Back to skill

Security audit

Voice Call Local

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward voice-call integration, but users should understand that live provider modes can place real calls through third-party services.

Install this only if you intend agents to be able to initiate voice calls through the configured OpenClaw voice-call plugin. Use mock mode for testing, and in live Twilio, Telnyx, or Plivo modes confirm recipients, message content, consent, and provider costs before allowing calls.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill enables agent-initiated outbound phone calls through third-party telephony providers, but it does not clearly warn users that invoking the skill may place real calls and transmit message content and phone numbers to external services. This creates a consent, privacy, and cost-risk issue because users or operators may trigger actions without understanding that external providers such as Twilio, Telnyx, or Plivo will be involved.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.