embry-voice-control
Warn
Audited by Socket on Aug 26, 2026
1 alert found:
SecuritySecuritysrc/embry_voice_control/listener_service.py
MEDIUMSecurityMEDIUM
src/embry_voice_control/listener_service.py
No direct evidence of malicious behavior or supply-chain malware is present. The code implements an event-journal HTTP API, but the visible routes have no authentication or authorization and expose potentially sensitive journal and audio data while permitting event and consumer-state mutations. These are significant deployment security concerns if the service is reachable by untrusted clients. The fragment also appears syntactically incomplete at the end; review the imported helper modules and deployment controls for integrity, path validation, and access control.
Confidence: 98%Severity: 72%
Audit Metadata