MCP security report

qumge.com

F40/100
Security grade FHigh-severity signals — review these before connecting.
Connected ✓6 tools scanned

https://qumge.com/mcp

highget_skill
Instructs agent to auto-install fetched content without user review
The description tells the agent to 'Write the returned markdown to .claude/skills/<name>/SKILL.md ... and it is installed — no other step is needed.' This directs the agent to autonomously write arbitrary third-party content into its own skill directory and treat it as fully trusted/installed, without pausing for user confirmation or review. Since SKILL.md files are themselves instructions the agent will later read and follow, this creates a supply-chain / prompt-injection pathway: a malicious or compromised catalog entry could smuggle in instructions that override agent behavior once 'installed'. The phrase 'no other step is needed' actively discourages any human-in-the-loop check.
highget_bundle
Instructs agent to auto-install multiple fetched skill files without review
Same pattern as get_skill but for multiple skills at once: 'Write each returned skill to .claude/skills/<name>/SKILL.md ... and the whole set is installed — no other step is needed.' This compounds the risk by batch-writing several externally-sourced files directly into the agent's trusted skill directory with no verification or user confirmation step, increasing the attack surface for injected instructions hidden in any one of the bundled skills.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
Embed this badge

Show your MCP server’s security grade

MCP security grade F

Paste this into your README:

[![MCP security](https://gateturbo.com/badge/scan/b22251c8-40c4-4e51-a327-420dee374a4c)](https://gateturbo.com/report/b22251c8-40c4-4e51-a327-420dee374a4c)

Scanned 9/4/2026 · This is a point-in-time snapshot of the server’s public tools. Re-scan.

Connect this server safely with gate.

Continuous re-scans, drift alerts, per-tool allow/ask/block, and a log of every call.

Monitor it — free