yichen-volc-asr

Warn

Audited by Socket on Sep 11, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/transcribe.py

The code appears to be a media transcription and automatic editing utility, not malware. It performs expected but privacy-sensitive uploads of local media and sends configured ASR credentials to the fixed Volcengine API. The attempt to make uploaded objects publicly accessible is a significant security and privacy risk and should be removed or replaced with authenticated/private access. The provided fragment also cannot run due to syntax errors in acl_xml assignment and the final main() call. No evidence of unrelated exfiltration, persistence, command injection, reverse shell, or destructive behavior was found.

Confidence: 98%Severity: 62%
Audit Metadata
Analyzed At
Sep 11, 2026, 09:05 AM
Package URL
pkg:socket/skills-sh/mcncarl%2Fyichen-skills%2Fyichen-volc-asr%2F@1bf720ca43b5435136f76b2e6959358d64e7be34c5bd547cd9a5d8601a68bf59
Security Audit — socket — yichen-volc-asr