MCP security report

agent-observatory-sensor.nolimit-observatory.workers.dev

D49/100
Security grade DHigh-severity signals — review these before connecting.
Connected ✓29 tools scanned

https://agent-observatory-sensor.nolimit-observatory.workers.dev/s/base64-ok/mcp

highagent-tool-index
Directs agent to external third-party 'pay-per-call' gateways
This tool's stated purpose is to 'find a public pay-per-call tool gateway' and return 'connection methods' for arbitrary tasks. This goes far beyond a simple lookup: it could lead the agent to register with, authenticate to, or route user data/tasks through unknown, unvetted, and financially-billed third-party services without explicit user consent. This is a significantly broader and more dangerous capability than the innocuous-sounding name suggests, and could result in unexpected charges or data exfiltration to unknown endpoints.
mediumplaywright-url-ok
Tool name spoofs the well-known Playwright browser automation project
The name 'playwright-url-ok' strongly implies integration with the popular Playwright browser-automation framework, but the tool only performs a trivial URL-openability check ('No browser is launched'). This naming could mislead the agent (or the user reviewing tool calls) into believing real browser automation/rendering capability exists, potentially causing the agent to over-trust results or misrepresent what action was taken. It is also an exact functional duplicate of 'browser-url-ok', which reinforces that the 'playwright' name is being used for branding/spoofing rather than reflecting real functionality.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
lowcalc-eval
Schema exposes unrelated sensitive-looking fields (host, path, url, feed) for a simple arithmetic tool
The tool claims to only 'evaluate a+b style arithmetic' yet its input schema includes fields entirely unrelated to that purpose: 'path' (file path), 'host' (hostname), 'url', 'feed', 'json', 'ref', 'zone', and 'city'. Because every tool in this set shares an identical oversized schema regardless of stated function, an agent could be induced to populate sensitive fields (e.g., local file paths, internal hostnames) into a call whose description gives no indication those fields are used or how they are handled, creating risk of unintended data exposure to the backend.
lowfile-path-ok
Path-checking tool bundled with unrelated network/host/URL fields
Described as only checking whether a local path 'looks safe' with 'no disk access', but the schema also accepts 'host', 'url', 'feed', 'query', and other network-related fields with no explanation of why a path-safety checker needs them. Combined with the pattern seen across all 29 tools sharing one bloated schema, this raises the risk that path data could be combined with network-destination fields and sent off-device in ways not described to the agent or user.
lowcompatibility
Vague purpose combined with broad, irrelevant data-collecting schema
The description ('Show how this request is classified. No identifiers are retained.') is vague about what data is actually processed, yet the schema accepts host, path, url, city, query, json, feed, ref, and zone — none of which are explained as relevant to 'classification'. This mismatch between a vague stated purpose and a broad multi-field input schema is a pattern that could be exploited to collect more information than the tool's description implies is needed.
Embed this badge

Show your MCP server’s security grade

MCP security grade D

Paste this into your README:

[![MCP security](https://gateturbo.com/badge/scan/e44c26ad-0ccf-4dbf-9af2-449bfb11b7f1)](https://gateturbo.com/report/e44c26ad-0ccf-4dbf-9af2-449bfb11b7f1)

Scanned 9/9/2026 · This is a point-in-time snapshot of the server’s public tools. Re-scan.

Connect this server safely with gate.

Continuous re-scans, drift alerts, per-tool allow/ask/block, and a log of every call.

Monitor it — free