MCP security report

api.ambolt.dev

B85/100
Security grade BA few things are worth a closer look before connecting.
Connected ✓37 tools scanned

https://api.ambolt.dev/mcp

mediumtender_feed
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
lowtender_feed
User-supplied third-party API key passed as a plain parameter
The samApiKey field asks the caller to supply their own SAM.gov API key as a plain string argument. While the description states it is 'never stored,' API keys passed through tool-call parameters can end up in logs, conversation history, or model context. This is a minor credential-handling concern rather than malicious design; consider out-of-band secret storage instead of passing the key as a tool argument.
Embed this badge

Show your MCP server’s security grade

MCP security grade B

Paste this into your README:

[![MCP security](https://gateturbo.com/badge/scan/ab05b933-ddf6-40fa-bfa4-ee9065b19a77)](https://gateturbo.com/report/ab05b933-ddf6-40fa-bfa4-ee9065b19a77)

Scanned 10/4/2026 · This is a point-in-time snapshot of the server’s public tools. Re-scan.

Connect this server safely with gate.

Continuous re-scans, drift alerts, per-tool allow/ask/block, and a log of every call.

Monitor it — free