agentphone

Warn

Audited by Socket on Sep 5, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill is internally consistent and uses same-org official endpoints, so it does not look like credential theft or supply-chain malware. However, it grants an AI agent high-impact real-world communication powers—autonomous calls, texts, and webhook-driven conversations—which creates substantial abuse and consent risk even with otherwise coherent data flows.

Confidence: 91%Severity: 74%
Audit Metadata
Analyzed At
Sep 5, 2026, 12:29 AM
Package URL
pkg:socket/skills-sh/agentphone-ai%2Fskills%2Fagentphone%2F@f3efa13866e890692b0154e8b7009a413085bb21
Security Audit — socket — agentphone