openclaw-voice-call-realtime

Warn

Audited by Socket on Sep 12, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill’s stated purpose matches its telecom and transcript capabilities, and the flagged scanner items are mostly documentation artifacts. However, it installs third-party code from a personal repo under a different publisher brand, requires sensitive Twilio/OpenAI credentials, exposes a public webhook, and enables autonomous phone calls with real-world consequences; that combination makes the skill high-risk even without clear malware or credential theft behavior.

Confidence: 82%Severity: 72%
Audit Metadata
Analyzed At
Sep 12, 2026, 06:52 PM
Package URL
pkg:socket/skills-sh/reason-machines%2Fhermes-skills%2Fopenclaw-voice-call-realtime%2F@8e2eb5307ebe3b0e67802cb3ceb6cc0181a0e0e7d5192ea4a5b26f68335483f5
Security Audit — socket — openclaw-voice-call-realtime