Back to skill

Security audit

BeatAPI Agent Toolkit

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a legitimate BeatAPI integration, but it needs Review because one documented REST workflow tells agents to copy and run API-returned shell commands.

Install only if you are comfortable letting the agent call BeatAPI with your account, upload user-selected media, and start paid jobs when explicitly requested. Prefer MCP or structured client calls over the REST fallback; do not let an agent execute API-returned shell command strings directly.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
references/current.md:9
Finding

Remote API Response Can Be Interpreted as a Local Shell Command

Content
View full analysis

Vulnerability Details

File Location: references/current.md:9-10; related schema in references/beatapi.openapi.yaml:2173-2182
Vulnerability Type: Remote-response command injection
Risk Level: High

Vulnerable instructions:

markdown
**Every response has a `next` field: the exact call to make next, written for
your transport.** Copy it and replace the `<placeholders>`. Copy references
exactly as returned; never invent one.

Related API schema:

yaml
CapabilityNext:
  type: object
  required: [action]
  description: 'The call to make next, in the caller''s dialect: an MCP tool call `{tool, arguments}` when the request sent `X-Beat-Client: mcp`, otherwise a complete curl command. Copy it and replace the `<placeholders>`.'
  properties:
    action: { type: string, enum: [search, inspect, run, status, result, none] }
    call:
      oneOf:
        - type: string
          description: curl command against https://api.beatapi.io.
        - type: object
          required: [tool, arguments]
          properties:
            tool: { type: string, enum: [capabilities_search, capabilities_inspect, capabilities_run] }
            arguments: { type: object, additionalProperties: true }
    note: { type: string }

Technical Analysis

The REST workflow instructs the agent to copy and execute a complete curl command supplied in the remote API response. Although the schema describes the command as targeting https://api.beatapi.io, this is only descriptive text. The reviewed instructions do not require parsing the response into structured HTTP fields, checking for shell metacharacters, validating the destination, or comparing the command against a fixed endpoint allowlist.

This creates a data-to-code trust-boundary violation: remotely supplied response content is promoted from data to local shell syntax. Shell operators, command substitutions, redirects, or ...[truncated 2001 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove all instructions that tell an agent to execute next.call as a complete shell command.
  • Construct each HTTP request locally from structured fields using a fixed HTTPS origin and a fixed endpoint allowlist.
  • Use an HTTP client API rather than a shell. If a CLI is unavoidable, invoke it with an argument array and without shell=true.
  • Permit only the documented capability operations and endpoints:
    • /v1/capabilities/search
    • /v1/capabilities/inspect
    • /v1/capabilities/run
  • Validate that the scheme is HTTPS, the hostname exactly matches the configured and authorized BeatAPI origin, and redirects cannot forward authorization headers to another origin.
  • Validate action, reference, operation, task identifiers, request identifiers, and request bodies against local schemas before issuing a request.
  • Treat next.call, next.note, and other response strings as untrusted display data only.
  • For MCP responses, retain the existing tool-name allowlist and additionally validate arguments against the exact schema of the selected tool.
  • Prefer deriving the next operation from structured response fields such as action, task ID, and request ID rather than accepting executable instructions from the server.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (41)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/api-workflows.md (reported line 33)May include surrounding context.

md
| Create Ecommerce Video | `beatapi_create_ecommerce_video` | `beatapi ecommerce-video create --file INPUT` | `POST /v1/ecommerce-video/tasks` |
| Create Realtime session | Not agent-exposed; use trusted server-side code | Not allowed in Skills-only mode | `POST /v1/realtime/sessions` |
| Read Realtime session | `beatapi_get_realtime_session` | `beatapi realtime sessions get SESSION` | `GET /v1/realtime/sessions/{session_id}` |
| Close Realtime session | `beatapi_close_realtime_session` | `beatapi realtime sessions close SESSION` | `DELETE /v1/realtime/sessions/{session_id}` |
| Read task | `beatapi_get_task` | `beatapi tasks get TASK` | `GET /v1/tasks/{task_id}` |
| Wait for task | `beatapi_wait_for_task` | `beatapi tasks wait TASK` | Repeated task lookup |
| List webhooks | `beatapi_list_webhooks` | `beatapi webhooks list` | `GET /v1/webhooks` |

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/api-workflows.md (reported line 40)May include surrounding context.

md
| Create webhook | Not agent-exposed; use trusted server-side code or dashboard | Not allowed in Skills-only mode | `POST /v1/webhooks` |
| Read webhook | `beatapi_get_webhook` | `beatapi webhooks get ID` | `GET /v1/webhooks/{id}` |
| Update webhook | `beatapi_update_webhook` | `beatapi webhooks update ID --file INPUT` | `PATCH /v1/webhooks/{id}` |
| Delete webhook | `beatapi_delete_webhook` | `beatapi webhooks delete ID` | `DELETE /v1/webhooks/{id}` |

