Latest release: v2026.7.1Download zip
Compatibility
Security Scan
OpenClaw
Benign
high confidencePurpose & Capability
The CLI, gateway methods, and voice_call tool align with the stated purpose: initiating, continuing, speaking on, ending, and checking calls through Twilio, Telnyx, Plivo, or a mock provider.
Instruction Scope
The skill instructions are limited to using the voice-call plugin and do not contain hidden role changes, prompt-injection behavior, or unrelated agent instructions.
Install Mechanism
The package is an official trusted @openclaw plugin with normal package metadata, no install scripts, and a declared OpenClaw runtime extension.
Credentials
When enabled and configured, it reads telephony credentials from config or expected environment variables, starts a local webhook server, and may call provider APIs or optional ngrok/Tailscale tooling; these are expected for phone-call webhooks and are configuration-driven.
Persistence & Privilege
It persists bounded call records and transcripts in the OpenClaw/plugin state store, defaults inbound calling to disabled, uses webhook signature verification by default, and only enables broader realtime context/tool behavior through explicit configuration.
Scan Findings in Context
[SQP-2] expected: The concern about phone numbers and spoken/message content reaching Twilio, Telnyx, or Plivo is valid privacy guidance, but the artifacts clearly present those providers as the core purpose and do not show hidden or unrelated data sharing.
Assessment
Use the mock provider for testing. For real calls, assume phone numbers, call metadata, and spoken or typed call content may be sent to the configured telephony and speech providers and may be stored in call history. Keep provider credentials secret, leave webhook signature verification enabled, and be careful with open inbound calling, persistent per-phone sessions, and realtime tool policies.dist/runtime-entry-DwMgbq2p.js:1455
Shell command execution detected (child_process).
Patterns worth reviewing
These patterns may indicate risky behavior. Check the VirusTotal and OpenClaw results above for context-aware analysis before installing.Verification
Tags
@openclaw/voice-call
Official Voice Call plugin for OpenClaw.
Providers:
- Twilio (Programmable Voice + Media Streams)
- Telnyx (Call Control v2)
- Plivo (Voice API + XML transfer + GetInput speech)
- Mock (dev/no network)
Docs: https://docs.openclaw.ai/plugins/voice-call
Plugin system: https://docs.openclaw.ai/tools/plugin
Install
openclaw plugins install @openclaw/voice-call
Restart the Gateway afterwards.
Local dev install
PLUGIN_HOME=~/.openclaw/extensions
mkdir -p "$PLUGIN_HOME"
cp -R <local-plugin-checkout> "$PLUGIN_HOME/voice-call"
cd "$PLUGIN_HOME/voice-call" && pnpm install
Config
Put under plugins.entries.voice-call.config:
{
provider: "twilio", // or "telnyx" | "plivo" | "mock"
fromNumber: "+15550001234",
toNumber: "+15550005678",
sessionScope: "per-phone", // or "per-call"
twilio: {
accountSid: "ACxxxxxxxx",
authToken: "your_token",
},
telnyx: {
apiKey: "KEYxxxx",
connectionId: "CONNxxxx",
// Telnyx webhook public key from the Telnyx Mission Control Portal
// (Base64 string; can also be set via TELNYX_PUBLIC_KEY).
publicKey: "...",
},
plivo: {
authId: "MAxxxxxxxxxxxxxxxxxxxx",
authToken: "your_token",
},
// Webhook server
serve: {
port: 3334,
path: "/voice/webhook",
},
// Public exposure (pick one):
// publicUrl: "https://example.ngrok.app/voice/webhook",
// tunnel: { provider: "ngrok" },
// tailscale: { mode: "funnel", path: "/voice/webhook" }
outbound: {
defaultMode: "notify", // or "conversation"
},
// Optional response agent workspace. Defaults to "main".
agentId: "main",
streaming: {
enabled: true,
// optional; if omitted, Voice Call picks the first registered
// realtime-transcription provider by autoSelectOrder
provider: "<realtime-transcription-provider-id>",
streamPath: "/voice/stream",
providers: {
"<realtime-transcription-provider-id>": {
// provider-owned options
},
},
preStartTimeoutMs: 5000,
maxPendingConnections: 32,
maxPendingConnectionsPerIp: 4,
maxConnections: 128,
},
}
Notes:
- Twilio/Telnyx/Plivo require a publicly reachable webhook URL.
- Twilio defaults to US1. For a non-US Region, set
twilio.regiontoie1orau1and use credentials created in that Region; see Twilio's regional REST API guide. mockis a local dev provider (no network calls).- Telnyx requires
telnyx.publicKey(orTELNYX_PUBLIC_KEY) unlessskipSignatureVerificationis true. - If older configs still use
provider: "log",twilio.from, or legacystreaming.*OpenAI keys, runopenclaw doctor --fixto rewrite them. - advanced webhook, streaming, and tunnel notes:
https://docs.openclaw.ai/plugins/voice-call responseModelis optional. When unset, voice responses use the runtime default model.sessionScopedefaults toper-phone, preserving caller memory across calls. Useper-callfor reception, booking, IVR, and bridge flows where each carrier call should start fresh.realtime.consultThinkingLevelis optional. When set, it overrides the thinking level used by the model behind realtimeopenclaw_agent_consultcalls.realtime.consultFastModeis optional. When set, it toggles fast mode for realtimeopenclaw_agent_consultcalls.
Stale call reaper
See the plugin docs for recommended ranges and production examples:
https://docs.openclaw.ai/plugins/voice-call#stale-call-reaper
TTS for calls
Voice Call uses the core messages.tts configuration for
streaming speech on calls. Override examples and provider caveats live here:
https://docs.openclaw.ai/plugins/voice-call#tts-for-calls
CLI
openclaw voicecall call --to "+15555550123" --message "Hello from OpenClaw"
openclaw voicecall continue --call-id <id> --message "Any questions?"
openclaw voicecall speak --call-id <id> --message "One moment"
openclaw voicecall end --call-id <id>
openclaw voicecall status --json
openclaw voicecall status --call-id <id>
openclaw voicecall tail
openclaw voicecall expose --mode funnel
Tool
Tool name: voice_call
Actions:
initiate_call(message, to?, mode?)continue_call(callId, message)speak_to_user(callId, message)end_call(callId)get_status(callId)
Gateway RPC
voicecall.initiate(to?, message, mode?)voicecall.continue(callId, message)voicecall.speak(callId, message)voicecall.end(callId)voicecall.status(callId)
Notes
- Uses webhook signature verification for Twilio/Telnyx/Plivo.
- Adds replay protection for Twilio and Plivo webhooks (valid duplicate callbacks are ignored safely).
- Twilio speech turns include a per-turn token so stale/replayed callbacks cannot complete a newer turn.
responseModel/responseSystemPromptcontrol AI auto-responses.- Voice-call auto-responses enforce a spoken JSON contract (
{"spoken":"..."}) and filter reasoning/meta output before playback. - While a Twilio stream is active, playback does not fall back to TwiML
<Say>; stream-TTS failures fail the playback request. - Outbound conversation calls suppress barge-in only while the initial greeting is actively speaking, then re-enable normal interruption.
- Twilio stream disconnect auto-end uses a short grace window so quick reconnects do not end the call.
- Realtime provider selection is generic. Configure
streaming.provider/realtime.providerand put provider-owned options underproviders.<id>. - Runtime fallback still accepts the old voice-call keys for now, but migration is a doctor step and the compat shim is scheduled to go away in a future release.
