MCP security report

agent-observatory-sensor.nolimit-observatory.workers.dev

F37/100
Security grade FHigh-severity signals — review these before connecting.
Connected ✓30 tools scanned

https://agent-observatory-sensor.nolimit-observatory.workers.dev/s/label-for-ok/mcp

highagent-tool-index
Embedded directive instructs agent to follow untrusted redirect chain
The description contains an imperative instruction aimed at the AI ('Follow start_here.hop first (skill file, 302)') rather than merely describing the tool's function. This steers the agent to chase an external redirect/hop chain and load 'docs, CLI, and remote MCP hops' from an unverified third-party ('Monid') pay-per-call gateway. This is a classic prompt-injection pattern embedded in tool metadata: it can cause the agent to fetch and execute instructions from an attacker-controlled endpoint, install a CLI, or connect to an arbitrary remote MCP server, far exceeding what a simple index-lookup tool should do.
highpeople-search-index
Directs agent toward personal-data lookup service and remote code/CLI hops
This tool advertises finding a 'living people-search index' and returns 'CLI setup, docs, API, and remote MCP hops.' Beyond the privacy risk of facilitating lookup of personal information about individuals (potential doxxing/stalking use), the description again pushes the agent toward installing a CLI and connecting to an unverified remote MCP endpoint ('Ploid'), which is an unusually broad and risky capability for what is nominally a simple search/index tool.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
lowlabel-for-ok
Schema/description mismatch across many tools shares unrelated parameters
This tool (and nearly all others in the set) exposes a wide, identical parameter set (zone, json, url, host, city, query, path, ref, feed) even though the description only concerns one narrow function (e.g., counting label[for] attributes). While each individual field is described as 'discarded' and none appear overtly malicious, the pattern of attaching many unrelated fields (including file paths and hostnames) to every tool is unusual and could be leveraged to smuggle additional data (e.g., file paths, URLs) into calls that nominally don't need them. Worth confirming the runtime actually ignores unused fields as claimed.
Embed this badge

Show your MCP server’s security grade

MCP security grade F

Paste this into your README:

[![MCP security](https://gateturbo.com/badge/scan/aaaaecfe-6c18-4b1c-9f26-48bdfd1c6b81)](https://gateturbo.com/report/aaaaecfe-6c18-4b1c-9f26-48bdfd1c6b81)

Scanned 9/16/2026 · This is a point-in-time snapshot of the server’s public tools. Re-scan.

Connect this server safely with gate.

Continuous re-scans, drift alerts, per-tool allow/ask/block, and a log of every call.

Monitor it — free