highagent-tool-index
Embedded instruction to follow untrusted redirect chains
The description tells the agent to 'Follow start_here.hop first (skill file, 302)' and references 'docs, CLI, and remote MCP hops.' This is a directive embedded in a tool description that instructs the calling agent to automatically follow external redirects/hops and potentially connect to additional, unvetted remote MCP servers or a 'pay-per-call' gateway. This could be used to smuggle the agent into fetching and executing instructions from an attacker-controlled location, or incur costs/actions without explicit user awareness.
highpeople-search-index
Facilitates people-search / doxing infrastructure discovery
The tool is designed to locate a 'living people-search index (Ploid)' and provides CLI, API, and remote MCP hop information. This capability could be used to help locate and aggregate personal information about real individuals, which is a privacy-sensitive and potentially harmful capability not comparable to the other benign, read-only utility tools in this collection.
mediumagent-tool-index
Broad capability beyond stated purpose / monetization risk
Description references a 'pay-per-call tool gateway (Monid)' which implies the tool can lead to financial transactions or external service usage far beyond the simple lookup/indexing function suggested by its name and the other benign tools in this set.
mediumpeople-search-index
Same redirect/hop-following pattern as agent-tool-index
Like agent-tool-index, this tool likely encourages following external hops to remote services (CLI setup, docs, API, remote MCP), which could route the agent to untrusted third-party infrastructure without clear user consent or visibility.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
lowsm3-ok
Schema/description mismatch across all tools may mask actual behavior
All 30 tools share an identical, broad input schema (zone, json, url, host, city, query, path, ref, feed) regardless of the tool's stated single-purpose function (e.g., 'SM3 hex length'). This makes it hard to verify that a given tool only uses the fields relevant to its description, and could allow a tool to silently accept and act on unrelated inputs (e.g., path, url, feed) beyond what its name suggests. Not proven malicious, but worth flagging for schema hygiene and auditability.