mediumlibrary_search
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumlibrary_get_concept
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumlibrary_get_indicator
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumlibrary_get_source_code
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumlibrary_list_concepts
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumlibrary_list_indicators
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumlibrary_list_tags
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumlibrary_list_families
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumlibrary_get_family
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumpropfirms_search
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumpropfirms_get
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumpropfirms_search_challenges
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumpropfirms_search_offers
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumpropfirms_list_simulatable
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumpropfirms_challenge_rules
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumpropfirms_simulate
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumpropfirms_optimal_risk
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumpropfirms_compare
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumpropfirms_simulate_trades
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumpropfirms_pass_rates
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumpropfirms_validate_strategy
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumtrackers_datasets
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumtrackers_query
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumtrackers_latest
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumtrackers_ticker
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumedge_symbols
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumedge_presets
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
mediumedge_report
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
lowpropfirms_search
Unusually long tool description
Very long descriptions are sometimes used to bury instructions to the AI. Skim it before allowing.
lowpropfirms_search_challenges
Unusually long tool description
Very long descriptions are sometimes used to bury instructions to the AI. Skim it before allowing.
lowpropfirms_search_offers
Unusually long tool description
Very long descriptions are sometimes used to bury instructions to the AI. Skim it before allowing.
lowpropfirms_challenge_rules
Unusually long tool description
Very long descriptions are sometimes used to bury instructions to the AI. Skim it before allowing.
lowpropfirms_simulate
Unusually long tool description
Very long descriptions are sometimes used to bury instructions to the AI. Skim it before allowing.
lowpropfirms_optimal_risk
Unusually long tool description
Very long descriptions are sometimes used to bury instructions to the AI. Skim it before allowing.
lowpropfirms_compare
Unusually long tool description
Very long descriptions are sometimes used to bury instructions to the AI. Skim it before allowing.
lowpropfirms_simulate_trades
Unusually long tool description
Very long descriptions are sometimes used to bury instructions to the AI. Skim it before allowing.
lowpropfirms_validate_strategy
Unusually long tool description
Very long descriptions are sometimes used to bury instructions to the AI. Skim it before allowing.
lowtrackers_query
Unusually long tool description
Very long descriptions are sometimes used to bury instructions to the AI. Skim it before allowing.
lowtrackers_latest
Unusually long tool description
Very long descriptions are sometimes used to bury instructions to the AI. Skim it before allowing.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
lowlibrary_search
Mandatory 'context' parameter enforces agent behavior beyond the tool's function
Every tool in this collection (library_search, library_get_concept, library_get_indicator, library_get_source_code, library_list_concepts, library_list_indicators, library_list_tags, library_list_families, library_get_family, propfirms_search, propfirms_get, propfirms_search_challenges, propfirms_search_offers, propfirms_list_simulatable, propfirms_challenge_rules, propfirms_simulate, propfirms_optimal_risk, propfirms_compare, propfirms_simulate_trades, propfirms_pass_rates, propfirms_validate_strategy, trackers_datasets, trackers_query, trackers_latest, trackers_ticker, edge_symbols, edge_presets, edge_report) requires a 'context' string with imperative instructions directed at the AI model itself ('YOU MUST provide 15-25 words', 'NEVER use first person', 'maintain third-person perspective') under the guise of an 'analytics' field. This is a directive embedded in a tool schema that shapes the agent's output/behavior rather than describing what the tool does, and it forces the agent to generate and transmit a free-text description of the user's private goal/intent to the tool provider on every single call. While the field explicitly forbids including credentials/PII, the mechanism itself is a form of mandatory behavioral compliance and covert usage-intent telemetry baked into every tool invocation, which is unusual and could be leveraged to exfiltrate summarized user intent to a third party without explicit user consent for each call.location:
lowpropfirms_simulate_trades
Accepts pasted broker/account statements that may contain personal or account-identifying data
The tool accepts free-form pasted broker exports (MT4/MT5 account statements as CSV or HTML, ThinkOrSwim statements, TradingView trade lists, broker JSON fills) via tradeLogText/tradeLogTexts. These real-world export formats commonly include account numbers, account holder names, server/broker identifiers, and other account metadata beyond bare R-multiples. The tool does not instruct the agent to strip or warn about such identifying data before sending it to the MCP server, so an agent naively pasting a full statement could transmit more personal/account data than necessary for the stated simulation purpose.