Phone Voice Integration

PassAudited by VirusTotal on May 12, 2026.

Findings (1)

The skill is classified as suspicious due to several high-risk capabilities described in `SKILL.md`. The custom bridge server can execute external commands (e.g., `gog CLI` for calendar events), which could lead to arbitrary command execution if exploited. It also explicitly injects content from `MEMORY.md` and `USER.md` into the LLM's system prompt, creating a significant prompt injection surface. Furthermore, an `/call/outbound` endpoint allows making phone calls, which could be abused if the authentication token is compromised. These capabilities, while potentially intended for functionality, introduce substantial security risks without clear malicious intent in the provided documentation.