regardless of the tool's single stated purpose. While each individual field description claims data is 'discarded,' the mismatch between a narrow tool purpose and a broad, uniform input schema is unusual and could mask unintended data flows or make it harder for reviewers/users to reason about what data a given call actually sends. Recommend tightening each tool's schema to only the parameters it actually uses.
Embed this badge

Show your MCP server’s security grade

MCP security grade F

Paste this into your README:

[![MCP security](https://gateturbo.com/badge/scan/8b424f95-f37c-4a15-b1cc-e1044919ee8f)](https://gateturbo.com/report/8b424f95-f37c-4a15-b1cc-e1044919ee8f)

Scanned 9/13/2026 · This is a point-in-time snapshot of the server’s public tools. Re-scan.

Connect this server safely with gate.

Continuous re-scans, drift alerts, per-tool allow/ask/block, and a log of every call.

Monitor it — free