add-dial-tool

Warn

Audited by Socket on Aug 30, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally aligned with its stated purpose, but that purpose is high impact. It intentionally grants agents real-world calling/SMS and spending power, reads a raw Dial API key from disk, and forwards it into OneCLI's intermediary injection layer. Install provenance for Dial is reasonably verifiable and same-org, so this is not confirmed malware, but the combination of credential forwarding, proxy-mediated data flow, and autonomous real-world actions makes it a high-risk skill.

Confidence: 91%Severity: 82%
AnomalyLOW
container-skills/dial-cli/SKILL.md

BENIGN overall for a telecom/phone-action skill: capabilities match the stated purpose and data flows stay on official Dial domains. Main risk is high real-world action scope (texts, calls, number purchases) plus moderate ecosystem install hygiene concerns outside this skill; there is no clear sign of credential theft, covert exfiltration, or publisher mismatch.

Confidence: 88%Severity: 62%
Audit Metadata
Analyzed At
Aug 30, 2026, 02:01 AM
Package URL
pkg:socket/skills-sh/nanocoai%2Fnanoclaw%2Fadd-dial-tool%2F@3d85b367a4cab0b236630ce6849c324b82de2aad363631f199cd712613a45a0e
Security Audit — socket — add-dial-tool