mediumtender_feed
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
lowtender_feed
User-supplied third-party API key passed as a plain parameter
The samApiKey field asks the caller to supply their own SAM.gov API key as a plain string argument. While the description states it is 'never stored,' API keys passed through tool-call parameters can end up in logs, conversation history, or model context. This is a minor credential-handling concern rather than malicious design; consider out-of-band secret storage instead of passing the key as a tool argument.