asr-sentence-recognition

Fail

Audited by Socket on Mar 19, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
references/tencent_cloud_activation.md

This document is a clear, concise user guide for enabling Tencent Cloud ASR and retrieving API credentials. It does not contain executable or obfuscated code and shows no intrinsic malware. The primary security issue is operational: the guide encourages or permits users to paste their SecretId/SecretKey/AppId into chat/LLM and to store screenshots with potential credential exposure. That practice significantly increases the risk of credential leakage via chat logs, telemetry, or persistent assets. Recommend revising the guide to prohibit posting secrets to chat, require secure local configuration or vault usage, redact credentials in any screenshots, and provide safer alternatives for agent-assisted configuration.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 19, 2026, 08:51 AM
Package URL
pkg:socket/skills-sh/TencentCloud%2Ftencentcloud-speech-skills%2Fasr-sentence-recognition%2F@ed239296e84fc4e155e1dfa49167de0b84a78838