file-transcribe

Warn

Audited by Socket on May 16, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
transcribe.mjs

No clear evidence of malware, backdoors, or supply-chain sabotage is present in this module. The dominant security concerns are operational/intentional but sensitive: it reads a local JWT secret and transmits it to a remote proxy, it sends user-provided audio URLs for transcription, it logs transcript previews that may contain sensitive content, and it executes ffprobe/ffmpeg on untrusted media paths (expanding the trust boundary to external binaries). Overall, this looks like a legitimate transcription utility with moderate security risk driven by credential handling, PII exposure in logs, and reliance on ffmpeg/ffprobe for untrusted inputs.

Confidence: 68%Severity: 52%
AnomalyLOW
SKILL.md

SUSPICIOUS. The capability mostly matches the stated purpose, and the local tooling footprint is modest, but the core data flow sends user media through an OpenKBS proxy/preview server rather than a clearly documented official Whisper endpoint. That proxy design is proportionate to transcription but insufficiently transparent, creating medium risk around data handling and trust.

Confidence: 82%Severity: 61%
Audit Metadata
Analyzed At
May 16, 2026, 08:02 AM
Package URL
pkg:socket/skills-sh/open-kbs%2Fskills-file-transcribe%2Ffile-transcribe%2F@1d6f1100892ed015f6354aa8e27f2de68fc114a8
Security Audit — socket — file-transcribe