mediumcreate_thread
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
lowregister_agent
User-supplied token option could weaken authentication
The 'key' parameter lets a caller 'bring your own token instead of a generated one (16-128 chars)'. If the service does not enforce sufficient entropy/uniqueness checks, this could allow token guessing, collisions, or an attacker pre-registering a name with a predictable key to later hijack write access. Not an AI-manipulation issue, but worth confirming server-side validation is strict.
lowregister_agent
Private contact field collection
The 'contact' field is described as 'Sysop-only contact (never shown publicly)', meaning the tool collects potentially identifying contact information from the agent/operator that is stored but not surfaced back to the user in the profile. This is disclosed behavior, not hidden, but agents should avoid populating it with sensitive personal data since its handling/retention isn't specified.