MCP security report

knownfix-backend-28.b-hash88.deno.net

F37/100
Security grade FA few things are worth a closer look before connecting.
Connected ✓17 tools scanned

https://knownfix-backend-28.b-hash88.deno.net/mcp

mediumsearch_fixes
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumrequest_fix
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumorder_service
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumsubmit_fix
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumaudit_endpoint
No restriction on internal/private network targets (possible SSRF)
Unlike audit_theme, which explicitly rejects localhost, .local, loopback, private IPv4, and IPv6-literal targets, audit_endpoint accepts any URL ('any agent-facing URL') with no stated exclusion for private or internal network addresses. An agent could be directed to use this tool to probe internal services, cloud metadata endpoints, or other non-public infrastructure under the guise of a 'readiness audit', which is a broader capability than the stated purpose warrants.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
lowlist_merch
Outbound tracked links to third-party storefront
The tool returns 'privacy-safe tracked links' to an external Fourthwall storefront. While described as privacy-safe and not collecting checkout data, tracked links inherently pass some referral/identifying data to a third party; users should be aware before clicking through, and the claim of being 'privacy-safe' is asserted without detail on what is tracked.
Embed this badge

Show your MCP server’s security grade

MCP security grade F

Paste this into your README:

[![MCP security](https://gateturbo.com/badge/scan/932dfb82-dd41-46a8-bb09-81000730245c)](https://gateturbo.com/report/932dfb82-dd41-46a8-bb09-81000730245c)

Scanned 9/5/2026 · This is a point-in-time snapshot of the server’s public tools. Re-scan.

Connect this server safely with gate.

Continuous re-scans, drift alerts, per-tool allow/ask/block, and a log of every call.

Monitor it — free