Back to skill

Security audit

Agentic Calling

Security checks for vulnerabilities and agentic risk

Overview

This Twilio calling skill is purpose-aligned, but it needs Review because it can place real calls/SMS and has unsafe scripting around untrusted message content, recordings, callbacks, and credentials.

Review before installing. Use only test or least-privilege Twilio credentials, restrict which numbers and callback hosts the agent may use, keep credentials in a secret manager or a 600-permission file, and do not enable recording or transcription unless consent and retention rules are handled. The scripts should be fixed before use with untrusted message, voice, URL, media, timeout, or phone-number inputs.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/make-call.sh:106
Finding

Arbitrary Python Code Execution Through Call Message or Voice Arguments

Content
View full analysis
$MESSAGE" if [[ "$URGENT" == "true" ]]; then TWIML="${TWIML}This is an urgent message. Please respond immediately." fi TWIML="${TWIML}" # URL encode TwiML TWIML_ENCODED=$(python3 -c "import urllib.parse; print(urllib.parse.quote('''$TWIML'''))") ``` ### Technical Analysis The `--message` and `--voice` command-line arguments are incorporated into `TWIML`, which is then directly interpolated into Python source supplied to `python3 -c`. Shell quoting does not make the interpolated content safe as Python source. An attacker who can influence either argument can include a sequence such as `'''` to terminate the Python triple-quoted string and append attacker-selected Python statements. Those statements can invoke operating-system commands, read files, modify user-owned data, or access secrets available to the process. This is a direct local code-execution vulnerability rather than ordinary malformed-input handling. ### Attack Path 1. An attacker supplies or causes an agent to supply a malicious `--message` or `--voice` value. 2. The script embeds that value into the `TWIML` shell variable. 3. The complete value is inserted into the source string passed to `python3 -c`. 4. The malicious value terminates the intended Python string literal and introduces additional Python code. 5. Python executes the injected statements with the identity and environment of the user running the skill. ### Impact Assessment Successful exploitation provides arbitrary code execution under the invoking user's privileges. The attacker could: - Read the Twilio Auth Token and Account SID from the process environment or configuration file. - Ma ...[truncated 321 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/make-call.sh:106
Finding

TwiML Injection Through Unescaped Message and Voice Values

Content
View full analysis
$MESSAGE" if [[ "$URGENT" == "true" ]]; then TWIML="${TWIML}This is an urgent message. Please respond immediately." fi TWIML="${TWIML}" ``` ### Technical Analysis The script concatenates `MESSAGE` into an XML text node and `VOICE` into an XML attribute without applying XML escaping or structural validation. A crafted message can close the intended `` element and insert additional TwiML verbs. Likewise, a crafted voice value can terminate its attribute and alter the surrounding element. If Twilio accepts the resulting document, injected verbs such as ``, ``, or `` may be interpreted as call-control instructions rather than spoken text. URL encoding performed later only transports the generated document; it does not neutralize malicious XML that is already structurally valid. ### Attack Path 1. An attacker controls or influences the value passed through `--message` or `--voice`. 2. The value includes XML delimiters that terminate the expected text node or attribute. 3. The script concatenates the value into the TwiML document without escaping it. 4. The generated document is submitted to Twilio through the Calls API. 5. Twilio parses the injected elements as call-control instructions. 6. The active call can perform behavior not authorized by the caller of the script. ### Impact Assessment Exploitation is limited to Twilio capabilities available to the configured account, but may allow: - Dialing or forwarding to attacker-selected destinations. - Redirecting call processing to an attacker-controlled endpoint. - Enabling recording or otherwise changing call behavior. - Disclosure of c ...[truncated 305 chars]
Remediation
View remediation
` cannot create elements. 3. Encode attribute values correctly and restrict `VOICE` to an explicit allowlist. 4. Reject control characters and malformed Unicode before XML generation. 5. Parse the completed TwiML locally with a secure XML parser and verify that it contains only the expected structure and permitted verbs. 6. Add tests using closing tags, injected TwiML verbs, quotes, ampersands, and malformed XML. ]]>

T09 · Insecure Skill Coding Practices

Error
Location
scripts/sms-notify.sh:66
Finding

Twilio API Form-Parameter Injection Through Manually Concatenated Request Data

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
README.md:12
Finding

Twilio Authentication Token Stored Without Enforced Restrictive File Permissions

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (20)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README explicitly promotes autonomous phone calls and SMS but does not prominently warn that these actions reach real recipients, may trigger unwanted communications, and can incur Twilio charges. In an agent skill context, this omission increases the risk of accidental abuse, spam, or unexpected billing because users may run examples without appreciating the real-world effects.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 14)May include surrounding context.

  1. Configure Twilio Credentials:

Create ~/.clawdbot/twilio-config.json:

json
{
  "accountSid": "YOUR_ACCOUNT_SID",

Session Persistence

Medium
Category
Rogue Agent
Confidence
84% confidence
Finding

The skill instructs users to store Twilio credentials in a persistent plaintext file under the home directory without mentioning file permissions, secret management, or encryption. If the host is multi-user, compromised, or backed up broadly, these credentials could be recovered and used to place calls, send SMS, access recordings, or harvest account data.

Content

Scanner excerpt · SKILL.md (reported line 25)May include surrounding context.

