MCP security report

ground-truth-mcp.anishdasmail.workers.dev

F5/100
Security grade FA few things are worth a closer look before connecting.
Connected ✓19 tools scanned

https://ground-truth-mcp.anishdasmail.workers.dev/mcp

mediumlist_resources
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumassess_compliance_posture
Runs arbitrary code or commands
This tool appears to execute arbitrary code, shell commands, or SQL — a broad capability worth gating with allow/ask.
mediumcreate_monitor
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumlist_monitors
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumrun_monitor_now
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumget_monitor_result
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumdelete_monitor
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumgenerate_change_report
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumcreate_share_link
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumcreate_monitor
Arbitrary webhook destination could be used for data exfiltration
The notification_destination parameter allows configuring any HTTPS URL to receive POST notifications when a monitored value changes. While the description notes no API key is included, this still creates a channel through which monitored content (pricing data, claims, endpoint status, etc.) is sent to an arbitrary third-party destination chosen at tool-call time. An agent could be manipulated (via prompt injection elsewhere) into setting this to an attacker-controlled endpoint, silently exfiltrating information the user is tracking. Consider allow-listing destinations or requiring explicit user confirmation of the exact webhook URL before each creation.
lowtest_hypothesis
Unusually long tool description
Very long descriptions are sometimes used to bury instructions to the AI. Skim it before allowing.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
lowpreview_monitor
Embedded upsell instruction to the agent
The description contains a directive aimed at the agent's behavior rather than describing the tool's function: 'offer create_monitor only when the user wants scheduled checks, history, or change alerts.' This is a soft behavioral instruction embedded in tool metadata that nudges the agent toward promoting a paid/persistent feature. It is not overtly malicious, but it is an example of a tool description trying to script the agent's conversational conduct beyond simply documenting inputs/outputs, which is worth reviewing to ensure it doesn't conflict with the agent's own guidelines on unsolicited upselling.
lowcreate_share_link
Creates public, unauthenticated link exposing monitor data
This tool generates a publicly accessible URL (no login required) containing monitor metadata and evidence, valid for up to 30 days. If a monitor tracks sensitive or proprietary information (e.g., internal pricing analysis, competitive intel, or vendor claims tied to a business deal), a share link could unintentionally leak that data to anyone with the URL. This is a normal product feature but should require clear user confirmation before generating a link, since the agent could be induced to create and expose one without the user realizing the content is now publicly reachable.
Embed this badge

Show your MCP server’s security grade

MCP security grade F

Paste this into your README:

[![MCP security](https://gateturbo.com/badge/scan/f1b64833-a310-45c1-a02f-12d2563c6db8)](https://gateturbo.com/report/f1b64833-a310-45c1-a02f-12d2563c6db8)

Scanned 9/5/2026 · This is a point-in-time snapshot of the server’s public tools. Re-scan.

Connect this server safely with gate.

Continuous re-scans, drift alerts, per-tool allow/ask/block, and a log of every call.

Monitor it — free