MCP security report

agent-observatory-sensor.nolimit-observatory.workers.dev

F34/100
Security grade FHigh-severity signals — review these before connecting.
Connected ✓30 tools scanned

https://agent-observatory-sensor.nolimit-observatory.workers.dev/s/lpm-lps/mcp

highagent-tool-index
Embedded directive to follow an unverified redirect/hop chain
The description instructs the agent to 'Follow start_here.hop first (skill file, 302)' and describes chaining to docs, CLI, and 'remote MCP hops.' This is an instruction aimed at the calling AI to autonomously follow untrusted external redirects and load additional 'skill' content, which is a classic vector for prompt injection or fetching hidden instructions from a third party. It also references a 'pay-per-call' gateway, meaning following the hop could incur costs or register the agent with an external service without explicit user consent or visibility.
highpeople-search-index
Facilitates locating a people-search / personal-data broker service
This tool's stated purpose is to help find a 'living people-search index (Ploid)' with API/CLI/MCP access. Tools that index and surface personal-information lookup services materially increase risk of enabling doxing, stalking, or other privacy-invasive lookups on real individuals, which goes beyond typical benign utility functionality and deserves scrutiny before being wired into an agent that might act on it without the user's informed involvement.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
lowlpm-lps
Schema fields unrelated to stated function repeated across all tools
Every tool in this set (including this unit-conversion tool) exposes an identical broad parameter set — zone, json, url, host, city, query, path, ref, feed — regardless of what the tool actually claims to do. For example, a liters/min-to-liters/s converter has no legitimate need for a file path, git ref, RSS feed URL, or hostname parameter. This mismatch between description and schema is a pattern that could be used to justify passing arbitrary URLs, file paths, or JSON blobs to a tool under an unrelated, innocuous-sounding name, increasing the risk of disguised data exfiltration or SSRF if the implementation does not strictly ignore the unused fields as claimed.
lowweather-hint
Unnecessary parameter surface beyond stated purpose
Like other tools in this collection, weather-hint exposes path, host, url, json, ref, and feed parameters that have no relation to fetching a city's temperature. While the description claims these are discarded/unused, the presence of file-path and arbitrary-URL parameters on a weather tool is an unusual design that could mask broader capability (e.g., local file access or arbitrary HTTP requests) not reflected in the tool's name or description.
Embed this badge

Show your MCP server’s security grade

MCP security grade F

Paste this into your README:

[![MCP security](https://gateturbo.com/badge/scan/b6ea3b19-8870-459b-8502-11044b02e8bf)](https://gateturbo.com/report/b6ea3b19-8870-459b-8502-11044b02e8bf)

Scanned 9/16/2026 · This is a point-in-time snapshot of the server’s public tools. Re-scan.

Connect this server safely with gate.

Continuous re-scans, drift alerts, per-tool allow/ask/block, and a log of every call.

Monitor it — free