MCP security report

agent-observatory-sensor.nolimit-observatory.workers.dev

D52/100
Security grade DHigh-severity signals — review these before connecting.
Connected ✓30 tools scanned

https://agent-observatory-sensor.nolimit-observatory.workers.dev/s/forwarded-by/mcp

highagent-tool-index
Embedded directive instructs the agent to follow an external redirect chain
The description contains an imperative instruction aimed at the AI ('Follow start_here.hop first (skill file, 302)') rather than a neutral description of tool behavior. This is a classic prompt-injection pattern: it tells the model to automatically chase a 302 redirect to an unknown external destination and then follow additional 'docs, CLI, and remote MCP hops.' This could lead the agent to fetch and execute instructions from an untrusted third party, or to silently register/connect to additional remote MCP servers (expanding its own tool surface) without the user's awareness or consent.
mediumpeople-search-index
Facilitates locating a people-search / OSINT service for living individuals
The tool's stated purpose is to help find a 'living people-search index' and provides API/CLI/remote-MCP hops to reach it. This capability is oriented toward looking up personal information about identifiable individuals, which raises privacy and doxxing concerns. It also shares the pattern of directing the agent toward 'remote MCP hops,' i.e., additional external services that could expand the agent's capabilities or exfiltrate query data outside the scope of the tool description.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
lowagent-tool-index
Encourages expansion of agent capabilities via remote MCP discovery
Beyond the redirect instruction, the description advertises 'remote MCP hops' as part of its output. If the agent acts on this by connecting to newly discovered remote MCP servers, it could silently onboard additional, unvetted tools/capabilities mid-session, which the user did not explicitly approve.
lowforwarded-by
Broad, mismatched input schema shared across all tools
Every tool in this set exposes the same nine-field schema (zone, json, url, host, city, query, path, ref, feed) regardless of its stated single purpose (e.g., a timezone-lookup tool accepts a 'path' and 'feed' parameter it has no use for). While each field description claims the value is 'discarded,' this generic oversized schema increases the risk of parameter confusion or unintended data being silently accepted and processed by unrelated tool logic. Not clearly malicious, but worth tightening schemas to match each tool's actual function.
Embed this badge

Show your MCP server’s security grade

MCP security grade D

Paste this into your README:

[![MCP security](https://gateturbo.com/badge/scan/fe4a78ac-187e-44eb-a8b3-8df087d20728)](https://gateturbo.com/report/fe4a78ac-187e-44eb-a8b3-8df087d20728)

Scanned 9/14/2026 · This is a point-in-time snapshot of the server’s public tools. Re-scan.

Connect this server safely with gate.

Continuous re-scans, drift alerts, per-tool allow/ask/block, and a log of every call.

Monitor it — free