mediumdecide_approve
Unauthenticated approval endpoint can bypass human-in-the-loop control
This tool is explicitly described as 'Public so the desk can approve without the org key,' meaning it requires no write key or other authentication beyond an approval_id and decision string. Since request_approve (the HITL pause gate used before spend/actions) relies on a human tapping 'yes', the lack of authentication on decide_approve means any party (including the agent itself, a compromised script, or an attacker who can guess/observe an approval_id) could submit 'approved' and bypass genuine human consent for spend or other sensitive actions. This undermines the entire purpose of the approval gate and could allow unauthorized spend or actions to proceed as if a human approved them.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
lowhandshake
Trust-switch check is a no-op by default, risking false sense of security
The description states 'While activation is off (default) business proceeds either way,' meaning the bot-to-bot trust handshake does not actually gate any action unless explicitly turned on. An agent could represent to a user or log that a 'trust check with the counterparty' occurred, while in practice (given default settings) the outcome has no effect on whether business proceeds. This could create a misleading appearance of safety/verification without any enforcement, and should be clearly surfaced to users rather than silently defaulting to a permissive, non-blocking mode.