Back to plugin

Security audit

Amazon Transcribe Provider

Security checks for vulnerabilities and agentic risk

Overview

This plugin transparently adds Amazon Transcribe support and its sensitive audio handling is expected, documented, and user-configured.

Install only if your deployment is allowed to send voice-note audio to AWS. Use a dedicated S3 bucket, least-privilege IAM limited to the configured prefix, server-side encryption and lifecycle cleanup, and prefer IAM roles or environment credentials over storing static keys in plugin config.

Static analysis

No suspicious patterns detected.