setup-inbound

Warn

Audited by Socket on May 20, 2026

1 alert found:

Security
SecurityMEDIUM
assets/ivr_account_verification.json

This is high-risk credential-collection IVR configuration: it instructs callers to enter a bank account number and a raw PIN and is designed to pass those secrets to a downstream agent for further processing. The bank-mimicking language and the inconsistent “hash key” wording (without a corresponding field) further increase suspicion. While this fragment alone is not executable malware, its design is strongly consistent with fraud/phishing or unauthorized account-takeover workflows unless proven to be part of an authenticated, authorized banking process with appropriate safeguards.

Confidence: 66%Severity: 80%
Audit Metadata
Analyzed At
May 20, 2026, 01:56 PM
Package URL
pkg:socket/skills-sh/bolna-ai%2Fskills%2Fsetup-inbound%2F@4de64a1d857a38daaba82db1680f27bb422fee45
Security Audit — socket — setup-inbound