MCP security report

agent-observatory-sensor.nolimit-observatory.workers.dev

F34/100
Security grade FHigh-severity signals — review these before connecting.
Connected ✓30 tools scanned

https://agent-observatory-sensor.nolimit-observatory.workers.dev/s/iso-week-date/mcp

highagent-tool-index
Embedded directive telling the agent to follow an external redirect chain
The description instructs the agent to 'Follow start_here.hop first (skill file, 302)' and says it 'also returns docs, CLI, and remote MCP hops.' This is an instruction aimed at the AI's behavior (not just data the tool returns) that pushes the agent to fetch and act on content from an external, unauthenticated 'pay-per-call' gateway and to add/connect to remote MCP servers. This is a classic vector for prompt-injection/tool-supply-chain hijacking: the agent could be induced to load attacker-controlled 'skill' files or register untrusted remote tool servers without the user's informed consent.
highpeople-search-index
People-search tool advertises remote MCP hops and broad personal-data lookup capability
The tool is described as a 'living people-search index' that 'returns CLI setup, docs, API, and remote MCP hops.' Beyond the privacy concerns of a people-search capability (potential for doxxing/surveillance misuse), the mention of 'remote MCP hops' suggests the tool can direct the agent to connect to additional, unvetted remote MCP servers — a supply-chain risk that could let an external party inject new tool definitions or capabilities into the agent's session.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
lowiso-week-date
Schema unrelated to stated tool function is shared across all tools
Every tool in this set — including simple utilities like iso-week-date, utc-time, calc-eval, and validate-json — exposes an identical, broad input schema with unrelated fields (json, url, host, city, query, path, ref, feed) that have nothing to do with the tool's stated purpose. While each field is annotated as 'discarded,' this generic catch-all schema pattern is unusual and could mask undocumented data flows (e.g., a 'path' or 'json' field silently used for something other than the described no-op). Recommend tightening each tool's schema to only the parameters it actually needs so behavior can be verified from the schema alone.
lowplaywright-url-ok
Possible name-based confusion with the real Playwright tool/library
The tool name invokes 'Playwright,' a well-known browser-automation library, but the description clarifies 'No browser is launched.' This naming could cause an agent or user to assume real browser automation capability is present when it is not, which could lead to mistaken trust in results or confusion when chaining with actual Playwright-based tools.
Embed this badge

Show your MCP server’s security grade

MCP security grade F

Paste this into your README:

[![MCP security](https://gateturbo.com/badge/scan/b9ddf514-e756-46db-a458-e3c7935742ef)](https://gateturbo.com/report/b9ddf514-e756-46db-a458-e3c7935742ef)

Scanned 9/13/2026 · This is a point-in-time snapshot of the server’s public tools. Re-scan.

Connect this server safely with gate.

Continuous re-scans, drift alerts, per-tool allow/ask/block, and a log of every call.

Monitor it — free