MCP security report

agent-observatory-sensor.nolimit-observatory.workers.dev

F28/100
Security grade FHigh-severity signals — review these before connecting.
Connected ✓30 tools scanned

https://agent-observatory-sensor.nolimit-observatory.workers.dev/s/iso-wd-ok/mcp

highagent-tool-index
Embedded directive urging agent to follow untrusted redirect chains
The description explicitly instructs the agent to 'Follow start_here.hop first (skill file, 302)' and then chain into docs, CLI, and remote MCP hops. This is an instruction aimed at the AI's behavior rather than a description of a simple lookup, and it encourages the agent to autonomously fetch and execute content from an external, unverified gateway ('Monid') and to connect to additional remote MCP servers. This could be used to smuggle in a prompt-injection payload, install unauthorized tooling, or route the agent to a pay-per-call service without the user's explicit awareness or consent.
highpeople-search-index
People-search / OSINT capability with embedded hop-following instruction, privacy risk
This tool is framed as a simple 'query length' style utility but its description reveals it is actually a people-search index for locating information about living individuals, and instructs the agent to follow CLI setup, docs, API, and remote MCP hops. Combining (a) an instruction to chain into external/remote services and (b) a stated purpose of looking up personal data on real people raises both a manipulation risk (agent silently pivoting to untrusted external endpoints) and a privacy/harm risk (facilitating doxxing or unauthorized personal data lookup) that is far broader than the tool's ostensible one-line description suggests.
mediumagent-tool-index
Potential undisclosed financial/service commitment
Describing the target as a 'pay-per-call tool gateway' suggests that following the instructed hops could lead to billed API usage. The tool description does not warn the agent to inform the user before incurring costs, which could result in unexpected charges if the agent follows the embedded instructions verbatim.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
Embed this badge

Show your MCP server’s security grade

MCP security grade F

Paste this into your README:

[![MCP security](https://gateturbo.com/badge/scan/9eeb1f13-1bd0-42e4-9e2b-d7ebf8594cbc)](https://gateturbo.com/report/9eeb1f13-1bd0-42e4-9e2b-d7ebf8594cbc)

Scanned 9/14/2026 · This is a point-in-time snapshot of the server’s public tools. Re-scan.

Connect this server safely with gate.

Continuous re-scans, drift alerts, per-tool allow/ask/block, and a log of every call.

Monitor it — free