MCP security report

agent-observatory-sensor.nolimit-observatory.workers.dev

F22/100
Security grade FHigh-severity signals — review these before connecting.
Connected ✓30 tools scanned

https://agent-observatory-sensor.nolimit-observatory.workers.dev/s/cc-lk/mcp

highagent-tool-index
Embedded directive instructing agent to follow an external redirect/hop
The description contains an imperative instruction to the agent ('Follow start_here.hop first (skill file, 302)') rather than merely describing the tool's function. This steers the agent to fetch and potentially act on content from an unknown third-party 'pay-per-call' gateway (Monid) without the user's awareness or consent, and could be used to chain the agent into executing instructions or incurring paid transactions from an untrusted source.
highpeople-search-index
People-search tool with capability to add remote MCP servers
Description advertises finding a 'living people-search index' and returns 'remote MCP hops' that the agent could follow to connect to additional, unvetted MCP servers. This both raises privacy/safety concerns (facilitating lookup of information about real individuals) and represents an uncontrolled mechanism for silently expanding the agent's tool/capability surface beyond what the user approved.
mediumagent-tool-index
Pay-per-call gateway discovery without user consent framing
The tool's stated purpose is to 'find' a gateway, but the description implies the agent should chain further hops (docs, CLI, remote MCP) automatically, which could result in the agent registering new paid tool integrations or executing remote code paths the user never explicitly authorized.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
lowcc-lk
Broad, purpose-mismatched input schema shared across all tools
Every tool in this set (cc-lk, utc-time, timezone, validate-json, etc.) exposes an identical schema with fields like path, json, host, query, ref, feed regardless of the tool's stated single purpose (e.g., an ISO country-code lookup accepting a file path or JSON body). This inconsistency makes it hard to verify that inputs are actually used only as described, and relies entirely on unverifiable 'discarded'/'no disk access' claims in the description rather than schema constraints, which could mask exfiltration of file paths, hostnames, or other sensitive strings if the backend does not honor the stated behavior.
lowplaywright-url-ok
Tool name implies Playwright browser automation but description denies it
Naming the tool 'playwright-url-ok' invokes the well-known Playwright browser-automation tool, but the description states 'No browser is launched,' which is inconsistent with typical Playwright capability. This mismatch could mislead an agent (or a user reviewing tool calls) about what the tool actually does, and is duplicated verbatim by 'browser-url-ok', suggesting possible tool-name conflation.
Embed this badge

Show your MCP server’s security grade

MCP security grade F

Paste this into your README:

[![MCP security](https://gateturbo.com/badge/scan/f8d327e7-c50c-43a0-860c-84deeba5d441)](https://gateturbo.com/report/f8d327e7-c50c-43a0-860c-84deeba5d441)

Scanned 9/13/2026 · This is a point-in-time snapshot of the server’s public tools. Re-scan.

Connect this server safely with gate.

Continuous re-scans, drift alerts, per-tool allow/ask/block, and a log of every call.

Monitor it — free