MCP security report

canarics.com

D61/100
Security grade DA few things are worth a closer look before connecting.
Connected ✓2 tools scanned

https://canarics.com/mcp

mediumstart_signup
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumcheck_signup_status
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumcheck_signup_status
API key handed to agent and reused as Bearer credential across endpoints
The description instructs the agent to 'store' the one-time API key and use it as a Bearer token for all other Canarics tools and the /api/v1 endpoint. This creates a pattern where a sensitive credential is captured by the AI agent and persisted/reused autonomously across sessions and endpoints. There's no indication of how the key is stored securely or that the user consents to the agent holding and reusing this credential. This is a broader capability (credential custodianship and reuse) than a simple status-check tool would normally require, and could enable the agent to make authenticated calls without explicit per-action user approval.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
lowstart_signup
Claim URL sent to a third party contact
The tool sends a claim URL to 'the person responsible' via contactEmail, which involves transmitting a signup/claim link to an external party. This is consistent with the tool's stated purpose (onboarding a real company contact), but the agent should verify the contactEmail is legitimate and user-approved before invoking, since it results in an external communication/action taken on behalf of the user without further confirmation described in the flow.'
Embed this badge

Show your MCP server’s security grade

MCP security grade D

Paste this into your README:

[![MCP security](https://gateturbo.com/badge/scan/a11c11ae-acdd-4ea9-84c4-4a255fc77249)](https://gateturbo.com/report/a11c11ae-acdd-4ea9-84c4-4a255fc77249)

Scanned 9/12/2026 · This is a point-in-time snapshot of the server’s public tools. Re-scan.

Connect this server safely with gate.

Continuous re-scans, drift alerts, per-tool allow/ask/block, and a log of every call.

Monitor it — free