MCP security report

agent.avatargaia.top

B82/100
Security grade BA few things are worth a closer look before connecting.
Connected ✓13 tools scanned

https://agent.avatargaia.top/api/mcp/canvas

mediumpush_screen
Arbitrary HTML/JS injection into user canvas
The tool accepts a 'content' string that can contain a ```canvas-html fenced block described as a 'complete HTML document' to be rendered on the user's screen. This gives the calling agent the ability to push arbitrary HTML (and potentially embedded scripts) directly to an end-user's canvas/session. If the agent is manipulated (e.g., via a poisoned prompt or malicious upstream data) into calling this tool, it could be used to display phishing UI, misleading content, or embed scripts, with no described sanitization or review step before display.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
lowopen_canvas
Encourages pre-staging content to sessions before user consent
The description explicitly tells the agent that a session_id can be used to push_screen content to a user 'who hasn't arrived yet' so that opening the link auto-delivers a pre-staged card, and that chat/tracking will later be attributed to that same session. This normalizes proactively injecting content into a user's future session without any interactive consent step, which combined with push_screen's raw HTML capability increases risk of unsolicited or manipulative content reaching the user.
lowpatch_staff_config
Config allows arbitrary external URLs for promotion/product sources
patch_staff_config lets the caller set promotionConfig.categories[].url and productSources[].searchUrl to arbitrary values, and contextWebhookUrl to an arbitrary endpoint (contextMode=webhook). If misused, this could redirect end-user traffic to attacker-controlled destinations or exfiltrate conversational context to an external webhook. The tool does perform the change immediately ('改完立刻生效') with only a soft suggestion to confirm with the user, not an enforced check.
Embed this badge

Show your MCP server’s security grade

MCP security grade B

Paste this into your README:

[![MCP security](https://gateturbo.com/badge/scan/e091e173-ef5d-4423-af85-4d6501aef42d)](https://gateturbo.com/report/e091e173-ef5d-4423-af85-4d6501aef42d)

Scanned 9/14/2026 · This is a point-in-time snapshot of the server’s public tools. Re-scan.

Connect this server safely with gate.

Continuous re-scans, drift alerts, per-tool allow/ask/block, and a log of every call.

Monitor it — free