Back to skill

Security audit

Twilio Voice

Security checks for vulnerabilities and agentic risk

Overview

This Twilio Voice skill is not clearly malicious, but it needs Review because it enables real phone calls, recordings, DTMF/live-call control, and caller-driven use of other tools without clear authorization, consent, or confirmation boundaries.

Review before installing. Only use this with a Twilio account and phone numbers you are authorized to control, require human confirmation for outbound calls, recordings, DTMF/PIN entry, redirects, conference changes, and recording deletion, and do not let unauthenticated callers trigger other connected tools. Configure call-recording consent, transcript retention, access controls, callback URL allowlists, and pinned/reviewed setup dependencies before production use.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:191
Finding

Untrusted Live Callers Can Trigger Privileged External Tool Operations

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
schema.md:725
Finding

Unrestricted Status Callback URL Can Disclose Call Metadata

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:324
Finding

Unpinned Remote Installation Commands Create Supply-Chain Exposure

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (16)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill prominently advertises recording, transcription, transcript storage, and proof-of-what-was-said workflows, but does not pair them with a clear privacy, consent, retention, and jurisdiction warning. Because this skill handles phone conversations and potentially sensitive personal or business content, omission of those safeguards materially increases legal, privacy, and compliance risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill documents automated outbound calling, live AI conversations, IVR branching, and DTMF/PIN interactions without a clear warning that these features can trigger external real-world actions affecting customers or third parties. In this context, mistaken or over-broad invocation can cause harassment, compliance issues, reputational damage, and unintended disclosure over the phone.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The activation phrases are broad business-language terms such as phone assistant, reminders, approvals, and callbacks, which can overlap with ordinary user requests. In an agent ecosystem, that raises the chance of unintended skill activation leading to real-world calling actions, privacy-impacting call handling, or unnecessary charges.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 398)May include surrounding context.

md
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/twilio-voice
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 399)May include surrounding context.

md
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/twilio-voice
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Recording-related actions are documented without clear warnings about privacy, consent, retention, and jurisdiction-specific recording laws. Because this skill supports recording, fetching, saving, and transcribing call content, missing consent guidance can lead to unauthorized interception or mishandling of sensitive voice data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The delete-recording action is destructive and appears without an explicit warning that deletion may be irreversible and can remove evidence, audit artifacts, or business records. In a voice system handling recordings and transcripts, accidental or automated deletion can cause compliance, operational, or forensic harm.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The schema exposes powerful real-world telephony operations such as placing calls, redirecting calls, sending DTMF, and speaking into live calls, but does not include any explicit cautions about consent, user approval, call charges, harassment risk, or the real-world consequences of acting on the wrong number or session. In an agent skill, this omission increases the chance that an automated system will invoke high-impact call-control actions without adequate human confirmation or policy checks.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The schema states relay_language defaults to en-US when omitted, which imposes a specific locale by default rather than offering explicit user choice. The policy allows locale constraints when users are offered a choice or when the constraint is clearly justified, neither of which is documented here.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.