1. Configure Credentials

Create a file at ~/.clawdbot/twilio-config.json:

json
{

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The callback/webhook examples send call status and related metadata to external URLs without explaining that caller information, call events, and potentially other sensitive metadata will be shared off-platform. This can cause unintentional disclosure to third-party systems and weakens informed use of the skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly promotes call recording and transcription but does not warn users about consent, notice, retention, or jurisdiction-specific recording laws. In a telephony context this can lead operators to capture sensitive voice data unlawfully or without informed consent, creating privacy, legal, and compliance risk.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 298)May include surrounding context.

bash
# Test webhook
curl -X POST https://your-server.com/voice \
  -d "Called=+15551234567" \
  -d "From=+15559876543"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script enables call recording for automated appointment reminders by passing --record true, but there is no visible disclosure, consent flow, or jurisdiction check in this script. Recording calls without informing recipients can violate privacy laws and healthcare confidentiality expectations, especially because the message includes appointment details and provider names that may be sensitive.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script can download and store call recordings to an arbitrary local path supplied by the user without any confirmation, warning, or access-control checks. In the context of an agent skill handling telephony data, recordings are sensitive and writing them silently to disk increases the risk of unintended retention, disclosure, or placement in insecure locations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script enables call recording and optional transcription with simple boolean flags but provides no built-in consent notice, jurisdiction check, or operator warning beyond the flag names. In a phone-calling automation skill, this creates a realistic privacy and legal compliance risk because recordings and transcripts may be collected without proper notification or authorization.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

With no manifest available, the skill has no documented purpose or declared capability baseline. This script accesses sensitive credentials from both the environment and a home-directory config file in order to authenticate outbound messaging, which is a meaningful capability not justified by any provided skill description.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/call-status.sh (reported line 80)May include surrounding context.

sh
fi

# Build request
API_URL="https://api.twilio.com/2010-04-01/Accounts/${TWILIO_ACCOUNT_SID}/Messages.json"
FORM_DATA="To=${TO_NUMBER}&From=${TWILIO_PHONE_NUMBER}&Body=${MESSAGE}"

if [[ -n "$MEDIA_URL" ]]; then

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/call-status.sh (reported line 90)May include surrounding context.

sh
fi

# Build request
API_URL="https://api.twilio.com/2010-04-01/Accounts/${TWILIO_ACCOUNT_SID}/Messages.json"
FORM_DATA="To=${TO_NUMBER}&From=${TWILIO_PHONE_NUMBER}&Body=${MESSAGE}"

if [[ -n "$MEDIA_URL" ]]; then

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/call-status.sh (reported line 100)May include surrounding context.

sh
fi

# Build request
API_URL="https://api.twilio.com/2010-04-01/Accounts/${TWILIO_ACCOUNT_SID}/Messages.json"
FORM_DATA="To=${TO_NUMBER}&From=${TWILIO_PHONE_NUMBER}&Body=${MESSAGE}"

if [[ -n "$MEDIA_URL" ]]; then

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/call-status.sh (reported line 109)May include surrounding context.

sh
fi

# Build request
API_URL="https://api.twilio.com/2010-04-01/Accounts/${TWILIO_ACCOUNT_SID}/Messages.json"
FORM_DATA="To=${TO_NUMBER}&From=${TWILIO_PHONE_NUMBER}&Body=${MESSAGE}"

if [[ -n "$MEDIA_URL" ]]; then

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/call-status.sh (reported line 120)May include surrounding context.

sh
fi

# Build request
API_URL="https://api.twilio.com/2010-04-01/Accounts/${TWILIO_ACCOUNT_SID}/Messages.json"
FORM_DATA="To=${TO_NUMBER}&From=${TWILIO_PHONE_NUMBER}&Body=${MESSAGE}"

if [[ -n "$MEDIA_URL" ]]; then

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/make-call.sh (reported line 115)May include surrounding context.

sh
fi

# Build request
API_URL="https://api.twilio.com/2010-04-01/Accounts/${TWILIO_ACCOUNT_SID}/Messages.json"
FORM_DATA="To=${TO_NUMBER}&From=${TWILIO_PHONE_NUMBER}&Body=${MESSAGE}"

if [[ -n "$MEDIA_URL" ]]; then

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/sms-notify.sh (reported line 68)May include surrounding context.

sh
fi

# Build request
API_URL="https://api.twilio.com/2010-04-01/Accounts/${TWILIO_ACCOUNT_SID}/Messages.json"
FORM_DATA="To=${TO_NUMBER}&From=${TWILIO_PHONE_NUMBER}&Body=${MESSAGE}"

if [[ -n "$MEDIA_URL" ]]; then

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The code constructs a Twilio API endpoint and sends an authenticated POST request that transmits user-supplied message content and destination number. Because no manifest is available, this remote communication capability is not justified by any declared skill purpose and should be treated as context-inappropriate for an unknown-purpose skill.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/make-call.sh (reported line 133)May include surrounding context.

sh
# Send SMS
echo "Sending SMS to ${TO_NUMBER}..."
RESPONSE=$(curl -s -X POST "$API_URL" \
  -u "${TWILIO_ACCOUNT_SID}:${TWILIO_AUTH_TOKEN}" \
  -d "$FORM_DATA")

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/sms-notify.sh (reported line 77)May include surrounding context.

sh
# Send SMS
echo "Sending SMS to ${TO_NUMBER}..."
RESPONSE=$(curl -s -X POST "$API_URL" \
  -u "${TWILIO_ACCOUNT_SID}:${TWILIO_AUTH_TOKEN}" \
  -d "$FORM_DATA")

Static analysis

No suspicious patterns detected.