Back to skill

Security audit

ElevenLabs Phone Reminder (Lite)

Security checks across malware telemetry and agentic risk

Overview

This appears to be a normal setup guide for ElevenLabs and Twilio phone reminders, but users should handle call consent and API credentials carefully.

Install only if you intend to connect ElevenLabs and Twilio for outbound reminders. Use it only for recipients who have agreed to receive calls, clearly identify AI callers where required, avoid sensitive personal data in call content, and store API keys in environment variables or a secret manager with periodic rotation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill promotes outbound AI phone calls and natural voice interactions without any guidance on consent, caller identification, lawful use, or recipient privacy. That omission can enable misuse such as unsolicited robocalling, deceptive AI impersonation, or collection/disclosure of personal information during calls, especially because the workflow is framed as simple and production-oriented.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The guide instructs users to handle highly sensitive credentials and send them to external services, including embedding Twilio SID and auth token in API requests, without warning about secret management or third-party data exposure. This increases the chance that users will paste secrets into shells, logs, screenshots, repos, or untrusted environments, and may not realize that call metadata and conversation content are processed by ElevenLabs and Twilio.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.