MCP security report

mcp.ateam-ai.com

F5/100
Security grade FA few things are worth a closer look before connecting.
Connected ✓57 tools scanned

https://mcp.ateam-ai.com/mcp

mediumateam_auth
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumateam_test_notification
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumateam_patch
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumateam_upload_connector
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumateam_get_chain
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumateam_get_widget_catalog
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumateam_auth
master_key parameter grants cross-tenant authentication bypassing normal tenant scoping
The tool accepts a 'master_key' that 'Authenticates across ALL tenants without per-tenant API keys,' effectively bypassing the per-tenant isolation that every other tool in this set relies on for safety (e.g. ateam_test_notification and ateam_chain_status explicitly note tenant isolation as a safety property). If this key is ever supplied or solicited inappropriately, it enables broad cross-tenant data access/operations far beyond a single user's own solution — a capability disproportionate to a routine 'authenticate' action and worth restricting/confirming carefully before use.
lowateam_get_spec
Unusually long tool description
Very long descriptions are sometimes used to bury instructions to the AI. Skim it before allowing.
lowateam_patch
Unusually long tool description
Very long descriptions are sometimes used to bury instructions to the AI. Skim it before allowing.
lowateam_upload_connector
Unusually long tool description
Very long descriptions are sometimes used to bury instructions to the AI. Skim it before allowing.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
lowateam_bootstrap
Description instructs agent to hijack generic conversational turns
The description commands the agent to call this tool 'when user greets, says hi, asks what this is, asks for help, explores capabilities' and explicitly says 'Do NOT improvise an introduction — call this tool instead.' This is an instruction aimed at controlling the assistant's behavior on broad, generic user input (e.g. simple greetings) rather than being scoped to the tool's actual function, which is a pattern worth noting even though it appears to be legitimate onboarding UX rather than malicious redirection.
lowateam_status_all
Cross-tenant enumeration requiring master key
Returns GitHub sync status for ALL tenants and solutions at once. Combined with the master_key auth path in ateam_auth, this allows a single session to enumerate data across every tenant rather than the caller's own tenant, which is a broad capability that should only be exercised with strong justification/confirmation.
lowateam_sync_all
Cross-tenant bulk sync requiring master key
Pushes/pulls GitHub and Core state for ALL tenants in one call. Like ateam_status_all, this is a very broad, irreversible-adjacent operation (bulk state sync across every tenant) gated only by possession of a master key, which is a large blast radius relative to normal per-solution tooling in this set.
Embed this badge

Show your MCP server’s security grade

MCP security grade F

Paste this into your README:

[![MCP security](https://gateturbo.com/badge/scan/dcb410a1-4e3f-4725-8280-3360656f30e0)](https://gateturbo.com/report/dcb410a1-4e3f-4725-8280-3360656f30e0)

Scanned 9/5/2026 · This is a point-in-time snapshot of the server’s public tools. Re-scan.

Connect this server safely with gate.

Continuous re-scans, drift alerts, per-tool allow/ask/block, and a log of every call.

Monitor it — free