Back to skill

Security audit

Elevenlabs Calls

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it says: it provides user-run scripts for ElevenLabs/Twilio AI phone calls and related lookup/download tasks, with privacy and consent cautions users should consider.

Install only if you intend to let an agent use your ElevenLabs account to place outbound calls and retrieve conversation records. Use explicit approval before calls, avoid unnecessary personal or sensitive data in dynamic variables, and make sure you have consent and comply with call-recording and telecom rules for the people and locations involved.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (15)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared purpose says the skill makes AI phone calls using ElevenLabs Conversational AI and Twilio, implying call initiation/orchestration and use of both services. The actual code only performs a GET request to ElevenLabs' /v1/convai/agents endpoint to retrieve and print agent metadata. There is no call creation, telephony handling, Twilio API usage, or any phone-related behavior. This is a materially different primary purpose, so the description does not accurately represent the code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared purpose emphasizes making AI phone calls with ElevenLabs and Twilio, implying call initiation/orchestration functionality and likely Twilio usage. The actual code is a read-only retrieval utility for ElevenLabs conversation data: it calls ElevenLabs conversation and audio endpoints, prints transcript/metadata/analysis, and never places calls, manages telephony, or uses Twilio at all. This is a materially different primary purpose, so the description does not accurately represent the code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared purpose says the skill makes AI phone calls using ElevenLabs Conversational AI and Twilio. However, the supplied code only performs a read-only GET request to ElevenLabs' conversations endpoint to retrieve and display recent conversations. It does not initiate calls, place outbound phone calls, interact with Twilio, or implement telephony behavior. This is a materially different primary purpose from the description, so it is a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared purpose suggests active call functionality using ElevenLabs and Twilio. However, this code chunk performs a read-only GET request to the ElevenLabs /v1/convai/phone-numbers endpoint, checks for errors, and displays imported phone number details plus setup guidance if none exist. It does not initiate calls, connect to Twilio directly, or implement call execution behavior. That is a material description-to-behavior mismatch in primary purpose.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
81% confidence
Finding

The skill advertises and documents shell-based scripts but does not declare an explicit tool scope such as allowed shell permissions. That increases the risk of overbroad execution in agent environments, because consumers cannot easily tell what command execution capability is required or intended.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill encourages outbound calling and retrieval of transcripts/audio recordings but provides no warning about consent, call recording laws, or transmission of conversation data to external providers. In this context, that omission is dangerous because users may unknowingly initiate regulated communications or expose sensitive spoken content to ElevenLabs and Twilio.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The examples explicitly pass names, phone numbers, email addresses, vehicle details, and appointment context into dynamic variables without warning that these details are transmitted to external services and may appear in transcripts or recordings. Because the skill is built for phone calls and conversation storage, the context makes this more dangerous than a generic example: it normalizes sending personally identifiable and potentially sensitive scheduling data to third parties.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/call.sh (reported line 78)May include surrounding context.

sh
echo "Initiating call to $TO_NUMBER..."

response=$(curl -s -X POST "https://api.elevenlabs.io/v1/convai/twilio/outbound-call" \
  -H "xi-api-key: $API_KEY" \
  -H "Content-Type: application/json" \
  -d "$BODY")

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/agents.sh (reported line 29)May include surrounding context.

sh
exit 1
fi

response=$(curl -s -X GET "https://api.elevenlabs.io/v1/convai/phone-numbers" \
  -H "xi-api-key: $API_KEY" \
  -H "Content-Type: application/json")

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/call.sh (reported line 78)May include surrounding context.

sh
exit 1
fi

response=$(curl -s -X GET "https://api.elevenlabs.io/v1/convai/phone-numbers" \
  -H "xi-api-key: $API_KEY" \
  -H "Content-Type: application/json")

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/conversation.sh (reported line 48)May include surrounding context.

sh
exit 1
fi

response=$(curl -s -X GET "https://api.elevenlabs.io/v1/convai/phone-numbers" \
  -H "xi-api-key: $API_KEY" \
  -H "Content-Type: application/json")

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/conversation.sh (reported line 54)May include surrounding context.

sh
exit 1
fi

response=$(curl -s -X GET "https://api.elevenlabs.io/v1/convai/phone-numbers" \
  -H "xi-api-key: $API_KEY" \
  -H "Content-Type: application/json")

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/conversations.sh (reported line 34)May include surrounding context.

sh
exit 1
fi

response=$(curl -s -X GET "https://api.elevenlabs.io/v1/convai/phone-numbers" \
  -H "xi-api-key: $API_KEY" \
  -H "Content-Type: application/json")

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/phones.sh (reported line 12)May include surrounding context.

sh
exit 1
fi

response=$(curl -s -X GET "https://api.elevenlabs.io/v1/convai/phone-numbers" \
  -H "xi-api-key: $API_KEY" \
  -H "Content-Type: application/json")

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This shell script performs an outbound HTTP request to the ElevenLabs API and sends the ELEVENLABS_API_KEY in a header, but it provides no user-facing notice before doing so. Although the file header states the script lists phone numbers, there is no explicit warning, prompt, or disclosure around the network call or credential use in the script itself.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.