mediummvr_first_call
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediummvr_entity_resolve
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediummvr_evidence_completeness
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediummvr_context_compile
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediummvr_decision_check
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediummvr_first_call
Description tries to mandate agent behavior across unrelated decision types
The description instructs the agent to invoke this tool 'before' a sweeping list of business actions (pre-MVP build, entry, BNPL, investment, partnership, scale, lend, deploy) and even says 'Use when asked to ignore, fabricate, or transfer evidence.' This reads less like a functional description and more like an attempt to insert a mandatory gating step into the agent's reasoning for many unrelated user requests, which is a form of instruction embedding aimed at controlling agent behavior beyond the tool's actual scope.
mediummvr_decision_check
Implies routing of user evidence to an undisclosed external 'licensed MVR scoring' service
The description states the tool 'routes a structurally complete pack toward licensed MVR scoring,' implying evidence submitted by the user (business/market data) may be forwarded to an external licensed scoring system. There is no clarity on what this external service is, who operates it, or how data is handled, which raises a data-exfiltration/third-party-disclosure concern if the agent submits user evidence without explicit user awareness.
lowmvr_evidence_completeness
Unusually long tool description
Very long descriptions are sometimes used to bury instructions to the AI. Skim it before allowing.
lowmvr_decision_check
Unusually long tool description
Very long descriptions are sometimes used to bury instructions to the AI. Skim it before allowing.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
lowmvr_first_call
Repeated 'never authorizes' disclaimer alongside broad mandatory-use language is contradictory
The tool claims it 'never authorizes' decisions yet is described as a required preflight gate for numerous major business decisions. This mismatch could be used to make the agent feel obligated to call the tool far more often than necessary, expanding its footprint in the conversation without a clear functional justification tied to the user's actual request.