Back to skill

Security audit

Messari

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward Messari crypto research helper that discloses its API-key requirement and third-party API use.

Install this only if you want your agent to send crypto research queries to Messari using your API key. Monitor API and AI credit usage, avoid sending secrets or sensitive trading details in prompts, and treat market analysis as informational rather than trading advice.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The skill advertises itself for essentially any blockchain or crypto data question, which creates an overly broad trigger scope and increases the chance it will be invoked for loosely related prompts. That can lead to unnecessary third-party API usage, unintended exposure of user queries to Messari, and selection of this skill over more appropriate or narrower tools.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.