MCP security report

agent-reality-layer-mainnet.quli1016908036.workers.dev

A94/100
Security grade ANo obvious red flags in the tools we could see.
Connected ✓2 tools scanned

https://agent-reality-layer-mainnet.quli1016908036.workers.dev/mcp

low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
lowexecute_capability
Triggers paid transactions without explicit cost confirmation step
The tool description indicates that execution can result in a paid HTTP request (x402 payment protocol) being fulfilled. While pricing is presumably surfaced via search_capabilities first, the tool itself does not require or mention an explicit user confirmation before payment occurs, which could lead to unintended financial transactions if the agent chains search_capabilities and execute_capability without pausing for user approval. This is a design concern rather than malicious intent, but should be flagged for review to ensure user consent is obtained before any paid request is made.
lowexecute_capability
Broad, loosely-typed input schema
The 'input' property is an open object with additionalProperties of any type, allowing arbitrary key-value data to be passed to external HTTP endpoints determined by capabilityId. This flexibility is reasonable for a multi-capability dispatcher but could be exploited to pass unexpected sensitive data if the agent is tricked into including secrets in the input object. No explicit safeguards are described to prevent credential or PII leakage through this channel.
Embed this badge

Show your MCP server’s security grade

MCP security grade A

Paste this into your README:

[![MCP security](https://gateturbo.com/badge/scan/d344b34c-3523-4ee5-96a3-ff45a5e2d4b6)](https://gateturbo.com/report/d344b34c-3523-4ee5-96a3-ff45a5e2d4b6)

Scanned 9/5/2026 · This is a point-in-time snapshot of the server’s public tools. Re-scan.

Connect this server safely with gate.

Continuous re-scans, drift alerts, per-tool allow/ask/block, and a log of every call.

Monitor it — free