phone-calls
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires the installation and execution of the
agentcashpackage from the NPM registry. Instructions guide the agent to usenpm install -g agentcashandnpx agentcash@latestto interact with the service endpoints. - [COMMAND_EXECUTION]: The skill relies on shell command execution to perform all its primary functions, including making calls, buying numbers, and checking status via the
agentcash fetchcommand. - [INDIRECT_PROMPT_INJECTION]: The skill processes external data in the form of call transcripts and AI-generated summaries which could potentially contain adversarial instructions.
- Ingestion points: Call transcripts and summaries are retrieved from the
https://stablephone.dev/api/call/{call_id}endpoint and loaded into the agent's context. - Boundary markers: No explicit delimiters or instructions are provided to the agent to treat transcript content as untrusted data.
- Capability inventory: The agent can perform subsequent network requests and shell commands based on the information parsed from these transcripts.
- Sanitization: The documentation does not specify any sanitization or filtering of the transcript text before it is processed by the agent.
Audit Metadata