Security audit
jm-call
Security checks for vulnerabilities and agentic risk
Overview
This is a small macOS text-to-speech skill that only tells the agent to speak responses aloud when a specific voice-recognition prefix is present.
Install this only if you want responses spoken aloud on macOS when the Voice Wake prefix is present. Avoid using it for sensitive conversations in shared spaces, and verify the package identity because the embedded metadata and registry version are not perfectly aligned.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
