speech-to-text
Audited by Socket on Feb 25, 2026
1 alert found:
MalwareThe content documents a CLI-driven workflow that transmits user audio and local inputs to inference.sh hosted transcription apps. There is no direct evidence of embedded malware in the provided documentation fragment, but the distribution and usage patterns present significant supply-chain and privacy risks: a pipe-to-shell installer (curl | sh) and externally-hosted binaries increase the chance of arbitrary code execution if the distribution is compromised; authentication and data-retention practices are undocumented, creating credential and data-exposure concerns. For sensitive use, do not use the quickstart pipe-to-shell flow without manual checksum verification; prefer audited installs, local transcription, or reviewing the service's security/privacy posture first.