Back to skill

Security audit

beam

Security checks for vulnerabilities and agentic risk

Overview

The skill appears purpose-built for Beam data transfers, but it can start credit-consuming, destination-overwriting transfers without an enforced confirmation check in its helper script.

Review this before installing if agents may run tools autonomously. Use it only with tightly scoped Beam and storage credentials, require an explicit user approval step before every live transfer or Room creation, prefer dry-run/estimate first, and avoid running the curl-to-shell CLI installer unless you trust the Beam distribution path.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/beam_transfer.py:394
Finding

Transfer Execution Does Not Enforce the Documented User Confirmation Gate

Content
View full analysis

Vulnerability Details

File Location: scripts/beam_transfer.py:394-407
Vulnerability Type: Missing authorization confirmation for a destructive, credit-consuming operation
Risk Level: Medium

Code Snippet:

python
async def cmd_run(args: argparse.Namespace) -> int:
    spec = build_spec(args)
    if args.dry_run:
        emit("plan", **spec.describe(), name=args.name, timeout_seconds=args.timeout)
        return EXIT_OK
    api_key = require_api_key()
    transfer_id = ""
    async with beam_client(api_key) as beam:
        try:
            try:
                prepared = await beam.transfers.create_transfer(
                    sources=[spec.source_model],
                    destinations=spec.destination_models,
                    name=args.name,
                )

Technical Analysis

The Skill documentation requires the Agent to disclose the source, all destinations, overwrite risk, object size, and estimated credit cost, and then obtain user agreement before starting a transfer (SKILL.md:114-117). The executable helper does not enforce that authorization requirement.

When the run subcommand is invoked without the optional --dry-run flag, cmd_run() immediately constructs the transfer specification, obtains BEAM_API_KEY, and calls beam.transfers.create_transfer(). There is no required confirmation flag, approved-plan identifier, interactive prompt, or validation that an estimate was previously shown and accepted.

The relevant inputs are the caller-supplied --source and repeated --dest arguments. These determine which object is read and which destination objects are written. Because the helper can be invoked directly by an Agent or another local caller, the prose-only confirmation instruction does not form a technical authorization boundary.

The presence of --dry-run does not prevent this path: it is optional, and omitting it selects the live transfer path.

...[truncated 1379 chars]

Remediation
View remediation

Remediation Suggestions

Enforce authorization in the executable helper rather than relying exclusively on Agent instructions:

  1. Make live execution require an explicit flag such as --confirmed.
  2. Have estimate or --dry-run produce a cryptographically bound plan containing the normalized source, all normalized destinations, object size, estimated credits, overwrite warning, and a short expiration time.
  3. Require run to receive the approved plan or its digest and reject execution if the current arguments differ from the approved values.
  4. Display the exact destination keys and overwrite implications before approval.
  5. Consider an optional maximum-credit limit and reject transfers whose estimate exceeds it.
  6. Preserve a non-interactive mode for automation only when it supplies an explicit confirmation artifact or policy-approved limit.
  7. Apply the same authorization design to other consequential operations, while retaining the documented requirement that cancellation occur only at the user's request.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (3)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The skill instructs the agent to install software by piping a remote script directly into the shell, which is a classic arbitrary code execution pattern. If the CDN, DNS, TLS trust chain, or upstream install script is compromised, the agent could execute attacker-controlled code with the user's privileges and potentially access the many secrets this skill expects in the environment.

Content

Scanner excerpt · SKILL.md (reported line 76)May include surrounding context.

md
1. Check the tools you need: `uv --version` for transfers, `beam --version` for
   Rooms. If `uv` is missing, offer the installer from this skill. If `beam` is
   missing, the official installer is
   `curl -fsSL https://cdn.b1m.ai/cli/install.sh | sh`. Ask before running it.
2. Check that the key works. The header goes through stdin so the key never
   appears in a process list:
   `printf 'X-Api-Key: %s\n' "$BEAM_API_KEY" | curl -fsS -H @- https://beamcore.b1m.ai/auth/me`.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill requires access to environment secrets and network operations, but it does not declare any explicit tool scope such as permissions or allowed-tools. That weakens policy enforcement and increases the chance an agent can invoke broader-than-necessary capabilities, including access to sensitive credentials and outbound connections not clearly constrained by the skill contract.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/rooms.md (reported line 97)May include surrounding context.

  1. The invitee joins (its own agent with this skill runs the same command):

    bash
    chmod 600 invitation.token
    beam room join ROOM --invitation-file invitation.token --json
    

Static analysis

No suspicious patterns detected.