transcript-pipeline
Audited by Socket on Aug 29, 2026
2 alerts found:
Anomalyx2No explicit malware behavior (e.g., obfuscation, exec/subprocess, reverse shells, or direct network exfiltration of secrets) is present in this module. However, it is a high-sensitivity authenticated capture tool: it loads user-provided authentication material, visits/fetches arbitrary manifest-provided URLs without allowlisting, and saves potentially sensitive authenticated artifacts (HTML/screenshots/PDFs/raw Notion chunks) to disk. The main security concern is abuse of credentials and broad targetability if manifests or auth inputs are compromised. Additionally, --dry-run is not fully respected in the Canva path for HTML writing.
SUSPICIOUS. The core transcript-processing pipeline is coherent and mostly local, but the optional enrichment stage introduces disproportionate credential/session access with undocumented endpoint behavior and nonstandard auth patterns for Notion/Canva. No confirmed malware or hostile installer is shown, yet the credential handling and opaque data flow make the skill medium risk overall.