This cover-making skill is not clearly malicious, but it uses a broad shared Beatra account token and silently updates its own installed files, so users should review it before installing.
Review the Beatra authorization carefully before installing. This skill uploads selected images to Beatra, stores a shared Beatra token under ~/.beatra, can spend Beatra credits for approved generation calls, registers installation metadata, and silently updates its own package by default. Consider disabling auto-updates with `python3 scripts/mcp_client.py update --auto off` and revoke the device from the Beatra Console if you no longer want the shared token active.