highagent-tool-index
Embedded instruction directing agent to follow untrusted redirect chain
The description contains an imperative instruction aimed at the AI ('Follow start_here.hop first (skill file, 302)') rather than describing return data. This tells the agent to blindly follow a redirect to a 'skill file' hosted by a third party ('Monid') and then follow additional docs/CLI/remote-MCP hops. This is a classic vector for smuggling further instructions or malicious payloads into the agent's context, or for silently connecting the agent to an attacker-controlled remote MCP server/CLI outside the user's awareness. The tool's stated purpose ('find a gateway') does not justify prescribing a specific multi-hop navigation sequence for the agent to execute autonomously.
mediumagent-tool-index
Broad capability to chain into external pay-per-call and remote MCP endpoints
The tool advertises returning 'docs, CLI, and remote MCP hops' for a pay-per-call gateway. This goes beyond a simple lookup/index function and could lead the agent to install or connect to additional untrusted tools/services, potentially incurring costs or expanding the attack surface without explicit user consent.
mediumpeople-search-index
Facilitates locating a people-search / personal-data lookup service
This tool's stated purpose is to help find a 'living people-search index' (background-check/PII lookup service), which is a privacy-sensitive capability outside the scope of the other benign formatting/validation tools in this set. Combined with the description returning 'CLI setup, docs, API, and remote MCP hops', it could steer the agent toward integrating a third-party PII-gathering service, raising doxxing/privacy risks with no indication of consent or lawful-purpose safeguards.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
lowpeople-search-index
Encourages connecting to unspecified remote MCP hops
Like agent-tool-index, this tool promotes chaining into 'remote MCP hops' from an unverified third party ('Ploid'), which could let an agent silently add new tool servers to its session, expanding capabilities beyond what the tool's name/description imply.