MCP security report

stackfast.ai

F5/100
Security grade FA few things are worth a closer look before connecting.
Connected ✓74 tools scanned

https://stackfast.ai/api/mcp

mediumcredentials_inventory
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumdealership_sales_floor_brief
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumcogentcast_package_preview
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumcogentcast_package_create
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumcogentcast_production_run
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumcogentcast_production_status
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumcogentcast_approval_resolve
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumtalent_scout_my_profile_upsert
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumtalent_scout_profile_upsert
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumtalent_scout_my_profile_status
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumtalent_scout_profile_status
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumtalent_scout_reconcile_application_history
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumtalent_scout_set_search_rails
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumtalent_scout_upsert_campaign_profile
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumtalent_scout_discover_companies_by_campaign
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumtalent_scout_discover_local_companies
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumtalent_scout_scan_company_for_roles
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumtalent_scout_person_research_notes
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumtalent_scout_business_email_receipt
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumtalent_scout_draft_manual_note
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumtalent_scout_record_manual_note
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumtalent_scout_record_relationship_activity
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumtalent_scout_correct_relationship_activity
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumboot_status
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
lowdealership_check_lead_follow_up
Unusually long tool description
Very long descriptions are sometimes used to bury instructions to the AI. Skim it before allowing.
lowcogentcast_package_preview
Unusually long tool description
Very long descriptions are sometimes used to bury instructions to the AI. Skim it before allowing.
lowcogentcast_package_create
Unusually long tool description
Very long descriptions are sometimes used to bury instructions to the AI. Skim it before allowing.
lowtalent_scout_my_profile_upsert
Unusually long tool description
Very long descriptions are sometimes used to bury instructions to the AI. Skim it before allowing.
lowtalent_scout_profile_upsert
Unusually long tool description
Very long descriptions are sometimes used to bury instructions to the AI. Skim it before allowing.
lowtalent_scout_upsert_campaign_profile
Unusually long tool description
Very long descriptions are sometimes used to bury instructions to the AI. Skim it before allowing.
lowtalent_scout_record_manual_note
Unusually long tool description
Very long descriptions are sometimes used to bury instructions to the AI. Skim it before allowing.
lowtalent_scout_compose_application
Unusually long tool description
Very long descriptions are sometimes used to bury instructions to the AI. Skim it before allowing.
lowvoice_intelligence_run
Unusually long tool description
Very long descriptions are sometimes used to bury instructions to the AI. Skim it before allowing.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
lowtalent_scout_review_queue
Embedded directive constraining agent tool choice
The description contains an imperative aimed at the AI agent ('Clients MUST NOT invoke their own Gmail/email connector; ... surface the red receipt and stop') rather than purely describing the tool's function. While the apparent intent is to prevent stale/unauthorized mailbox reads via a different connector, this is a behavioral instruction embedded in a tool description that attempts to steer the agent's use of other tools, which is a pattern worth flagging even when benign in intent.
lowtalent_scout_daily_pipeline
Embedded directive constraining agent tool choice
Same pattern as talent_scout_review_queue: the description instructs the agent to avoid invoking a client-side Gmail/email connector and to stop instead, which is an instruction to the AI about tool usage beyond describing this tool's own inputs/outputs.
lowcredentials_inventory
Credential enumeration helper
This tool is explicitly designed to enumerate credential/service names, aliases, and env-var mappings for an agent that is 'unsure whether a key exists.' Although it states it never returns raw secret values, it still provides a systematic way for an agent to discover what credentials exist and their canonical resolver names, which is reconnaissance-adjacent functionality worth noting even though not directly dangerous on its own.
Embed this badge

Show your MCP server’s security grade

MCP security grade F

Paste this into your README:

[![MCP security](https://gateturbo.com/badge/scan/fcd393e0-9cc0-4098-9cad-67e72f579d26)](https://gateturbo.com/report/fcd393e0-9cc0-4098-9cad-67e72f579d26)

Scanned 9/3/2026 · This is a point-in-time snapshot of the server’s public tools. Re-scan.

Connect this server safely with gate.

Continuous re-scans, drift alerts, per-tool allow/ask/block, and a log of every call.

Monitor it — free