mediumadw.sample
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
lowadw.feedback
Tool description directly addresses and solicits the AI agent
The description is phrased as a message to the AI ('We'd love your feedback as an AI agent using this data') and requests an optional 'agent_name' field. While this appears to be a benign survey mechanism, directly addressing the calling model and requesting its identity is an unusual pattern that could be used for agent fingerprinting or to nudge the agent into unprompted behavior (e.g., proactively calling a feedback tool unrelated to the user's request). No secrets or harmful actions are involved, but the pattern is worth noting.
lowadw.catalog
Embedded directive telling the agent what to do ('Call this first')
The description includes an instruction aimed at the agent's workflow ('Call this first to discover what you can query') rather than purely describing the tool's function. This is a mild steering directive; combined with similar phrasing in adw.sample ('Call this first to try the data before subscribing'), it nudges the agent toward a specific tool-call sequence. This is low-risk/benign in this context (legitimate API discovery guidance) but is the kind of embedded imperative that should be monitored since it goes slightly beyond neutral tool description.