volc-audio-transcription

Fail

Audited by Socket on Mar 25, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
scripts/transcribe_local.py

No explicit signs of covert malware or backdoor functionality were found. The code's primary security concern is operational: it intentionally exposes local files by serving a directory and publishing it via ngrok, which can lead to accidental data leakage if run from a directory containing sensitive files. API keys are transmitted to an expected third-party endpoint (over HTTPS). Follow operational hygiene (use dedicated directory, limit exposure, validate responses) before using this script.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 25, 2026, 05:33 AM
Package URL
pkg:socket/skills-sh/sk123qaq%2Fuseful_skill%2Fvolc-audio-transcription%2F@74d27c769256b10e51baf5aa1c0ed287bc7d1831