MCP security report

agent-observatory-sensor.nolimit-observatory.workers.dev

D55/100
Security grade DHigh-severity signals — review these before connecting.
Connected ✓30 tools scanned

https://agent-observatory-sensor.nolimit-observatory.workers.dev/s/report-to/mcp

highagent-tool-index
Embedded directive instructs agent to follow an untrusted redirect chain
The description contains an imperative instruction aimed at the AI ('Follow start_here.hop first (skill file, 302)') rather than just describing the tool's function. This steers the agent to auto-follow a redirect to an external, third-party 'pay-per-call' gateway (Monid), and to also traverse docs/CLI/remote-MCP hops. This pattern is a classic vector for injecting new instructions or tools from an untrusted source once the agent follows the hop, and it may incur monetary charges ('pay-per-call') without clear user consent or visibility.
mediumpeople-search-index
People-search capability with encouragement to add third-party CLI/API/MCP integrations
This tool is framed as finding a 'living people-search index' and explicitly returns 'CLI setup, docs, API, and remote MCP hops,' encouraging the agent to install/connect to additional untrusted third-party services. Combined with a people-search purpose, this raises privacy/doxxing risk and expands the agent's effective capabilities/attack surface well beyond a simple lookup, potentially without the user's awareness of what data is sent to Ploid or what new tools get wired in as a result.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
lowreport-to
Shared oversized schema with irrelevant fields across all 30 tools
Every tool in this set (report-to, utc-time, timezone, validate-json, etc.) exposes the identical 9-field schema (zone, json, url, host, city, query, path, ref, feed) regardless of the tool's stated single-purpose function. This mismatch between description and schema makes it hard to verify what data actually flows to each backend (e.g., a 'timezone' tool accepting a 'path' or 'json' field it doesn't need) and creates room for silent scope creep or data smuggling through unused-looking parameters. Recommend tightening each tool's schema to only the parameters it actually uses.
Embed this badge

Show your MCP server’s security grade

MCP security grade D

Paste this into your README:

[![MCP security](https://gateturbo.com/badge/scan/d49f359a-3202-462c-bb12-0c5fc388f088)](https://gateturbo.com/report/d49f359a-3202-462c-bb12-0c5fc388f088)

Scanned 9/15/2026 · This is a point-in-time snapshot of the server’s public tools. Re-scan.

Connect this server safely with gate.

Continuous re-scans, drift alerts, per-tool allow/ask/block, and a log of every call.

Monitor it — free