The CLI writes result JSON to stdout and progress/errors to stderr. Use
`--json` only as a compatibility alias for `--file`.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The instruction to fill an Ecommerce Video request with a "language" parameter appears as a required execution step, but the surrounding guidance does not state that language should be selected by the user or defaulted only with consent. Because language/locale policy applies to all file types, this can be read as the skill choosing a language implicitly rather than offering user opt-in.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill enables implicit invocation (allow_implicit_invocation: true) without any visible constraint on when the agent should activate it. Because this toolkit can trigger broad external capabilities such as models, social data, web search, workflows, and video-related actions, an agent may invoke it in situations the user did not clearly intend, increasing the risk of over-broad tool use, unintended data disclosure, or execution of external actions.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/beatapi.openapi.yaml (reported line 37)May include surrounding context.

yaml
read -rsp "BeatAPI API key: " BEATAPI_API_KEY && echo
    export BEATAPI_API_KEY

    curl https://api.beatapi.io/v1/workflows

    curl https://api.beatapi.io/v1/music-video/tasks \
      -H "Authorization: Bearer $BEATAPI_API_KEY" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/beatapi.openapi.yaml (reported line 2740)May include surrounding context.

yaml
suggestions: ['data:xiaohongshu.app_v2.search_notes']
              next:
                action: inspect
                call: "curl -sS -X POST https://api.beatapi.io/v1/capabilities/inspect -H 'Content-Type: application/json' -d '{\"reference\":\"data:xiaohongshu.app_v2.search_notes\"}'"
                note: Closest published match.
    InsufficientCredits:
      description: Insufficient balance (`insufficient_credits`). The account balance is zero or below the price of this request. Top up, then send it again; not retryable before that.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/capabilities.md (reported line 35)May include surrounding context.

REST example

bash
curl https://api.beatapi.io/v1/capabilities/search \
  -H "Authorization: Bearer $BEATAPI_API_KEY" \
  -H 'Content-Type: application/json' \
  -d '{"query":"小红书 搜索笔记"}'

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/credits-and-limits.md (reported line 19)May include surrounding context.

md
exact reserved or charged amount from the response. Manual Music Video
composition is the fixed public exception documented in the current contract.

Do not promise a welcome balance or promotional amount without checking the
current public contract.

For Music Video creation, BeatAPI bills detected audio duration. Use the

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/inspect.md (reported line 8)May include surrounding context.

(https://beatapi.io/skill.md). Inspect needs no key.

sh
curl -sS -X POST https://api.beatapi.io/v1/capabilities/inspect \
  -H 'Content-Type: application/json' -d '{"reference":"data:xiaohongshu.app_v2.search_notes"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/run.md (reported line 8)May include surrounding context.

loop in the main Skill (https://beatapi.io/skill.md). Run needs the key.

sh
curl -sS -X POST https://api.beatapi.io/v1/capabilities/run \
  -H "Authorization: Bearer $BEATAPI_API_KEY" -H 'Content-Type: application/json' \
  -d '{"reference":"data:xiaohongshu.app_v2.search_notes","input":{"keyword":"AI 视频"},"view":"preview"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/current.md (reported line 22)May include surrounding context.

(https://beatapi.io/skill.md). Search needs no key.

sh
curl -sS -X POST https://api.beatapi.io/v1/capabilities/search \
  -H 'Content-Type: application/json' -d '{"query":"小红书 搜索笔记"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/free-models.md (reported line 10)May include surrounding context.

(https://beatapi.io/skill.md). Search needs no key.

sh
curl -sS -X POST https://api.beatapi.io/v1/capabilities/search \
  -H 'Content-Type: application/json' -d '{"query":"小红书 搜索笔记"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/search.md (reported line 8)May include surrounding context.

(https://beatapi.io/skill.md). Search needs no key.

sh
curl -sS -X POST https://api.beatapi.io/v1/capabilities/search \
  -H 'Content-Type: application/json' -d '{"query":"小红书 搜索笔记"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/social-data.md (reported line 55)May include surrounding context.

The direct REST form is:

bash
curl https://api.beatapi.io/v1/social-data/call \
  -H "Authorization: Bearer $BEATAPI_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"action":"douyin.web.fetch_one_video","params":{"aweme_id":"7364837462110"}}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/beatapi.openapi.yaml (reported line 37)May include surrounding context.

yaml
# Web search, read, map and research

MCP tools `web_search`, `web_read`, `web_map`, `web_research`. Over REST:
`POST https://api.beatapi.io/v1/web/search`, `/v1/web/read`, `/v1/web/map`,
`/v1/web/research` with the same JSON bodies. They are also capabilities
(`data:web.search`, `data:web.read`, `data:web.map`, `data:web.research`) that
Search, Inspect and Run handle like any other. Fields:

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/beatapi.openapi.yaml (reported line 39)May include surrounding context.

