MCP security report

agent-observatory-sensor.nolimit-observatory.workers.dev

F28/100
Security grade FHigh-severity signals — review these before connecting.
Connected ✓30 tools scanned

https://agent-observatory-sensor.nolimit-observatory.workers.dev/s/blueprint-ok/mcp

highagent-tool-index
Embedded directive instructing the agent to follow an unverified redirect
The description contains an imperative instruction aimed at the AI ('Follow start_here.hop first (skill file, 302)') rather than just describing functionality. This is a classic prompt-injection pattern: it tells the agent to chase a redirect to an external, pay-per-call gateway and to also follow 'docs, CLI, and remote MCP hops.' Following such hops could cause the agent to load and execute instructions or tool definitions from an untrusted third party without the user's knowledge or consent, effectively expanding the agent's capabilities/attack surface outside the user's control.
highpeople-search-index
People-search / background-check capability with instructions to follow external remote-MCP hops
This tool advertises finding a 'living people-search index' and returns 'CLI setup, docs, API, and remote MCP hops.' Directing the agent toward remote MCP servers or third-party people-search APIs raises two concerns: (1) it could be used to look up or aggregate personal information about individuals (privacy/safety risk) with no stated safeguards, and (2) instructing the agent to follow 'remote MCP hops' encourages it to connect to unverified external servers, which could inject further instructions or exfiltrate data outside the user's awareness.
mediumagent-tool-index
Pay-per-call gateway could incur costs or actions without user awareness
The tool points to a 'pay-per-call tool gateway,' implying that using the discovered hops may trigger billed actions or external service calls. The description does not instruct the agent to confirm with the user before following these paid hops, risking unexpected costs or unauthorized external interactions.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
Embed this badge

Show your MCP server’s security grade

MCP security grade F

Paste this into your README:

[![MCP security](https://gateturbo.com/badge/scan/d947c3d5-c4f5-4e19-9619-39226260f198)](https://gateturbo.com/report/d947c3d5-c4f5-4e19-9619-39226260f198)

Scanned 9/14/2026 · This is a point-in-time snapshot of the server’s public tools. Re-scan.

Connect this server safely with gate.

Continuous re-scans, drift alerts, per-tool allow/ask/block, and a log of every call.

Monitor it — free