Back to skill

Security audit

Telecom Agent Skill

Security checks across malware telemetry and agentic risk

Overview

This skill is coherent as a telecom automation tool, but it gives an agent high-impact calling, recording, transcript, and account authority without enough documented limits or privacy controls.

Review carefully before installing. Use only with a trusted implementation, a limited Twilio account or subaccount, verified opt-in call lists, explicit campaign approvals, spend and rate limits, authorized Telegram admins, and clear policies for recording consent, transcript access, retention, and deletion.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill explicitly states that audio is recorded automatically for quality assurance, but the description and usage guidance do not provide a clear warning about consent, notice, retention, or legal obligations. In a telecom context, silent or inadequately disclosed recording can expose users to privacy violations, regulatory noncompliance, and misuse of sensitive call content, especially because transcripts and logs are also retrievable and persisted.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.