Back to skill

Security audit

Call Bridge Free

Security checks across malware telemetry and agentic risk

Overview

This phone-call skill is mostly explicit about its telephony purpose, but its trigger text also claims unrelated coding and deployment uses that could route ordinary development prompts into a real outbound-calling tool.

Install only if you want an agent to place US phone calls on your behalf. Before use, narrow invocation to explicit call requests, confirm every outbound call target and task, protect ~/.config/call-bridge/key.json with restrictive permissions, and avoid placing sensitive personal, financial, medical, or regulated information in call tasks unless you understand how transcripts and recordings are retained by the service.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The manifest advertises broad coding, debugging, and deployment use cases even though the skill only documents telephony operations. This can cause the agent to invoke a phone-calling skill in unrelated contexts, increasing the chance of unintended external actions, data disclosure, or user confusion about what the skill will do.

Intent-Code Divergence

Medium
Confidence
92% confidence
Finding
The capability-coverage statement falsely claims support for coding and deployment-related scenarios that are not present elsewhere in the skill. This creates an integrity and routing risk: an agent may trust the capability declaration and select this skill for inappropriate tasks, leading to unintended outbound calls or mishandling of user data.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger description is overly broad and includes unrelated coding and deployment scenarios, which makes accidental invocation much more likely. In this skill's context, misrouting is more dangerous because the tool has exec capability and can initiate real outbound phone calls, creating privacy, cost, and external-action risks from benign user prompts.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill persists API keys and phone numbers locally and returns transcripts and recording links, but it does not prominently warn users about the sensitivity, retention, and privacy implications of this data. In a telephony skill, these artifacts may contain personal, confidential, or regulated information, so insufficient disclosure increases the risk of unintentional collection, storage, and exposure.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.