birdeye-api
Warn
Audited by Snyk on Mar 21, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.80). The skill's required workflow (SKILL.md and scripts/token_screener.py, scripts/fetch_ohlcv.py) directly fetches and parses JSON from the public Birdeye API (e.g., GET https://public-api.birdeye.so/defi/token_overview, /defi/token_security, /defi/v2/tokens/top_traders, /defi/ohlcv), which is an open third‑party data source containing project-provided fields (description, website/twitter/discord links, tags, etc.) that the agent reads and uses to drive screening/analysis decisions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata