low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
lowwatch_add
User-supplied webhook could exfiltrate verification data
The optional 'webhook' field POSTs each recorded change (citation/package details, verdicts) to an arbitrary https URL supplied by the caller. If an agent is manipulated (e.g., via prompt injection elsewhere) into supplying an attacker-controlled webhook, verification data could be sent to a third party. This is standard webhook functionality and not inherently malicious, but the agent should confirm the webhook destination with the user before setting it, especially if the URL did not originate from the user directly.'
lowwatch_portfolio
User-supplied webhook could exfiltrate bulk verification data
Same pattern as watch_add: an optional https webhook receives JSON for every change across up to 25 watched references. If the webhook URL is attacker-supplied rather than user-confirmed, this could leak which packages/citations are being tracked and their status to a third party.