Skip to main content

phone-agent

Enables real-time AI phone interactions using Twilio and ElevenLabs for seamless voice communication and transcription.

Install this skill

or
49/100

Security score

The phone-agent skill was audited on Feb 9, 2026 and we found 7 security issues across 3 threat categories, including 2 high-severity. Review the findings below before installing.

Categories Tested

Security Issues

medium line 56

Webhook reference - potential data exfiltration

SourceSKILL.md
56- Set "Voice & Fax" -> "A Call Comes In" to **Webhook**.
high line 25

Ngrok tunnel reference

SourceSKILL.md
255. **Ngrok** (or similar): To expose your local port 8080 to Twilio.
medium line 51

Ngrok tunnel reference

SourceSKILL.md
51ngrok http 8080
high line 57

Ngrok tunnel reference

SourceSKILL.md
57- URL: `https://<your-ngrok-url>.ngrok.io/incoming`
medium line 34

Access to hidden dotfiles in home directory

SourceSKILL.md
342. **Set Environment Variables** (in `~/.moltbot/.env`, `~/.clawdbot/.env`, or export):
medium line 34

Access to .env file

SourceSKILL.md
342. **Set Environment Variables** (in `~/.moltbot/.env`, `~/.clawdbot/.env`, or export):
low line 57

External URL reference

SourceSKILL.md
57- URL: `https://<your-ngrok-url>.ngrok.io/incoming`
Scanned on Feb 9, 2026
View Security Dashboard
Installation guide →