agent-debugging

Fail

Audited by Socket on Feb 26, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This Skill is a legitimate debugging/troubleshooting guide and helper code for an ElevenLabs + Twilio voice agent. It calls official vendor APIs and reads local logs/configs as expected for the purpose. No active malware or exploitation code was found. Main security concerns are operational: unredacted logging of PII and transcripts, potential leakage of conversation IDs, and broad read/write tooling that could expose secrets if misused. Recommendations: ensure logs redact PII and secrets, avoid logging full transcripts in production, limit file access permissions, rotate and scope API keys, and treat conversation IDs as sensitive when appropriate.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 26, 2026, 06:05 AM
Package URL
pkg:socket/skills-sh/onesmartguy%2Fnext-level-real-estate%2Fagent-debugging%2F@8b165f7bc2f950dd0842ede0ee132c7d0bf522d0