Back to skill

Security audit

Messari

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward Messari crypto data API guide with expected third-party API calls and no hidden execution, persistence, or destructive behavior.

Install only if you are comfortable sending crypto research queries and your Messari API key to Messari's service. Do not include private keys, seed phrases, wallet credentials, or confidential personal/business data in prompts or API requests.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill’s activation criteria are excessively broad, ending with 'any blockchain/crypto data question,' which can cause it to trigger for a very wide range of requests. Overbroad routing increases the chance that unrelated or sensitive user prompts get sent to an external crypto data provider unnecessarily, expanding data exposure and making downstream prompt/data handling harder to control.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

This example shows sending user-provided prompt content to Messari’s AI chat completion endpoint along with an API key. Transmitting free-form user content to a third-party AI service can expose sensitive information if prompts contain confidential data, and the broad skill scope makes such transmission more likely.

Content

Scanner excerpt · SKILL.md (reported line 69)May include surrounding context.

AI Chat Completion

bash
curl -X POST "https://api.messari.io/ai/v1/chat/completions" \
  -H "x-messari-api-key: $MESSARI_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

This example shows sending user-provided prompt content to Messari’s AI chat completion endpoint along with an API key. Transmitting free-form user content to a third-party AI service can expose sensitive information if prompts contain confidential data, and the broad skill scope makes such transmission more likely.

Content

Scanner excerpt · SKILL.md (reported line 69)May include surrounding context.

AI Chat Completion

bash
curl -X POST "https://api.messari.io/ai/v1/chat/completions" \
  -H "x-messari-api-key: $MESSARI_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 82)May include surrounding context.

Asset Metrics Lookup

bash
curl "https://api.messari.io/metrics/v2/assets?assetSlugs=bitcoin,ethereum" \
  -H "x-messari-api-key: $MESSARI_API_KEY"

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 89)May include surrounding context.

Asset Metrics Lookup

bash
curl "https://api.messari.io/metrics/v2/assets?assetSlugs=bitcoin,ethereum" \
  -H "x-messari-api-key: $MESSARI_API_KEY"

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 96)May include surrounding context.

Asset Metrics Lookup

bash
curl "https://api.messari.io/metrics/v2/assets?assetSlugs=bitcoin,ethereum" \
  -H "x-messari-api-key: $MESSARI_API_KEY"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The document instructs users to send an API key in a header and to submit chat prompts to Messari's external AI endpoints, but it does not warn that both credentials and user-provided content will leave the local environment and be processed by a third party. In a skill that may handle portfolio, research, or other sensitive user queries, this omission can lead to unintended disclosure of secrets or confidential data through normal use.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.