phone-agent
Audited by Socket on Sep 4, 2026
1 alert found:
AnomalyNo explicit malware/backdoor behavior is evident in the provided fragment (no eval/exec, no process spawning, no obvious covert exfiltration). However, there is a concrete security problem: load_task(task_name) constructs a YAML filepath from task_name without sanitization, enabling path traversal/probing if task_name can be influenced externally. Additionally, the service handles highly sensitive telephony transcripts and appears to log transcripts and persist call results to disk; this increases privacy and data-retention risk. Because the snippet is truncated and many referenced functions/variables are not shown, assessment of any additional outbound exfiltration or malicious logic elsewhere in the module remains low-confidence.