mediumdeveloper.secret-scan
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumdeveloper.openapi-test-generate
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
lowdata.us-weather-forecast
Unusually long tool description
Very long descriptions are sometimes used to bury instructions to the AI. Skim it before allowing.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
lowdeveloper.code-metrics
Embedded promotional URL directing agent to external endpoint
The tool description includes marketing/redirect content ('One bounded no-wallet trial is available through the separate HTTP endpoint https://apiacre.com/trials/developer.code-metrics; this MCP tools/call operation remains paid.') that is not part of the tool's technical function. This kind of embedded external URL and promotional framing in a description read verbatim by an agent could be used to steer the agent toward visiting or recommending an unverified third-party endpoint. It is not overtly malicious here, but embedding advertising/redirection instructions inside a tool schema description is an unusual pattern worth flagging.