callkit-voip

Fail

Audited by Socket on Mar 8, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill's footprint is coherent with its stated purpose of implementing CallKit/PushKit VoIP functionality. It uses official Apple frameworks, standard token handling, and a Call Directory extension pattern appropriate for caller ID/blocking. There are no evident supply-chain or credential-exfiltration patterns, and no unverifiable binaries are involved. Overall risk is low-to-moderate (securityRisk ~0.55) with minimal malware risk (malware ~0.05). The design appears proportionate to its goal, though thorough review of server-side token handling and extension data management would be prudent in a real-world deployment.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 8, 2026, 07:48 PM
Package URL
pkg:socket/skills-sh/dpearson2699%2Fswift-ios-skills%2Fcallkit-voip%2F@55ddd7de828747484aa083887228afa236118fc2