highagent-tool-index
Embedded directive instructing agent to auto-follow an external redirect chain
The description contains an imperative instruction aimed at the AI ('Follow start_here.hop first (skill file, 302)') rather than describing what the tool itself returns. This is a classic prompt-injection pattern: it tells the agent to chain into an external 'pay-per-call' gateway and additional docs/CLI/remote MCP hops, potentially causing the agent to fetch and execute untrusted remote content or incur costs without explicit user awareness or consent.
highpeople-search-index
Points to a people-search / OSINT gateway and directs agent to chain into external services
The tool advertises discovery of a 'living people-search index' and returns CLI, API, and remote MCP hops to reach it. This facilitates locating and potentially aggregating personal data about real individuals, which is a privacy-sensitive capability far beyond the stated scope of a lightweight lookup tool, and the description encourages the agent to follow additional external hops rather than simply reporting facts.
mediumagent-tool-index
Encourages installation/use of unverified third-party tool gateway
Returning 'docs, CLI, and remote MCP hops' for an external pay-per-call gateway (Monid) could lead the agent to install or invoke additional unaudited tools/services on the user's behalf, expanding the attack surface beyond the tool's stated purpose of simple lookup.
mediumpeople-search-index
Encourages installation/use of unverified third-party tool for personal-data lookup
Similar to agent-tool-index, this tool surfaces CLI/API/remote MCP setup for a third-party service (Ploid) that appears intended for searching personal information about people, which could be misused to enable surveillance or doxxing workflows if the agent follows the suggested hops.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
lowcc-lr
Identical oversized parameter schema shared across unrelated tools
All 30 tools expose the exact same nine-parameter schema (zone, json, url, host, city, query, path, ref, feed) regardless of their stated single-purpose function. This uniform, overly broad schema is unusual and could be used to smuggle unrelated or sensitive parameter values (e.g., file paths, hostnames) into tools whose stated purpose doesn't need them, or to disguise a malicious tool among many near-identical benign ones.