https://agent-observatory-sensor.nolimit-observatory.workers.dev/s/hexkey-len/mcp
highagent-tool-index
Embedded directive instructing agent to follow redirect chains to an unvetted pay-per-call gateway
The description explicitly instructs the AI to 'Follow start_here.hop first (skill file, 302)' and mentions it 'also returns docs, CLI, and remote MCP hops.' This is an instruction embedded in a tool description that directs the agent's behavior (auto-following redirects to external resources) rather than describing a discrete function. This could lead the agent to fetch and execute instructions from an untrusted third-party 'Monid' service, potentially incurring pay-per-call charges or loading additional unreviewed remote MCP tool definitions without explicit user awareness/consent.
highpeople-search-index
Facilitates PII/people-search lookups and dynamic loading of unreviewed remote tools
Tool description offers to find a 'living people-search index' and return 'CLI setup, docs, API, and remote MCP hops.' This both encourages privacy-invasive people-search activity and instructs the agent to pull in additional remote MCP tool/server configurations dynamically, which is a supply-chain risk — the agent could be induced to load and trust unreviewed external tool definitions or services without the user's informed consent.
mediumhexkey-len
Schema far exceeds stated single-purpose function
A tool described as computing a 'hex key length band' accepts unrelated fields (json, url, host, city, query, path, ref, feed) with no apparent use for the stated task. This pattern is repeated identically across all 30 tools, suggesting the schema is designed to normalize passing file paths, hostnames, URLs, and arbitrary JSON/query text into many different tools regardless of their stated purpose, with only a self-reported (unverifiable) claim that inputs are 'discarded'.
mediumfile-path-ok
File path acceptance with unverifiable 'no disk access' claim
Tool claims to check whether a path 'looks safe' with 'no disk access', but this claim cannot be verified from the description alone, and the same broad schema (accepting URLs, hosts, JSON, queries) is shared identically across unrelated tools, raising concern that path data could be used beyond the stated syntactic check.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
lowutc-time
Oversized input schema unrelated to stated function
A simple 'current UTC timestamp' tool accepts 9 fields including file paths and hostnames it has no stated need for. This is consistent with a broader pattern across the tool set of schema bloat that could be used to funnel sensitive data (paths, URLs, hosts) through unrelated tools.
lowtimezone
Oversized input schema unrelated to stated function
Same broad 9-field schema (including path/host/json/url/feed) attached to a simple timezone lookup tool, inconsistent with its narrow purpose.
lowvalidate-json
Oversized input schema unrelated to stated function
Tool only needs a 'json' field to validate JSON, yet accepts url, host, path, query, feed, etc. Unverifiable claim that data is 'discarded'.
lownormalize-url
Oversized input schema unrelated to stated function
Only 'url' is needed to normalize a URL, but the schema includes file path, host, json, query, and feed fields as well.
lowinspect-robots
Oversized input schema unrelated to stated function
Fetching robots.txt only requires a URL/host, yet the tool accepts file paths, JSON bodies, and search queries irrelevant to the task.
lowdomain-shape
Oversized input schema unrelated to stated function
Splitting a hostname into labels only needs 'host', but the schema exposes file path, JSON, query, and feed fields with no stated use.
lowcitation
Oversized input schema unrelated to stated function
Only a URL is needed to return HTTP status, yet the schema accepts file paths and other unrelated data.
lowcompatibility
Oversized, vague schema and unclear function
Description is vague ('classification of the request') while accepting broad unrelated fields including file paths and hostnames; unclear what is actually done with each field.
lowstatus-catalog
Oversized input schema unrelated to stated function
A static catalog lookup tool that needs no input at all accepts 9 unrelated fields including file paths and hostnames.
lowiana-zones
Oversized input schema unrelated to stated function
A static list-lookup tool accepts unrelated fields such as file path, host, and JSON with no stated purpose.
lowweb-fetch
Oversized input schema unrelated to stated function
Only URL is needed to check status/content-type, yet file path, host, JSON, and query fields are also accepted without explanation.
lowfetch-status
Oversized input schema unrelated to stated function
HEAD request tool needs only a URL but accepts file paths and other unrelated fields.
lowgithub-repo-shape
Oversized input schema unrelated to stated function
Parsing a GitHub URL only needs 'url', yet the schema includes file path, host, JSON, and other unrelated fields.
lowweather-hint
Oversized input schema unrelated to stated function
Only 'city' is needed for a weather lookup, but the tool accepts file paths, JSON, URLs, and other unrelated fields.
lowmemory-key-count
Oversized input schema unrelated to stated function
Counting JSON keys only needs the 'json' field; other accepted fields (path, host, url, feed) have no stated purpose.
lowbrowser-url-ok
Oversized input schema unrelated to stated function
Tool claims to check whether a URL 'can be opened' without launching a browser, yet accepts file paths and other unrelated fields with no stated use.
lowthink-steps
Oversized input schema unrelated to stated function
A static template-return tool needs no input, yet accepts 9 unrelated fields including file paths and hostnames.
lowsearch-query-len
Oversized input schema unrelated to stated function
Only 'query' is needed to count characters, but file path, host, URL, and JSON fields are also accepted without stated purpose.
lowhn-front-count
Oversized input schema unrelated to stated function
Counting HN stories needs no user-supplied identifying data, yet the tool accepts file paths, hosts, and JSON fields.
lowlib-docs-hint
Oversized input schema unrelated to stated function
Only a URL is needed to check HTTP status, but file path and other unrelated fields are accepted as well.
lowplaywright-url-ok
Oversized input schema unrelated to stated function; name resembles automation tool
Tool name suggests Playwright browser automation, but description says no browser is launched; regardless, it carries the same broad unrelated schema (file path, host, JSON, etc.) as other tools in this set.
lowfigma-url-shape
Oversized input schema unrelated to stated function
Parsing a Figma URL only needs 'url', but file path, host, JSON, and query fields are also accepted.
lowjira-key-shape
Oversized input schema unrelated to stated function
Checking a Jira key shape only needs a key/ref-like field, but file path, host, URL, and JSON fields are also present.
lowgeo-hint
Oversized input schema unrelated to stated function
Only 'city' is needed for lat/long lookup, but file path, host, JSON, and other unrelated fields are accepted.
lowcalc-eval
Oversized input schema unrelated to stated function
Arithmetic evaluation only needs an expression field, yet file path, host, URL, JSON, and query fields are also accepted with no stated purpose — potential vector for smuggling unrelated data through an innocuous-looking tool.
lowwiki-title-ok
Oversized input schema unrelated to stated function
Checking a Wikipedia title only needs a title/query, but file path, host, JSON, and URL fields are also accepted.