Claude security directory

Speko

Published by Speko

High risk

Speko runs voice AI agents that make and take phone calls. This connector gives Claude read access to that account, plus one audio capability: transcription. Ask it to list your agents and their versions, pull a call transcript or recording, check which phone numbers you hold, inspect a knowledge base, or review credit balance and usage. Give it an audio file or a recording URL and it returns text. It can also search the Speko documentation and turn an existing voice-agent config into a Speko draft. Creating agents, deploying them, placing calls and generating speech are not available through this connector, and no request can enable them. Those live in the Speko dashboard, the REST API and the SDKs.

Security assessment

Plutonium assessed this web connector for permissions, capabilities, and security-relevant behavior.

  • Can permanently delete data: This connector can erase records, files, or accounts. Once deleted the data may be unrecoverable - even an accidental request can cause permanent loss.
  • Can run commands or queries on your behalf: This connector can execute scripts, shell commands, or arbitrary database queries. In a worst case, an attacker could install software, read files, or pull or change any data its login can reach.
  • Can change or update your information: This connector can edit, rename, overwrite, or otherwise modify records in the connected service. If a request gets manipulated, your data could be altered without you noticing.
  • Reads your private information: This connector can read data the connected service holds about you - documents, messages, contact lists, source code, customer records, or saved profile details - and pass it back to the AI.
  • Sends your data to outside companies: Anything you share with this connector flows through one or more third-party services. Those companies see, store, and may use the data according to their own policies.

Available capabilities

This add-on exposes 59 tools or capabilities.

  • agents.calls.list
  • agents.create
  • agents.delete
  • agents.deploy
  • agents.evals.create
  • agents.evals.list
  • agents.evals.run
  • agents.get
  • agents.list
  • agents.monitoring.results.list
  • agents.monitors.create
  • agents.monitors.delete
  • agents.monitors.events.list
  • agents.monitors.list
  • agents.monitors.update
  • agents.preview_stacks
  • agents.rollback
  • agents.test_call
  • agents.tools.create
  • agents.tools.delete
  • agents.tools.get
  • agents.tools.list
  • agents.tools.update
  • agents.update

The interactive security report will load automatically.