T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:191- Finding
Untrusted Live Callers Can Trigger Privileged External Tool Operations
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This Twilio Voice skill is not clearly malicious, but it needs Review because it enables real phone calls, recordings, DTMF/live-call control, and caller-driven use of other tools without clear authorization, consent, or confirmation boundaries.
Review before installing. Only use this with a Twilio account and phone numbers you are authorized to control, require human confirmation for outbound calls, recordings, DTMF/PIN entry, redirects, conference changes, and recording deletion, and do not let unauthenticated callers trigger other connected tools. Configure call-recording consent, transcript retention, access controls, callback URL allowlists, and pinned/reviewed setup dependencies before production use.
SKILL.md:191Untrusted Live Callers Can Trigger Privileged External Tool Operations
schema.md:725Unrestricted Status Callback URL Can Disclose Call Metadata
SKILL.md:324Unpinned Remote Installation Commands Create Supply-Chain Exposure
The skill prominently advertises recording, transcription, transcript storage, and proof-of-what-was-said workflows, but does not pair them with a clear privacy, consent, retention, and jurisdiction warning. Because this skill handles phone conversations and potentially sensitive personal or business content, omission of those safeguards materially increases legal, privacy, and compliance risk.
The skill documents automated outbound calling, live AI conversations, IVR branching, and DTMF/PIN interactions without a clear warning that these features can trigger external real-world actions affecting customers or third parties. In this context, mistaken or over-broad invocation can cause harassment, compliance issues, reputational damage, and unintended disclosure over the phone.
The activation phrases are broad business-language terms such as phone assistant, reminders, approvals, and callbacks, which can overlap with ordinary user requests. In an agent ecosystem, that raises the chance of unintended skill activation leading to real-world calling actions, privacy-impacting call handling, or unnecessary charges.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/twilio-voice
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/twilio-voice
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase
Recording-related actions are documented without clear warnings about privacy, consent, retention, and jurisdiction-specific recording laws. Because this skill supports recording, fetching, saving, and transcribing call content, missing consent guidance can lead to unauthorized interception or mishandling of sensitive voice data.
The delete-recording action is destructive and appears without an explicit warning that deletion may be irreversible and can remove evidence, audit artifacts, or business records. In a voice system handling recordings and transcripts, accidental or automated deletion can cause compliance, operational, or forensic harm.
The schema exposes powerful real-world telephony operations such as placing calls, redirecting calls, sending DTMF, and speaking into live calls, but does not include any explicit cautions about consent, user approval, call charges, harassment risk, or the real-world consequences of acting on the wrong number or session. In an agent skill, this omission increases the chance that an automated system will invoke high-impact call-control actions without adequate human confirmation or policy checks.
The schema states relay_language defaults to en-US when omitted, which imposes a specific locale by default rather than offering explicit user choice. The policy allows locale constraints when users are offered a choice or when the constraint is clearly justified, neither of which is documented here.
No suspicious patterns detected.