Back to skill

Security audit

Beamer

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a coherent Beamer connector, but it includes broad routing and an unsafe remote install command that should be reviewed before use.

Review the oo CLI installation path before installing; prefer official, version-pinned, verifiable installation instructions where available. Only use this skill when you intend to operate your connected Beamer account, and confirm any post creation payload before it runs.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The skill instructs users to install the CLI by piping a remotely fetched script directly into a shell (curl ... | bash). This pattern allows arbitrary code from the remote endpoint to execute immediately without verification, so compromise of the host, TLS interception in some environments, or supply-chain tampering could lead to full code execution on the user's machine.

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger text is overly broad: 'Use this skill for ANY Beamer request' and 'Whenever a task involves Beamer' can cause the agent to invoke this skill for any mention of Beamer, including cases where direct API use, unrelated discussion, or higher-safety handling would be more appropriate. Overbroad routing increases the chance of unintended tool execution and expands exposure to the skill's shell-based behaviors.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.