agent-phone-network
Audited by Socket on Mar 9, 2026
1 alert found:
Obfuscated FileThe skill's purpose (agent-to-agent calling) is coherent with its described capabilities to authenticate, resolve targets, place calls, and exchange messages via an A2A service. The data flow inherently involves external endpoints and bearer tokens, which is appropriate for this scope but warrants strong trust in the A2A endpoint, TLS validation, and secure secret handling. The risk profile is moderate: credential handling and external network calls introduce potential exposure vectors, and there is reliance on an unverifiable external service for core functionality. Overall, the footprint is plausible for the stated purpose but requires careful operational controls (endpoint trust, ephemeral credentials, secure storage, and rigorous TLS checks) to be considered acceptable.