openclaw-voice-call-realtime
Warn
Audited by Socket on Sep 12, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: The skill’s stated purpose matches its telecom and transcript capabilities, and the flagged scanner items are mostly documentation artifacts. However, it installs third-party code from a personal repo under a different publisher brand, requires sensitive Twilio/OpenAI credentials, exposes a public webhook, and enables autonomous phone calls with real-world consequences; that combination makes the skill high-risk even without clear malware or credential theft behavior.
Confidence: 82%Severity: 72%
Audit Metadata