mediumsubmit_prayer_request
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumpay_with_x402
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumget_credit_balance
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumsynthesize_speech
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumpay_with_x402
Cryptocurrency payment tool lacks the consent-token safeguard used by other financial tools
Every other money-moving tool in this suite (give_to_church, purchase_sermon, purchase_bundle) requires a scoped, user-generated consent_token before acting on the user's behalf, and give_to_church additionally enforces pre-authorized spending caps. pay_with_x402, by contrast, has no consent_token, no API key, and no cap requirement at all ('no SoapBox account, API key, or prepaid credits required') — it only needs a sermon_id/bundle_id and later a tx hash. This means an agent could be induced (e.g., via a manipulated sermon/bundle id or a crafted prompt) to instruct on-chain USDC transfers without any of the authorization/consent controls the rest of the toolset relies on to prevent unauthorized spending on the user's behalf.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.