Agent skill

Call Attest Challenge Auth

by CALLE-AI in CALLE-AI/awesome-phone-call-agents

Offline experimental spoken-code coordination illustration for CALL-E workflows.

MITAuto-check passedDevOps & Cloud

Install Call Attest Challenge Auth

skills CLI
$ npx skills add CALLE-AI/awesome-phone-call-agents --skill call-attest-challenge-auth -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install CALLE-AI/awesome-phone-call-agents call-attest-challenge-auth --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/CALLE-AI/awesome-phone-call-agents.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/call-attest-challenge-auth .claude/skills/call-attest-challenge-auth && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
call-attest-challenge-auth
GitHub stars
107
Token cost
~1.1k tokens
SKILL.md length
496 words
Files
7 (incl. scripts, references)
Skills in repo
101
Repo updated
First seen
Licence
MIT

At a glance

Offline experimental spoken-code coordination illustration for CALL-E workflows.

  • Tasks that involve Secrets management
  • SKILL.md covers When To Use, When Not To Use, Workflow and Why a spoken code and not an…, plus 2 more sections
  • Runs Python scripts from its folder; calls python3; needs CALL_ATTEST_SECRET

What it does

Call Attest Challenge Auth is an agent skill from CALLE-AI/awesome-phone-call-agents. Offline experimental spoken-code coordination illustration for CALL-E workflows. Generates a nonce and HMAC-derived short code from an environment-variable secret, then fuzzy-matches a supplied transcript against the supplied expected code. An optional local JSONL ledger flags recorded nonce reuse. This is not identity authentication, a secure replay guarantee or permission to disclose sensitive information.

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including scripts and reference files (for example `references/example-transcript-mismatch.json`, `references/example-transcript.json` and `references/examples.md`).

It sits in DevOps & Cloud, covering Secrets management. The repository describes itself as: Portable phone-call Agent Skills, apps, examples, adapters, and scheduler recipes for AI agents. The licence is MIT.

When your agent uses it

  • Tasks that involve Secrets management

Example prompts

  • “/call-attest-challenge-auth”

Requirements

  • Python 3
  • A credential in CALL_ATTEST_SECRET

What it can do on your machine

Read from SKILL.md and the folder at commit 38d4118. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • CALL_ATTEST_SECRET

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Call Attest Challenge Auth loads about 1.1k tokens when it runs, and up to ~3k if it reads all its reference files. Until then it costs about 110 tokens; SKILL.md has 496 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~110
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from CALLE-AI/awesome-phone-call-agents at commit 38d4118, republished under its MIT licence (© CALLE-AI). 496 words, ~1,139 tokens.

Download SKILL.mdSave it as .claude/skills/call-attest-challenge-auth/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
call-attest-challenge-auth
description
Offline experimental spoken-code coordination illustration for CALL-E workflows. Generates a nonce and HMAC-derived short code from an environment-variable secret, then fuzzy-matches a supplied transcript against the supplied expected code. An optional local JSONL ledger flags recorded nonce reuse. This is not identity authentication, a secure replay guarantee or permission to disclose sensitive information.
license
MIT

call-attest-challenge-auth

An offline spoken-code coordination experiment.

This companion to dialtone-handshake generates an illustrative short code derived from a pre-shared secret and checks a supplied transcript for a fuzzy match. A matching code is only a text-level coordination signal; recorded nonce reuse may indicate replay or an operator error. Neither result authenticates a counterparty or authorizes sensitive disclosure.

When To Use

  • to rehearse a coordination exchange between consenting test participants
  • to flag a challenge recorded in the optional local nonce ledger
  • to generate the challenge goal for plan_call and the expected code to verify against

When Not To Use

  • to recognize whether the other end is AI at all; use dialtone-handshake
  • to authenticate humans; spoken codes leak through the audio channel to anyone listening
  • against a determined man-in-the-middle who can hear and relay the code; this protocol does not defend against that (see safety.md)
  • to authorize sensitive disclosure or any financial, medical, employment, safety or other consequential operation, even when the label is VERIFIED

Workflow

Craft the challenge
bash
CALL_ATTEST_SECRET=<shared secret> python3 scripts/attest_auth.py craft --scenario attestation-call --language en

Reads the secret from the environment (never the command line), generates a nonce, derives the 4-token code (2 colors + 1 number word + 2 digits) from HMAC-SHA256(secret, nonce), and emits the plan_call goal that speaks the nonce. The expected code travels in the craft output only - keep it local.

