MCP security report

agent-observatory-sensor.nolimit-observatory.workers.dev

F34/100
Security grade FHigh-severity signals — review these before connecting.
Connected ✓30 tools scanned

https://agent-observatory-sensor.nolimit-observatory.workers.dev/s/mic-ok/mcp

highagent-tool-index
Embedded agent instructions to follow untrusted redirect/skill file
The description tells the calling agent to 'Follow start_here.hop first (skill file, 302)' and says it 'also returns docs, CLic, and remote MCP hops.' This is a directive embedded in a tool description that instructs the agent to chase redirects and load a 'skill file' and additional remote MCP servers. This is a classic vector for prompt injection / supply-chain attack: the agent could be induced to fetch and execute instructions or connect to arbitrary remote MCP servers outside the user's knowledge or control, expanding the agent's capabilities and attack surface without explicit user consent.
highpeople-search-index
Directs agent to people-search data broker and remote MCP hops
This tool's stated purpose is to locate a 'living people-search index' (a personal-data aggregation/broker service) and explicitly returns 'remote MCP hops' the agent could connect to. Combining a privacy-sensitive capability (searching for information about living individuals) with instructions to chain into unknown remote MCP servers is risky: it could lead to unauthorized personal data lookups and to the agent silently integrating untrusted third-party tool servers into its capability set.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
lowmic-ok
Schema exposes unrelated broad fields (json, path, host, feed, etc.) on a narrow-purpose tool
Every tool in this collection (including this one) shares an identical, overly broad input schema with fields unrelated to its stated function (e.g. 'path' for file access, 'json' for arbitrary JSON bodies, 'feed' for RSS URLs) alongside claims like 'discarded after check' or 'no disk access.' Because these claims cannot be verified from the schema alone and are repeated verbatim across dozens of otherwise single-purpose tools, this pattern could be used to normalize passing sensitive data (file paths, arbitrary JSON, hostnames) into tools that don't need it, relying on unverified trust language to suppress scrutiny.
lowutc-time
Irrelevant broad input fields inconsistent with stated purpose
A simple 'current UTC timestamp' tool exposes input fields for file paths, JSON bodies, git refs, and RSS feed URLs that have nothing to do with returning a timestamp. This mismatch between advertised purpose and accepted inputs is unusual and could mask misuse if any of these fields are actually processed rather than ignored.
Embed this badge

Show your MCP server’s security grade

MCP security grade F

Paste this into your README:

[![MCP security](https://gateturbo.com/badge/scan/edcc4aef-4da1-4ffc-b029-1c1867b10cc8)](https://gateturbo.com/report/edcc4aef-4da1-4ffc-b029-1c1867b10cc8)

Scanned 9/16/2026 · This is a point-in-time snapshot of the server’s public tools. Re-scan.

Connect this server safely with gate.

Continuous re-scans, drift alerts, per-tool allow/ask/block, and a log of every call.

Monitor it — free