PhoneSAFE
The agent-native LLM router for autonomous agents. Every frontier model behind one wallet, <1ms local routing, USDC payments on Base & Solana via x402.
Overview
The agent-native LLM router for autonomous agents. Every frontier model behind one wallet, <1ms local routing, USDC payments on Base & Solana via x402.
6efc7dc8711bOBSERVED · 2026-10-07Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| openclaw | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
---
name: phone
description: Verify phone numbers (carrier + SIM-swap fraud signals) and place AI-powered outbound voice calls via BlockRun's gateway (Twilio + Bland.ai). Trigger when the user asks to look up a number, check fraud risk, buy/rent a phone number, or place an AI voice call. Payment is automatic via x402 from the wallet.
triggers:
- "blockrun phone"
- "blockrun voice"
- "voice call"
- "outbound call"
- "ai phone call"
- "ai voice call"
- "phone number lookup"
- "phone number verification"
- "carrier lookup"
- "sim swap"
- "sim-swap detection"
- "phone fraud check"
- "buy phone number"
- "rent phone number"
- "twilio number"
- "bland.ai"
- "blockrun bland"
metadata: { "openclaw": { "emoji": "📞", "requires": { "config": ["models.providers.blockrun"] } } }
---
# Phone & Voice
Phone-number intelligence (Twilio Lookup) and AI-powered outbound voice calls (Bland.ai) through ClawRouter's local proxy. Payment is automatic via x402 from the user's BlockRun wallet.
**Shortcuts:**
- Slash: `/cr-call +1<E.164> "<task>" [--voice nat] [--max-duration 5] [--from +1<owned-number>] [--language en-US]`
- CLI: `clawrouter phone numbers list/buy/renew/release`, `clawrouter phone lookup <+E.164>`, `clawrouter phone fraud <+E.164>`
- Partner tools (LLM-callable): `blockrun_phone_lookup`, `blockrun_phone_lookup_fraud`, `blockrun_phone_numbers_buy/renew/list/release`, `blockrun_voice_call`, `blockrun_voice_status`
> **⚠️ Real-world side effects.** `blockrun_voice_call` places a real outbound phone call to a real number. Only invoke when the user has explicitly asked for a call to be placed. Server enforces an emergency-number blocklist.
---
## Phone Number Intelligence (Twilio)
### Carrier + Line Type Lookup — `$0.01`
POST to `http://localhost:8402/v1/phone/lookup`:
```json
{ "phoneNumber": "+14155552671" }
```
Returns carrier name, line type (`mobile` / `landline` / `voip`), country, mobile country/network codes. Use to verify whether a number is reachable, detect VoIP/spam patterns, or route SMS appropriately.
### Fraud Risk Check — `$0.05`
POST to `http://localhost:8402/v1/phone/lookup/fraud`:
```json
{ "phoneNumber": "+14155552671" }
```
Adds SIM-swap recency and call-forwarding signals on top of carrier+line type. **Run this before sending sensitive SMS codes or initiating account-recovery flows** — a number flagged for recent SIM swap is high-risk for account takeover.
---
## Wallet-Owned Phone Numbers
Numbers are leased for 30 days, bound to the wallet's payer address. Use one as the `from` parameter of `voice_call` to present a stable caller ID.
### Buy — `$5.00 / 30 days`
POST to `http://localhost:8402/v1/phone/numbers/buy`:
```json
{ "country": "US", "areaCode": "415" }
```
`country` is `"US"` or `"CA"`. `areaCode` is optional (3-digit, best-effort match). Returns `{ phone_number, expires_at, chain }`.
### Renew — `$5.00 / +30 days`
POST to `http://localhost:8402/v1/phone/numbers/renew`:
```json
{ "phoneNumber": "+14155551234" }
```
Run before the existing lease expires. Numbers not renewed are released back to the pool.
### List — `$0.001`
POST to `http://localhost:8402/v1/phone/numbers/list` with an empty body. Returns an array of `{ phone_number, expires_at, country, chain }`. The CLI surfaces this as a human table with renew-soon warnings:
```
$ clawrouter phone numbers list
Active numbers (2):
+14155551234 US expires 2026-06-12 (in 27d)
+12135555678 US expires 2026-05-18 (in 2d) ⚠ renew soon
```
### Release — free
POST to `http://localhost:8402/v1/phone/numbers/release`:
```json
{ "phoneNumber": "+14155551234" }
```
No refund. Use only when the user has explicitly asked to give up the number.
---
## AI Voice Call (Bland.ai)
### Place a Call — `$0.54 flat (up to 30 min)`
POST to `http://localhost:8402/v1/voice/call`:
```json
{
"to": "+14155552671",
"task": "Call and confirm the 3pm Thursday meeting; reschedule if they can't make it.",
"voice": "nat",
"max_duration": 5,
"from": "+14155551234",
"language": "en-US"
}
```
**Required:** `to` (E.164), `task` (free-form natural language — what the AI should say or accomplish).
**Optional:**
| Field | Default | Notes |
| -------------- | ----------- | ------------------------------------------------------------------------------------------------------------------------------------------------ |
| `voice` | `nat` | Presets: `nat`, `josh`, `maya`, `june`, `paige`, `derek`, `florian`. Or a custom Bland voice ID. |
| `max_duration` | `5` | Maximum minutes (1–30). Price is flat $0.54 regardless of actual duration. |
| `from` | auto-picked | Must be a wallet-owned number from `phone_numbers_list`. If omitted, server auto-picks from wallet's active numbers — see auto-pick rules below. |
| `language` | `en-US` | Any spoken-language ISO code, e.g. `es-ES`, `zh-CN`, `de-DE`. |
**`from` auto-pick rules** (server-side, after payment verification):
| Wallet active numbers | Behavior |
| --------------------- | --------------------------------------------------------------------------------------------------------- |
| 0 | `403 no_active_number` — response includes `buy_endpoint` + marketplace URL so caller can provision first |
| Exactly 1 | Auto-used as caller ID |
| 2+ | `400 ambiguous_from` — response lists all active numbers; retry with `froTrust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | NA |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
6efc7dc8711bfull audit observations/trust-audit/skill/blockrunai__phone.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 6efc7dc8711b | SAFE | B | 89 | first audit |
Questions
What does the Phone skill do?
The agent-native LLM router for autonomous agents. Every frontier model behind one wallet, <1ms local routing, USDC payments on Base & Solana via x402.
Is Phone safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Phone access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Phone work with?
Its documentation mentions openclaw. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (6efc7dc8711b), read on 2026-10-07. The repository is watched, and a new audit runs when it changes — this is the first audit.