Voice Agent Builder Pro

v1.0.0

Build and manage Voice AI agents using Vapi, Bland.ai, or Retell. Create agents, configure voices, set prompts, make outbound calls, and retrieve transcripts...

0· 641·1 current·1 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
medium confidence
!
Purpose & Capability
The skill's name/description and the included Python wrapper align: it is a Vapi API client and legitimately requires VAPI_API_KEY. However, SKILL.md repeatedly claims support for Bland.ai and Retell and lists broader platform integrations and features that are not implemented in the provided script (the code only talks to https://api.vapi.ai). That overstatement is an incoherence between purpose/marketing and actual capability.
!
Instruction Scope
Runtime instructions expect you to pass potentially sensitive third‑party credentials (e.g., Twilio account SID and auth token) as JSON arguments to import-phone; the script will forward those values to Vapi's API. The SKILL.md also documents commands (e.g., create-kb) and integration patterns (calendar, CRM, Bland.ai/Retell) that are either not present in the CLI router or are only described at a conceptual level. In short: the instructions encourage transmitting credentials to the remote Vapi API and claim behaviors the code does not implement.
Install Mechanism
No install spec — instruction-only with a single Python script. Nothing is downloaded or installed automatically by the skill package itself, which minimizes install-time risk.
Credentials
Only one environment variable is required: VAPI_API_KEY, which is proportionate for a wrapper around the Vapi API. However, operational instructions direct users to supply other service credentials (e.g., Twilio SID/AuthToken) via CLI arguments; these will be transmitted to the Vapi service and so are sensitive. The skill does not request other unrelated environment variables, which is good.
Persistence & Privilege
The skill does not request 'always: true' and does not include installation hooks that modify other skills or system settings. It behaves as a normal user-invokable skill.
What to consider before installing
This package is essentially a Vapi API client and needs only your VAPI_API_KEY — that part is coherent. However: (1) SKILL.md overstates support for Bland.ai/Retell and documents commands (like create-kb) that aren't implemented in the shipped script; treat those claims as marketing, not functionality. (2) Several example commands (import-phone) show you passing third-party credentials (Twilio SID/AuthToken) on the command line — the script will send those values to api.vapi.ai. Only provide such secrets if you trust Vapi and the skill author (agxntsix.ai). (3) If you plan to use this in production, verify Vapi's security/BAA/compliance for any sensitive data (PHI/PCI), and consider using short‑lived or limited-scope credentials when possible. (4) If you need Bland.ai or Retell support, expect to supply separate, official integrations rather than relying on this skill. (5) To reduce risk: run the script in an isolated environment, monitor network calls (to ensure they go to the documented api.vapi.ai endpoint), and inspect or test with non-production credentials before supplying real accounts.

Like a lobster shell, security has layers — review code before you run it.

agxntsixvk97c1jkkg0xe0g7xq1be27vrss816wtqlatestvk97c1jkkg0xe0g7xq1be27vrss816wtq

License

MIT-0
Free to use, modify, and redistribute. No attribution required.

Runtime requirements

🗣️ Clawdis
EnvVAPI_API_KEY
Primary envVAPI_API_KEY

Comments