
Product
PHP and Composer Support Is Now in Beta
Socket’s PHP and Composer support is now in Beta for all customers, with PHP reachability analysis generally available.
Unofficial Plaud exporter for JSON-first bulk transcript and summary workflows, plus single-recording audio downloads
Export, sync, search, and de-duplicate Plaud recordings with speaker-labeled transcripts and optional AI summaries.
Plaud now ships official tooling. For supported auth and general terminal use, start with Plaud's official CLI:
npm install -g @plaud-ai/cli
Official docs:
This package remains an unofficial advanced exporter for JSON-first and bulk workflows that Plaud's official CLI does not yet cover. Use it when you specifically need stable machine-readable output, bulk transcript/summary export, ZIP export, or the packaged agent skill.
This is an unofficial project (not affiliated with Plaud). It uses a captured Plaud bearer token and private web endpoints, so it may break if Plaud changes their web app.
Operational note: Plaud's private web API may reject non-browser request fingerprints at the edge even when the bearer token is valid. The CLI sends browser-like request headers, including a web user-agent, to match Plaud's web app requests.
Security note: do not share tokens or *.har files (HARs often contain Authorization headers).
Plaud’s web UI uses “Files”. This CLI uses files as the primary command group, with recordings kept as an alias for compatibility: plaud files … (preferred) or plaud recordings ….
Global (recommended for frequent use):
npm i -g plaud
plaud auth login
No install (convenient for agents/one-offs):
npx -y plaud auth status --json
npx -y skills add -g danielgwilson/plaud --skill plaud
This repo is configured for npm trusted publishing from GitHub Actions.
.github/workflows/publish.ymlpublish.ymlgit clone https://github.com/danielgwilson/plaud.git
cd plaud
npm install
npm link
Requirements:
Preferred (easy onboarding, stores token locally):
plaud auth login
Verify:
plaud auth status
plaud doctor
Fallbacks:
plaud auth set --stdin
plaud auth import-har /path/to/web.plaud.ai.har
Or via env var (no local storage):
export PLAUD_AUTH_TOKEN="eyJ..."
Tip (Node 22+): you can also use Node’s --env-file if you want to load a local .env without adding any dependency to the CLI:
node --env-file .env "$(command -v plaud)" auth status --json
Create a single ZIP (default):
plaud files export --zip
Export to a directory:
plaud files export --out ./plaud-transcripts --formats txt,json,md
plaud files list --json --limit 10
plaud files download <id> --out ./plaud-download --what transcript,summary,json
plaud files download <id> --out ./plaud-download --what audio --audio-format opus
For larger libraries, sync file details into a private local store. The store is local-only, content-addressed, and kept outside the current working directory by default. By default, sync stores readable JSON details, transcripts, and summaries on your machine with restrictive file permissions.
plaud files sync
plaud files search "project kickoff"
plaud files search "project kickoff" --snippets
plaud files dupes --by content
plaud store status
plaud store path
plaud store verify
The default store location follows the OS data directory conventions. You can override it per command or process:
plaud files sync --store ./scratch-store --max 50
PLAUD_STORE_DIR=./scratch-store plaud files search "follow up"
De-dupe is intentionally conservative:
plaud files dupes --by content groups matching transcript/summary contentplaud files dupes --by snapshot only groups fully identical snapshotsSearch output is metadata-only by default. Search itself uses available local title, transcript, summary, tag, and speaker text. Pass --snippets only when you want transcript/summary excerpts in stdout. Use --ids-only for compact agent-safe result lists.
Search is a candidate generator, not proof of exhaustive coverage. Every files search --json response includes data.coverage and meta.coverageWarnings; agents should read those fields before claiming they found "all" matching recordings.
Important recall traps:
Speaker 1 / Speaker 2 segments can hide relevant recordingsdata.coverage.riskFactors.truncated means more candidate entries existed than were returned; increase --limit before treating the set as reviewedFor "all", "complete", or "thorough" retrieval tasks, include a coverage receipt in your answer: the queries and filters you used, broad result counts, confirmed IDs, suspected misses, and the lossy filters/search fields that limit the claim.
Use plaud store clear --yes to delete the local store. This never clears Plaud cloud data, and the command refuses dangerous paths such as /, your home directory, and the current working directory.
Notes:
plaud files export prints a JSON summary to stdout; progress goes to stderr.plaud files sync prints a JSON summary to stdout; progress goes to stderr.plaud recordings … is supported as an alias for plaud files ….)~/.config/plaud/config.json with 0600 permissions.See docs/CONTRACT_V1.md.
FAQs
Unofficial Plaud exporter for JSON-first bulk transcript and summary workflows, plus single-recording audio downloads
The npm package plaud receives a total of 178 weekly downloads. As such, plaud popularity was classified as not popular.
We found that plaud demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Product
Socket’s PHP and Composer support is now in Beta for all customers, with PHP reachability analysis generally available.

Product
Socket is bringing experimental protection to Firefox, scanning 97,000+ extensions in Mozilla's official directory for malware and risky updates.

Research
/Security News
Three compromised Rust crates pulled in a malicious dependency that downloaded and executed cross-platform malware during Cargo builds.