messari-token-research
Warn
Audited by Socket on Mar 21, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the Messari research purpose broadly matches the API calls, and the MoonPay CLI appears officially distributed, but the skill is over-scoped because it can trigger on-chain fund bridging as part of a research workflow. Data mainly flows to official Messari endpoints, yet routing paid requests through a third-party CLI and enabling autonomous financial actions makes the overall risk high enough to avoid classifying it as benign.
Confidence: 89%Severity: 74%
Audit Metadata