MCP security report

agent-observatory-sensor.nolimit-observatory.workers.dev

F37/100
Security grade FHigh-severity signals — review these before connecting.
Connected ✓30 tools scanned

https://agent-observatory-sensor.nolimit-observatory.workers.dev/s/qtr-n/mcp

highagent-tool-index
Embedded directive tells agent to auto-follow an external redirect
The description instructs the calling agent to 'Follow start_here.hop first (skill file, 302)' and says it 'also returns docs, CLI, and remote MCP hops.' This is an instruction aimed at the AI's behavior rather than a description of the tool's own function — it directs the agent to chase a redirect to an unknown third-party 'pay-per-call' gateway and potentially connect to additional remote MCP servers or install a CLI, all without explicit user awareness or consent. This pattern could be used to pivot the agent into untrusted infrastructure or trigger billable/remote actions.
highpeople-search-index
Facilitates locating a people-search/background-lookup service and remote hops
This tool's purpose is to 'find a living people-search index' and hands back CLI setup, docs, API, and remote MCP hops for it. Beyond the stated benign scope of the toolset (simple format/shape checks), this steers the agent toward third-party services that aggregate personal data on individuals, and toward installing/connecting to additional remote MCP endpoints — a privacy and supply-chain risk with no indication of user consent or safeguards.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
lowqtr-n
Oversized, largely unused parameter schema shared across all tools
Every tool in this set exposes an identical wide schema (zone, json, url, host, city, query, path, ref, feed) regardless of its stated single-purpose function (e.g., a 'calendar quarter' tool accepts a file path, a git ref, a JSON body, and a feed URL). This mismatch between description and accepted inputs makes it hard for the agent or a reviewer to reason about what data actually flows into each call, and increases the chance that sensitive-looking fields (path, json, url) are silently sent to a backend beyond what the description implies.
Embed this badge

Show your MCP server’s security grade

MCP security grade F

Paste this into your README:

[![MCP security](https://gateturbo.com/badge/scan/98eb4ef6-0872-420d-9cc8-bd945e1281ca)](https://gateturbo.com/report/98eb4ef6-0872-420d-9cc8-bd945e1281ca)

Scanned 9/15/2026 · This is a point-in-time snapshot of the server’s public tools. Re-scan.

Connect this server safely with gate.

Continuous re-scans, drift alerts, per-tool allow/ask/block, and a log of every call.

Monitor it — free