Back to skill

Security audit

RingBot

Security checks across malware telemetry and agentic risk

Overview

RingBot matches its phone-call purpose, but it needs review because it can place real outbound AI calls without clear consent, confirmation, or cancellation safeguards.

Install only if you trust and separately review the RingBot backend service. Use explicit approval for every call or schedule, limit Twilio spend, protect provider keys, avoid sensitive or regulated outreach unless you have consent and legal authority, and confirm there is a clear way to stop future calls.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Vague Triggers

High
Confidence
98% confidence
Finding
The manifest description includes very broad trigger phrases such as "call," "phone," "dial," and "ring," which are likely to match ordinary user language and cause the skill to activate in situations the user did not explicitly intend. Because this skill can initiate real-world outbound phone calls, over-triggering creates elevated risk of unauthorized calls, privacy violations, charges, harassment, and reputational harm.

Missing User Warnings

High
Confidence
97% confidence
Finding
The skill promotes autonomous outbound calling, including calls to leads, patients, family members, and businesses, but does not warn users about consent, call recording laws, impersonation boundaries, privacy handling, or the real-world consequences of AI-initiated calls. In this context, omission of these safeguards is dangerous because the skill directly interfaces with people outside the system and could be used in legally sensitive or harmful scenarios without adequate user awareness.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.