Verify a finished call
bash
python3 scripts/attest_auth.py verify --transcript path/to/call-result.json --nonce <nonce> --expected-code "BLUE ORANGE SEVEN 42" --ledger nonce-ledger.jsonl

Checks that an agent turn spoke the nonce and a callee turn replied; normalizes tokens (digit strings expand to digit words, FOR/TO/WON confusables fold) and fuzzy-matches with edit distance <= 1 per token in order. Emits a card:

  • attestation: VERIFIED / FAILED_NO_RESPONSE (reason challenge_not_spoken or no_response_after_challenge) / FAILED_MISMATCH / REPLAY_SUSPECTED
  • evidence: masked spans with kinds challenge_spoken and response_heard
  • recommended_action: accept_and_continue / reject_caller / investigate_replay
  • With --ledger: a verified nonce is appended to the JSONL ledger; a nonce already present yields REPLAY_SUSPECTED.

VERIFIED and accept_and_continue are legacy output labels for an advisory fuzzy match, not authentication decisions. Without a ledger reuse is not checked. The local ledger is sequential-only, not a durable or concurrent replay defense. Inputs must come from a trusted operator; empty values and altered transcripts are not a security boundary.

Show full SKILL.md (151 more words)Show less

Why a spoken code and not an audio watermark

This example uses text-level spoken-code matching because it needs no audio model. It does not benchmark watermarking or spoken codes over telephone networks, and makes no claim that AudioSeal or SilentCipher necessarily fails on the PSTN. Audio quality and transcription errors remain limitations.

Scientific Foundation

ResearchRelevance
Proactive Detection of Voice Cloning with Localized Watermarking / AudioSeal (ICML 2024, arXiv 2401.17264)Background on localized audio watermarking; not implemented or evaluated here
SilentCipher: Deep Audio Watermarking (Interspeech 2024, arXiv 2406.03822)Background on deep audio watermarking; not implemented or evaluated here

Neither watermarking scheme is used here. These references do not validate this short-code design or establish telephone-band performance.

Differences from sibling skills

  • dialtone-handshake proposes an agent-to-agent handshake; this skill illustrates a separate offline spoken-code check without switching modes.
  • call-fraud-shield detects scam patterns in conversations; this skill provides an advisory coordination signal, not counterparty authentication.

© CALLE-AI, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files (scripts, references) in skills/call-attest-challenge-auth of CALLE-AI/awesome-phone-call-agents.

  • SKILL.md
  • references/example-transcript-mismatch.json
  • references/example-transcript.json
  • references/examples.md
  • references/safety.md
  • scripts/attest_auth.py
  • scripts/test_attest_auth.py

Open the folder on GitHubat commit 38d4118

Compare with similar skills

Call Attest Challenge Auth next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Call Attest Challenge Auth compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Call Attest Challenge Auth this skillCALLE-AI/awesome-phone-call-agents107—~1.1kAutomated safety check: PassMIT
Iron Proxy Gateway for NanoClawnanocoai/nanoclaw31k—~4.6kAutomated safety check: NotesMIT
LangBot Deployment Guidelangbot-app/LangBot18k—~1.5kAutomated safety check: NotesApache-2.0
Env Var Conventionssgl-project/sglang37k2 repos~2.9kAutomated safety check: PassApache-2.0
Mac Fleet Maintenancesteipete/agent-scripts7.3k—~4.8kAutomated safety check: PassMIT
Add Config Env Varbaserow/baserow6.1k—~1.1kAutomated safety check: PassCustom licence

Similar skills

  • Installs or refreshes Iron Proxy and its Iron Control web console for NanoClaw, with a local Docker setup, database, credentials and a human approval bridge.

    31k GitHub stars~4.6k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes
  • LangBot Deployment Guide

    langbot-app/LangBot

    Deploys and configures a LangBot instance with Docker Compose or Kubernetes, covering config.yaml, the Box sandbox runtime, the plugin runtime and the global API key.

    18k GitHub stars~1.5k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Env Var Conventions

    sgl-project/sglang

    Conventions for SGLang environment variables — where to define, how to access, how to name, and how to deprecate.

    37k GitHub starsUsed in 2 repos~2.9k tokens
    DevOps & CloudAuto-check passed
  • Mac Fleet Maintenance

    steipete/agent-scripts

    Inventories and maintains a fleet of Macs from a desired-state file: package updates, repo and Xcode sync, and disk, backup and security health reports.

    7.3k GitHub stars~4.8k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Add Config Env Var

    baserow/baserow

    Add a Baserow configuration environment variable for the backend, frontend, or both, and propagate it through settings, Nuxt runtime config, Docker Compose, documentation, consumers, and tests as…

    6.1k GitHub stars~1.1k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • Edgeone Makers CLI

    TencentEdgeOne/edgeone-makers-tools

    EdgeOne Makers CLI command reference. An agent skill from TencentEdgeOne/edgeone-makers-tools.

    1.9k GitHub starsUsed in 1 repo~739 tokens
    DevOps & CloudAuto-check: notes

More from CALLE-AI/awesome-phone-call-agents

All 101 skills in this repo
  • Accessible Outing Verifier

    CALLE-AI/awesome-phone-call-agents

    Demonstrates advisory accessibility-planning checks with offline fixtures and a proposed bounded CALL-E workflow; use for exploring unknown or qualified venue claims without making calls.

