zerion
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the installation and execution of external tools including 'zerion-cli' via npm and 'zerion-mcp-server' via npx. These are official tools for interacting with the Zerion API.
- [REMOTE_CODE_EXECUTION]: The skill uses 'npx' to run the Zerion MCP server and references the 'bankr-mcp-server'. This involves downloading and executing code from public registries at runtime.
- [INDIRECT_PROMPT_INJECTION]: The skill fetches and interprets raw blockchain data (transactions, NFT metadata, DApp info) from external sources. Malicious actors could potentially craft transaction metadata or NFT attributes designed to influence the agent's behavior when this data is processed.
- Ingestion points: Data is ingested from the Zerion API (api.zerion.io) which aggregates data from 41+ blockchains.
- Boundary markers: The documentation does not specify explicit delimiters or warnings to the agent to ignore instructions embedded within the fetched blockchain data.
- Capability inventory: The skill is designed to work in tandem with execution skills like 'Bankr', which can perform wallet operations, trades, and setting stop-losses based on the analyzed data.
- Sanitization: There is no explicit mention of sanitizing or filtering instructions from incoming blockchain metadata before passing it to the agent.
Audit Metadata