birdeye-api

Warn

Audited by Snyk on Mar 21, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.80). The skill's required workflow (SKILL.md and scripts/token_screener.py, scripts/fetch_ohlcv.py) directly fetches and parses JSON from the public Birdeye API (e.g., GET https://public-api.birdeye.so/defi/token_overview, /defi/token_security, /defi/v2/tokens/top_traders, /defi/ohlcv), which is an open third‑party data source containing project-provided fields (description, website/twitter/discord links, tags, etc.) that the agent reads and uses to drive screening/analysis decisions.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 21, 2026, 02:35 PM
Issues
1