MCP security report

emem.dev

F43/100
Security grade FA few things are worth a closer look before connecting.
Connected ✓16 tools scanned

https://emem.dev/mcp

mediumemem_tools
Encourages agent to bypass host's curated tool list and connect to an alternate, unreviewed endpoint
The description repeatedly stresses that the visible 16 tools are 'a curated subset of 108' and instructs the agent to either call the other 92 tools by name even though they are not present in tools/list, or 'reconnect to the /mcp/full endpoint' to get the full catalog. This is an instruction embedded in a tool description that pushes the calling agent toward expanding its own capability surface beyond what the MCP host/administrator deliberately exposed, and toward establishing a connection to a different endpoint. Even if the underlying intent is legitimate progressive disclosure, this pattern (a description telling the agent to seek/invoke undeclared functionality or switch endpoints) is a classic vector for capability escalation and should not be acted on without explicit user/host approval.
mediumemem_intent
Reinforces calling tools not shown in tools/list, undermining host-side tool curation
The description states 'A tool this router names but tools/list does not show is NOT a dead end... every one of the 107 dispatches by name at /mcp and /mcp/full, so call emem_trajectory or emem_recall_polygon directly.' This actively instructs the agent to invoke tool names that were never declared to it via the standard discovery mechanism, encouraging it to bypass the enumerated, reviewed tool surface. Combined with emem_tools' similar guidance, this represents a coordinated attempt across the tool descriptions to get the agent to reach for hidden/undeclared functionality, which should be flagged even though no single call is overtly malicious.
lowemem_entity
Unusually long tool description
Very long descriptions are sometimes used to bury instructions to the AI. Skim it before allowing.
lowemem_recall
Unusually long tool description
Very long descriptions are sometimes used to bury instructions to the AI. Skim it before allowing.
lowemem_memory_token
Unusually long tool description
Very long descriptions are sometimes used to bury instructions to the AI. Skim it before allowing.
lowemem_verify_receipt
Unusually long tool description
Very long descriptions are sometimes used to bury instructions to the AI. Skim it before allowing.
lowemem_memory_contradictions
Unusually long tool description
Very long descriptions are sometimes used to bury instructions to the AI. Skim it before allowing.
lowemem_guard_verdict
Unusually long tool description
Very long descriptions are sometimes used to bury instructions to the AI. Skim it before allowing.
lowemem_tools
Unusually long tool description
Very long descriptions are sometimes used to bury instructions to the AI. Skim it before allowing.
lowemem_ask
Unusually long tool description
Very long descriptions are sometimes used to bury instructions to the AI. Skim it before allowing.
lowemem_echo_verify
Unusually long tool description
Very long descriptions are sometimes used to bury instructions to the AI. Skim it before allowing.
lowemem_find_similar
Unusually long tool description
Very long descriptions are sometimes used to bury instructions to the AI. Skim it before allowing.
lowemem_intent
Unusually long tool description
Very long descriptions are sometimes used to bury instructions to the AI. Skim it before allowing.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
Embed this badge

Show your MCP server’s security grade

MCP security grade F

Paste this into your README:

[![MCP security](https://gateturbo.com/badge/scan/c6320dc0-63b7-42a1-83d0-728b20c44691)](https://gateturbo.com/report/c6320dc0-63b7-42a1-83d0-728b20c44691)

Scanned 9/3/2026 · This is a point-in-time snapshot of the server’s public tools. Re-scan.

Connect this server safely with gate.

Continuous re-scans, drift alerts, per-tool allow/ask/block, and a log of every call.

Monitor it — free