asr-sentence-recognition
Audited by Socket on Mar 19, 2026
1 alert found:
Obfuscated FileThis document is a clear, concise user guide for enabling Tencent Cloud ASR and retrieving API credentials. It does not contain executable or obfuscated code and shows no intrinsic malware. The primary security issue is operational: the guide encourages or permits users to paste their SecretId/SecretKey/AppId into chat/LLM and to store screenshots with potential credential exposure. That practice significantly increases the risk of credential leakage via chat logs, telemetry, or persistent assets. Recommend revising the guide to prohibit posting secrets to chat, require secure local configuration or vault usage, redact credentials in any screenshots, and provide safer alternatives for agent-assisted configuration.