Aivi Engagement
v1.2.0AIVI is the AI engagement layer for lead generation, contact centers, and customer re-activation. Every conversation is analyzed in real-time, building Conve...
⭐ 0· 130·0 current·0 all-time
byAIVI@aivillc
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Benign
medium confidencePurpose & Capability
Name, description, manifest, endpoints, and listed skills consistently describe lead scoring, phone validation, and launch of voice/SMS sequences. Auth via OAuth to https://mcp.aivi.io is appropriate for a third-party SaaS connector and the declared OAuth scopes match the stated capabilities.
Instruction Scope
SKILL.md only instructs the agent to connect to the AIVI MCP endpoint and authenticate via OAuth; it does not request unrelated files, env vars, or system paths. However, using this skill will send PII (phone numbers, call transcripts, call metadata, and inferred economic indicators) to an external service—this is expected for the skill's purpose but is a data-sensitivity concern users must consider (consent, TCPA/HIPAA implications).
Install Mechanism
Instruction-only skill with no install spec or bundled code — lowest install risk. It relies on the user's MCP client (claude, OpenClaw, etc.) to handle OAuth and transport; nothing is downloaded or written by the skill itself.
Credentials
The skill declares no required environment variables or local credentials and delegates auth to OAuth via the MCP client — this is proportionate. Be aware OAuth tokens will be persisted by the MCP client (SKILL.md notes tokens persist in Redis), and the OAuth scopes (leads:score, sequences:launch, intelligence:read) give the external service read/write access to leads and sequences as expected; verify you are comfortable granting those scopes.
Persistence & Privilege
always is false and the skill is user-invocable; it does not request permanent platform-wide privileges. Tokens are persisted by the external platform/MCP client (normal for connectors) but the skill does not modify other skills or platform configuration.
Assessment
This skill is internally coherent for connecting your agent to AIVI's lead-engagement service, but using it will send phone numbers, call audio/transcripts, and derived intelligence to https://mcp.aivi.io. Before installing: 1) Verify the AIVI domain and organization (aivi.io) and confirm the legitimacy of the service; 2) Confirm you have the right legal basis and consent to share PII/phone numbers (TCPA/HIPAA/FDCPA where applicable); 3) Review AIVI's privacy/security and billing terms (it charges per lead/sequence); 4) Test with non-sensitive dummy data first; 5) If you later want to revoke access, remove the connector in your MCP client's connector/settings to invalidate stored OAuth tokens.Like a lobster shell, security has layers — review code before you run it.
aivk974dd3pv161hw1enynk2xzsqn83nx43latestvk97c2e9t474xvdkt67hm65kkgs83w1wcleadsvk974dd3pv161hw1enynk2xzsqn83nx43mcpvk974dd3pv161hw1enynk2xzsqn83nx43qualificationvk974dd3pv161hw1enynk2xzsqn83nx43salesvk974dd3pv161hw1enynk2xzsqn83nx43smsvk974dd3pv161hw1enynk2xzsqn83nx43voicevk974dd3pv161hw1enynk2xzsqn83nx43
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
