twilio-communications
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user data which is subsequently passed to the Twilio API.
- Ingestion points: The
bodyparameter insend_smsand theDigitsform parameter in the Flask IVR pattern (SKILL.md). - Boundary markers: The skill does not use specific delimiters for the SMS body content to differentiate between data and instructions.
- Capability inventory: The skill can send SMS messages, initiate phone calls, and perform 2FA verification using the Twilio Python SDK (SKILL.md).
- Sanitization: Security controls are present, including E.164 phone number validation and the use of Twilio's
RequestValidatorto authenticate incoming webhook requests (SKILL.md).
Audit Metadata