MCP security report

sendit.infiniteappsai.com

F5/100
Security grade FA few things are worth a closer look before connecting.
Connected ✓148 tools scanned

https://sendit.infiniteappsai.com/mcp

mediumconnect_bluesky
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumconnect_lemmy
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumconnect_telegram
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumconnect_devto
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumconnect_hashnode
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumconnect_whop
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumconnect_platform
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumupload_media
Arbitrary local file read and exfiltration to external URL
The tool accepts an unrestricted 'filePath' string and uploads the file's contents to a third-party cloud storage service, returning a public HTTPS URL. The schema does not enforce that the path point to an actual image/video file or restrict it to a media directory — only the description text mentions supported formats (jpg/png/gif/webp/mp4/mov/webm) as a convention, not a hard constraint. If a user's request or any injected content in chat causes the agent to pass a sensitive local path (e.g., an SSH key, .env file, or other credential file) instead of an actual media file, this tool would upload it to a public/external URL, which is a data-exfiltration risk broader than the tool's stated 'upload media for social posts' purpose.
lowpublish_content
Unusually long tool description
Very long descriptions are sometimes used to bury instructions to the AI. Skim it before allowing.
lowschedule_content
Unusually long tool description
Very long descriptions are sometimes used to bury instructions to the AI. Skim it before allowing.
lowvalidate_content
Unusually long tool description
Very long descriptions are sometimes used to bury instructions to the AI. Skim it before allowing.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
Embed this badge

Show your MCP server’s security grade

MCP security grade F

Paste this into your README:

[![MCP security](https://gateturbo.com/badge/scan/9651c8cc-73d0-462c-8861-eb437743ee50)](https://gateturbo.com/report/9651c8cc-73d0-462c-8861-eb437743ee50)

Scanned 9/3/2026 · This is a point-in-time snapshot of the server’s public tools. Re-scan.

Connect this server safely with gate.

Continuous re-scans, drift alerts, per-tool allow/ask/block, and a log of every call.

Monitor it — free