Back to skill

Security audit

Ai Intelligent Call Center

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to support call-center call recording, which can be legitimate, but the artifacts do not clearly document consent, retention, access controls, or narrow activation boundaries.

Review before installing. Use this only in environments where call recording is authorized, callers are properly notified or consent is obtained as required, and you have a clear policy for storage, access, retention, and deletion of recordings and transcripts.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill advertises call recording functionality but provides no notice about consent, retention, access controls, or jurisdiction-specific compliance requirements. In a call-center context, this can lead to unlawful recording, mishandling of sensitive customer data, and regulatory or contractual violations if deployers assume recording is safe by default.

Vague Triggers

Low
Confidence
94% confidence
Finding
The description field is overly generic and does not clearly constrain when the skill should be invoked or what exact operations it performs. In agent ecosystems, vague metadata can cause over-broad activation or misuse in unintended contexts, increasing the chance that the skill handles requests outside its intended scope.

Static analysis

No suspicious patterns detected.