Security audit
Amazon Transcribe Provider
Security checks for vulnerabilities and agentic risk
Overview
This plugin transparently adds Amazon Transcribe support and its sensitive audio handling is expected, documented, and user-configured.
Install only if your deployment is allowed to send voice-note audio to AWS. Use a dedicated S3 bucket, least-privilege IAM limited to the configured prefix, server-side encryption and lifecycle cleanup, and prefer IAM roles or environment credentials over storing static keys in plugin config.
Static analysis
No suspicious patterns detected.