yaml
# Web search, read, map and research

MCP tools `web_search`, `web_read`, `web_map`, `web_research`. Over REST:
`POST https://api.beatapi.io/v1/web/search`, `/v1/web/read`, `/v1/web/map`,
`/v1/web/research` with the same JSON bodies. They are also capabilities
(`data:web.search`, `data:web.read`, `data:web.map`, `data:web.research`) that
Search, Inspect and Run handle like any other. Fields:

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/beatapi.openapi.yaml (reported line 50)May include surrounding context.

yaml
# Web search, read, map and research

MCP tools `web_search`, `web_read`, `web_map`, `web_research`. Over REST:
`POST https://api.beatapi.io/v1/web/search`, `/v1/web/read`, `/v1/web/map`,
`/v1/web/research` with the same JSON bodies. They are also capabilities
(`data:web.search`, `data:web.read`, `data:web.map`, `data:web.research`) that
Search, Inspect and Run handle like any other. Fields:

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/beatapi.openapi.yaml (reported line 2740)May include surrounding context.

yaml
# Web search, read, map and research

MCP tools `web_search`, `web_read`, `web_map`, `web_research`. Over REST:
`POST https://api.beatapi.io/v1/web/search`, `/v1/web/read`, `/v1/web/map`,
`/v1/web/research` with the same JSON bodies. They are also capabilities
(`data:web.search`, `data:web.read`, `data:web.map`, `data:web.research`) that
Search, Inspect and Run handle like any other. Fields:

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/billing.md (reported line 17)May include surrounding context.

md
# Web search, read, map and research

MCP tools `web_search`, `web_read`, `web_map`, `web_research`. Over REST:
`POST https://api.beatapi.io/v1/web/search`, `/v1/web/read`, `/v1/web/map`,
`/v1/web/research` with the same JSON bodies. They are also capabilities
(`data:web.search`, `data:web.read`, `data:web.map`, `data:web.research`) that
Search, Inspect and Run handle like any other. Fields:

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/capabilities.md (reported line 35)May include surrounding context.

md
# Web search, read, map and research

MCP tools `web_search`, `web_read`, `web_map`, `web_research`. Over REST:
`POST https://api.beatapi.io/v1/web/search`, `/v1/web/read`, `/v1/web/map`,
`/v1/web/research` with the same JSON bodies. They are also capabilities
(`data:web.search`, `data:web.read`, `data:web.map`, `data:web.research`) that
Search, Inspect and Run handle like any other. Fields:

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/current.md (reported line 22)May include surrounding context.

md
# Web search, read, map and research

MCP tools `web_search`, `web_read`, `web_map`, `web_research`. Over REST:
`POST https://api.beatapi.io/v1/web/search`, `/v1/web/read`, `/v1/web/map`,
`/v1/web/research` with the same JSON bodies. They are also capabilities
(`data:web.search`, `data:web.read`, `data:web.map`, `data:web.research`) that
Search, Inspect and Run handle like any other. Fields:

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/free-models.md (reported line 10)May include surrounding context.

md
# Web search, read, map and research

MCP tools `web_search`, `web_read`, `web_map`, `web_research`. Over REST:
`POST https://api.beatapi.io/v1/web/search`, `/v1/web/read`, `/v1/web/map`,
`/v1/web/research` with the same JSON bodies. They are also capabilities
(`data:web.search`, `data:web.read`, `data:web.map`, `data:web.research`) that
Search, Inspect and Run handle like any other. Fields:

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/inspect.md (reported line 8)May include surrounding context.

md
# Web search, read, map and research

MCP tools `web_search`, `web_read`, `web_map`, `web_research`. Over REST:
`POST https://api.beatapi.io/v1/web/search`, `/v1/web/read`, `/v1/web/map`,
`/v1/web/research` with the same JSON bodies. They are also capabilities
(`data:web.search`, `data:web.read`, `data:web.map`, `data:web.research`) that
Search, Inspect and Run handle like any other. Fields:

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/recipes/decide-with-jev.md (reported line 72)May include surrounding context.

md
# Web search, read, map and research

MCP tools `web_search`, `web_read`, `web_map`, `web_research`. Over REST:
`POST https://api.beatapi.io/v1/web/search`, `/v1/web/read`, `/v1/web/map`,
`/v1/web/research` with the same JSON bodies. They are also capabilities
(`data:web.search`, `data:web.read`, `data:web.map`, `data:web.research`) that
Search, Inspect and Run handle like any other. Fields:

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/run.md (reported line 8)May include surrounding context.

md
# Web search, read, map and research

MCP tools `web_search`, `web_read`, `web_map`, `web_research`. Over REST:
`POST https://api.beatapi.io/v1/web/search`, `/v1/web/read`, `/v1/web/map`,
`/v1/web/research` with the same JSON bodies. They are also capabilities
(`data:web.search`, `data:web.read`, `data:web.map`, `data:web.research`) that
Search, Inspect and Run handle like any other. Fields:

Static analysis

No suspicious patterns detected.