T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/authorize.py:34- Finding
Authorization Requests Permissions Beyond the Skill's Functional Requirements
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill’s main caption-to-card workflow is coherent, but it asks for broad Beatra account permissions and silently self-updates executable code by default.
Review this before installing if you are not comfortable granting a shared Beatra device token with broad media, wallet, artifact, and task permissions. Disable automatic updates with `python3 scripts/mcp_client.py update --auto off` if you want approval before package code changes, and revoke the device from the Beatra Console if you later decide to disconnect it.
scripts/authorize.py:34Authorization Requests Permissions Beyond the Skill's Functional Requirements
scripts/mcp_client.py:969Default Silent Update Mechanism Retrieves and Installs Changeable Remote Code
The requested permissions include images, videos, music, speech, and voice read/write capabilities that do not align with turning public YouTube lesson captions into text takeaway cards. These excessive privileges broaden the attack surface and could enable misuse of user resources or unauthorized actions through the shared credential.
Including uninstall lifecycle actions, token revocation, inspection of installed-skill inventory, and deletion/modification of local state files is outside the stated lesson-card function. These behaviors are sensitive because they can alter account access and local application state, and they are easy to under-review when hidden inside a content-production skill.
Including uninstall lifecycle actions, token revocation, inspection of installed-skill inventory, and deletion/modification of local state files is outside the stated lesson-card function. These behaviors are sensitive because they can alter account access and local application state, and they are easy to under-review when hidden inside a content-production skill.
Including uninstall lifecycle actions, token revocation, inspection of installed-skill inventory, and deletion/modification of local state files is outside the stated lesson-card function. These behaviors are sensitive because they can alter account access and local application state, and they are easy to under-review when hidden inside a content-production skill.
Referenced artifact was not completely inspected
inspection (`scripts/mcp_client.py` / `beatra.assets.upload`). Keep
Referenced artifact was not completely inspected
inspection (`scripts/mcp_client.py` / `beatra.assets.upload`). Keep
Referenced artifact was not completely inspected
inspection (`scripts/mcp_client.py` / `beatra.assets.upload`). Keep
Referenced artifact was not completely inspected
inspection (`scripts/mcp_client.py` / `beatra.assets.upload`). Keep
Referenced artifact was not completely inspected
inspection (`scripts/mcp_client.py` / `beatra.assets.upload`). Keep
Referenced artifact was not completely inspected
inspection (`scripts/mcp_client.py` / `beatra.assets.upload`). Keep
Referenced artifact was not completely inspected
inspection (`scripts/mcp_client.py` / `beatra.assets.upload`). Keep
Referenced artifact was not completely inspected
inspection (`scripts/mcp_client.py` / `beatra.assets.upload`). Keep
Referenced artifact was not completely inspected
inspection (`scripts/mcp_client.py` / `beatra.assets.upload`). Keep
Referenced artifact was not completely inspected
inspection (`scripts/mcp_client.py` / `beatra.assets.upload`). Keep
Referenced artifact was not completely inspected
inspection (`scripts/mcp_client.py` / `beatra.assets.upload`). Keep
The documentation states that one approval grants access to image, video, music, speech, upload, model, and task tools, which is far broader than what a YouTube caption-to-cards skill should need. This creates a strong scope mismatch and violates least privilege, increasing the blast radius if the skill or its backend is abused or compromised.
The documented authorization explicitly covers multiple unrelated media and task tools despite the skill being described as a caption summarization/card generation utility. Overbroad capability grants enable unnecessary access paths and make lateral misuse more feasible if credentials are stolen, reused, or the service behavior changes.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
```
They share the one full-scope Device Token stored in
`~/.beatra/credentials.json`. Installing or switching packages must not trigger
another authorization when that credential is already valid. Do not add,
enable, trust, or configure a host Beatra Connector. Never print or move the
token into command arguments, environment variables, logs, chat, or another
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
They share the one full-scope Device Token stored in
`~/.beatra/credentials.json`. Installing or switching packages must not trigger
another authorization when that credential is already valid. Do not add,
enable, trust, or configure a host Beatra Connector. Never print or move the
token into command arguments, environment variables, logs, chat, or another
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
They share the one full-scope Device Token stored in
`~/.beatra/credentials.json`. Installing or switching packages must not trigger
another authorization when that credential is already valid. Do not add,
enable, trust, or configure a host Beatra Connector. Never print or move the
token into command arguments, environment variables, logs, chat, or another
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
They share the one full-scope Device Token stored in
`~/.beatra/credentials.json`. Installing or switching packages must not trigger
another authorization when that credential is already valid. Do not add,
enable, trust, or configure a host Beatra Connector. Never print or move the
token into command arguments, environment variables, logs, chat, or another
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
They share the one full-scope Device Token stored in
`~/.beatra/credentials.json`. Installing or switching packages must not trigger
another authorization when that credential is already valid. Do not add,
enable, trust, or configure a host Beatra Connector. Never print or move the
token into command arguments, environment variables, logs, chat, or another
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
```
They share the one full-scope Device Token stored in
`~/.beatra/credentials.json`. Installing or switching packages must not trigger
another authorization when that credential is already valid. Do not add,
enable, trust, or configure a host Beatra Connector. Never print or move the
token into command arguments, environment variables, logs, chat, or another
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
```
They share the one full-scope Device Token stored in
`~/.beatra/credentials.json`. Installing or switching packages must not trigger
another authorization when that credential is already valid. Do not add,
enable, trust, or configure a host Beatra Connector. Never print or move the
token into command arguments, environment variables, logs, chat, or another
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
```
They share the one full-scope Device Token stored in
`~/.beatra/credentials.json`. Installing or switching packages must not trigger
another authorization when that credential is already valid. Do not add,
enable, trust, or configure a host Beatra Connector. Never print or move the
token into command arguments, environment variables, logs, chat, or another
No suspicious patterns detected.