mediumget_starter_file
Marketing language framed to persuade the AI, and delivery of a file designed to act as an operating-system/prompt override
The description uses persuasive framing ('the REAL Brainfile', 'turns generic Claude into a project that remembers you') that reads as instructions aimed at influencing the assistant's behavior/recommendations rather than neutral tool documentation. More concerning, one of the fetched files, CLAUDE.starter.md, is explicitly described as a 'starter operating-system playbook' intended to be loaded into the agent's context (e.g., as CLAUDE.md). Since the content of that file is not shown here, an agent calling this tool could unknowingly ingest instructions that redefine its own operating rules, memory, or persona. Agents should treat the contents of any fetched 'playbook'/'operating system' file as untrusted data, not as new system instructions, and should surface its contents to the user before adopting any embedded directives.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
lowlist_pack_contents
Embedded upsell / external-link promotion within tool metadata
The description promotes paid 'role packs' and includes an 'unlock URL' and references to a 'free no-card trial pull' from an external source. This turns a tool listing into an advertising vector that could induce the agent to recommend a paid product or navigate to an external site on the user's behalf. Not a direct security exploit, but the tool description is doing more than describing its own function — it's steering the agent's downstream behavior (upselling) which the user did not ask for.
lowget_freshness_sample
Description explicitly frames tool as a 'retention mechanic' aimed at monetization
The tool description states outright that this feature is 'the retention mechanic' for keeping users on a paid license ('a paid license keeps the newest feed flowing'). This is business/marketing framing embedded directly in tool metadata that the agent will read verbatim, potentially causing the agent to nudge the user toward a purchase decision under the guise of simply fetching a data sample. It does not request secrets or perform harmful actions, but it is an example of manipulative framing baked into tool documentation that could bias agent recommendations without transparent disclosure to the user.