MCP security report

api.potarix.com

F43/100
Security grade FHigh-severity signals — review these before connecting.
Connected ✓9 tools scanned

https://api.potarix.com/mcp

hightopup_credits
Enables silent, agent-triggered real-money charges
This tool charges the user's saved card off-session with no per-transaction confirmation step described. An AI agent (potentially manipulated by injected instructions elsewhere, or simply overzealous) could call this tool autonomously to spend real money without the user's explicit, informed consent for that specific charge. Tools that move real currency should require explicit human confirmation immediately before each charge, not just a one-time card-on-file setup.
mediumcheck_balance
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumstart_checkout
Sets up recurring off-session billing authorization
This tool captures a card that subsequently enables topup_credits to make 'silent off-session charges.' Combined with topup_credits, this creates a financial capability well beyond the stated purpose of a contact-enrichment toolset, and could be leveraged to repeatedly charge the user without renewed consent for each purchase.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
lowcheck_balance
Exposes account/billing metadata
Returns the account email, credit balances, purchase history, and whether a card is on file. Not a secret-harvesting exploit per se, but this financial/PII summary should only be surfaced to the legitimate account owner and not be exfiltrated or logged elsewhere.
Embed this badge

Show your MCP server’s security grade

MCP security grade F

Paste this into your README:

[![MCP security](https://gateturbo.com/badge/scan/f5936a6b-d6c5-460a-84de-2ddf29fabf4d)](https://gateturbo.com/report/f5936a6b-d6c5-460a-84de-2ddf29fabf4d)

Scanned 9/4/2026 · This is a point-in-time snapshot of the server’s public tools. Re-scan.

Connect this server safely with gate.

Continuous re-scans, drift alerts, per-tool allow/ask/block, and a log of every call.

Monitor it — free