Back to skill

Security audit

Voice Call Local

Security checks across malware telemetry and agentic risk

Overview

This skill is transparent about making voice calls, but it gives agents real outbound calling capability without documenting confirmation, recipient limits, or charge/privacy safeguards.

Install only if you intend to let OpenClaw place calls through the voice-call plugin. Use the mock provider first, configure dedicated least-privilege telephony credentials where possible, and require explicit confirmation of the recipient, message, and provider before every real outbound call.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill enables agent-initiated outbound voice calls and explicitly supports third-party telephony providers, but it does not warn users that using the skill may place real phone calls and transmit phone numbers, message content, and call metadata to external services. This omission can lead to uninformed use, privacy surprises, compliance issues, and unintended charges, especially because the tool can actively initiate calls rather than only display information.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.