yichen-volc-asr
Warn
Audited by Socket on Sep 11, 2026
1 alert found:
AnomalyAnomalyscripts/transcribe.py
LOWAnomalyLOW
scripts/transcribe.py
The code appears to be a media transcription and automatic editing utility, not malware. It performs expected but privacy-sensitive uploads of local media and sends configured ASR credentials to the fixed Volcengine API. The attempt to make uploaded objects publicly accessible is a significant security and privacy risk and should be removed or replaced with authenticated/private access. The provided fragment also cannot run due to syntax errors in acl_xml assignment and the final main() call. No evidence of unrelated exfiltration, persistence, command injection, reverse shell, or destructive behavior was found.
Confidence: 98%Severity: 62%
Audit Metadata