phone-agent

Warn

Audited by Socket on Sep 4, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/server.py

No explicit malware/backdoor behavior is evident in the provided fragment (no eval/exec, no process spawning, no obvious covert exfiltration). However, there is a concrete security problem: load_task(task_name) constructs a YAML filepath from task_name without sanitization, enabling path traversal/probing if task_name can be influenced externally. Additionally, the service handles highly sensitive telephony transcripts and appears to log transcripts and persist call results to disk; this increases privacy and data-retention risk. Because the snippet is truncated and many referenced functions/variables are not shown, assessment of any additional outbound exfiltration or malicious logic elsewhere in the module remains low-confidence.

Confidence: 42%Severity: 60%
Audit Metadata
Analyzed At
Sep 4, 2026, 06:59 AM
Package URL
pkg:socket/skills-sh/delorenj%2Fskills%2Fphone-agent%2F@2c346a23ebab96c22c96b0338e498f1467b3575750fc3597677fb59af9e318b0
Security Audit — socket — phone-agent