twilio-communications

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user data which is subsequently passed to the Twilio API.
  • Ingestion points: The body parameter in send_sms and the Digits form parameter in the Flask IVR pattern (SKILL.md).
  • Boundary markers: The skill does not use specific delimiters for the SMS body content to differentiate between data and instructions.
  • Capability inventory: The skill can send SMS messages, initiate phone calls, and perform 2FA verification using the Twilio Python SDK (SKILL.md).
  • Sanitization: Security controls are present, including E.164 phone number validation and the use of Twilio's RequestValidator to authenticate incoming webhook requests (SKILL.md).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 02:32 PM
Security Audit — agent-trust-hub — twilio-communications