    107 GitHub stars~1.4k tokensUpdated yesterday
    Auto-check passed
  • Ground Truth Gate

    CALLE-AI/awesome-phone-call-agents

    A skill your agent uses when an agent holds some evidence for a physical-world claim but the evidence is broader, narrower, or older than the exact question asked, and it must first decide whether a…

    107 GitHub stars~3.3k tokensUpdated yesterday
    Auto-check passed
  • Is It Accessible

    CALLE-AI/awesome-phone-call-agents

    Call a venue and ask the accessibility questions that matter to one specific person — step-free entry, hearing loop, guide dogs, quiet hours, changing places — then return a per-need verdict backed…

    107 GitHub stars~4.3k tokensUpdated yesterday
    Auto-check passed
  • Landmark Navigation Assist

    CALLE-AI/awesome-phone-call-agents

    Turns a pre-written, building-level location config into a CALL-E outbound phone-call task that guides a delivery driver through the last few hundred metres to a specific building using landmarks…

    107 GitHub stars~1.6k tokensUpdated yesterday
    Auto-check passed
  • Research Gap Call Verifier

    CALLE-AI/awesome-phone-call-agents

    Turn cited business research into a bounded, approval-gated phone-call plan that asks only unresolved factual questions, then reconcile CALL-E-compatible results without treating voicemail, refusal…

    107 GitHub stars~1.7k tokensUpdated yesterday
    Auto-check passed
  • Structured Outcome Followup Call

    CALLE-AI/awesome-phone-call-agents

    Place a goal-driven CALL-E call that collects specific structured answers, score those answers against a deterministic rubric you supply, and conditionally trigger a follow-up action — all runnable…

    107 GitHub stars~1.4k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Call Attest Challenge Auth

What does Call Attest Challenge Auth do?

Offline experimental spoken-code coordination illustration for CALL-E workflows. Call Attest Challenge Auth is an agent skill from CALLE-AI/awesome-phone-call-agents. Offline experimental spoken-code coordination illustration for CALL-E workflows.

When should I use Call Attest Challenge Auth?

Call Attest Challenge Auth fits situations like: tasks that involve Secrets management.

How do I install Call Attest Challenge Auth in Claude Code?

Run `npx skills add CALLE-AI/awesome-phone-call-agents --skill call-attest-challenge-auth -a claude-code`. Or copy the skill folder (skills/call-attest-challenge-auth in CALLE-AI/awesome-phone-call-agents) into .claude/skills/call-attest-challenge-auth in your project. Claude Code loads it when a task matches its description.

How do I install Call Attest Challenge Auth in Codex?

Run `npx skills add CALLE-AI/awesome-phone-call-agents --skill call-attest-challenge-auth -a codex`. Or copy the skill folder (skills/call-attest-challenge-auth in CALLE-AI/awesome-phone-call-agents) into .agents/skills/call-attest-challenge-auth in your project. Codex loads it when a task matches its description.

Can I use Call Attest Challenge Auth in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add CALLE-AI/awesome-phone-call-agents --skill call-attest-challenge-auth -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/call-attest-challenge-auth, .gemini/skills/call-attest-challenge-auth, .github/skills/call-attest-challenge-auth and .opencode/skills/call-attest-challenge-auth in your project.

What does Call Attest Challenge Auth need to run?

Going by SKILL.md and its folder, Call Attest Challenge Auth needs Python for the scripts in its folder, the command-line tools its instructions call (python3) and credentials named CALL_ATTEST_SECRET. Our summary lists: Python 3; A credential in CALL_ATTEST_SECRET.

Does Call Attest Challenge Auth access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Call Attest Challenge Auth safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Call Attest Challenge Auth use?

Call Attest Challenge Auth is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Call Attest Challenge Auth use?

About 1.1k tokens (SKILL.md is roughly 4.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.9k tokens, read only when the agent opens those files.

What are the alternatives to Call Attest Challenge Auth?

Skills that share tags, products or a category with Call Attest Challenge Auth: Iron Proxy Gateway for NanoClaw (nanocoai/nanoclaw, 31k stars), LangBot Deployment Guide (langbot-app/LangBot, 18k stars), Env Var Conventions (sgl-project/sglang, 37k stars) and Mac Fleet Maintenance (steipete/agent-scripts, 7.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Call Attest Challenge Auth?

CALLE-AI (a GitHub organization) maintains it in CALLE-AI/awesome-phone-call-agents, which has 107 GitHub stars. The repository holds 101 skills in this directory. The repository was last updated on October 10, 2026.

Source: CALLE-AI/awesome-phone-call-agents on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.