
Research
/Security News
Malicious Chrome and Firefox Extensions Steal Crypto Traders’ Session and Wallet Data
Malicious Chrome and Firefox extensions target Axiom Trade and Padre users, stealing session tokens and wallet data.
Unofficial advanced Plaud exporter for JSON-first and bulk transcript, summary, and audio workflows
Export, sync, search, and de-duplicate Plaud recordings with speaker-labeled transcripts and optional AI summaries.
Plaud now ships official tooling. For supported auth and general terminal use, start with Plaud's official CLI:
npm install -g @plaud-ai/cli
Official docs:
This package remains an unofficial advanced exporter for JSON-first and bulk workflows that Plaud's official CLI does not yet cover. Use it when you specifically need stable machine-readable output, bulk transcript/summary export, ZIP export, or the packaged agent skill.
This is an unofficial project (not affiliated with Plaud). It uses a captured Plaud bearer token and private web endpoints, so it may break if Plaud changes their web app.
Operational note: Plaud's private web API may reject non-browser request fingerprints at the edge even when the bearer token is valid. The CLI sends browser-like request headers, including a web user-agent, to match Plaud's web app requests.
Security note: do not share tokens or *.har files (HARs often contain Authorization headers).
Plaud’s web UI uses “Files”. This CLI uses files as the primary command group, with recordings kept as an alias for compatibility: plaud files … (preferred) or plaud recordings ….
Global (recommended for frequent use):
npm i -g plaud
plaud auth login
No install (convenient for agents/one-offs):
npx -y plaud auth status --json
npx -y skills add -g danielgwilson/plaud --skill plaud
This repo is configured for npm trusted publishing from GitHub Actions.
.github/workflows/publish.ymlpublish.ymlcd plaud/plaud-cli
npm install
npm link
Requirements:
Preferred (easy onboarding, stores token locally):
plaud auth login
Verify:
plaud auth status
plaud doctor
Fallbacks:
plaud auth set --stdin
plaud auth import-har /path/to/web.plaud.ai.har
Or via env var (no local storage):
export PLAUD_AUTH_TOKEN="eyJ..."
Tip (Node 22+): you can also use Node’s --env-file if you want to load a local .env without adding any dependency to the CLI:
node --env-file .env "$(command -v plaud)" auth status --json
Create a single ZIP (default):
plaud files export --zip
Export to a directory:
plaud files export --out ./plaud-transcripts --formats txt,json,md
plaud files list --json --limit 10
plaud files download <id> --out ./plaud-download --what transcript,summary,json
plaud files download <id> --out ./plaud-download --what audio --audio-format opus
For larger libraries, sync file details into a private local store. The store is local-only, content-addressed, and kept outside the current working directory by default. By default, sync stores readable JSON details, transcripts, and summaries on your machine with restrictive file permissions.
plaud files sync
plaud files search "project kickoff"
plaud files search "project kickoff" --snippets
plaud files dupes --by content
plaud store status
plaud store path
plaud store verify
The default store location follows the OS data directory conventions. You can override it per command or process:
plaud files sync --store ./scratch-store --max 50
PLAUD_STORE_DIR=./scratch-store plaud files search "follow up"
De-dupe is intentionally conservative:
plaud files dupes --by content groups matching transcript/summary contentplaud files dupes --by snapshot only groups fully identical snapshotsSearch results are metadata-only by default. Pass --snippets only when you want transcript/summary excerpts in stdout. Use --ids-only for compact agent-safe result lists.
Use plaud store clear --yes to delete the local store. This never clears Plaud cloud data, and the command refuses dangerous paths such as /, your home directory, and the current working directory.
Notes:
plaud files export prints a JSON summary to stdout; progress goes to stderr.plaud files sync prints a JSON summary to stdout; progress goes to stderr.plaud recordings … is supported as an alias for plaud files ….)~/.config/plaud/config.json with 0600 permissions.See docs/CONTRACT_V1.md.
FAQs
Unofficial Plaud exporter for JSON-first bulk transcript and summary workflows, plus single-recording audio downloads
The npm package plaud receives a total of 45 weekly downloads. As such, plaud popularity was classified as not popular.
We found that plaud demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Malicious Chrome and Firefox extensions target Axiom Trade and Padre users, stealing session tokens and wallet data.

Security News
GPT-6 Astra hits 100% on ExploitBench and finds zero-days autonomously, while independent tests reveal scope violations and monitoring gaps.

Product
Socket can now send alerts and supply chain attack notifications to Microsoft Teams, with filters that route the right updates to each channel.