Flatsonar

Doubao Murmur

by lilong7676

Voice-to-text input using Doubao ASR

Dangerous permissions Unverified publisher MIT v1.5.1

About

Doubao Murmur is a voice-to-text input tool that uses Doubao's ASR (Automatic Speech Recognition) service to convert speech to text in real-time. Press the right Alt key to start dictating from anywhere; the transcription appears in a floating overlay and is pasted into whatever application had focus.

Permissions

4 permissions weaken the sandbox. Flatsonar asks before installing.

  • all devices (/dev): webcams, disks, raw hardware
    --device=all
  • sandbox escape: can run commands on the host via flatpak-spawn
    --talk-name=org.freedesktop.Flatpak
  • X11 display: X11 lets apps read input and windows of other apps
    --socket=x11
  • sets PYTHONPATH: changes which libraries or plugins get loaded
    --env=PYTHONPATH=/app/lib/python/site-packages
  • Wayland display
    --socket=wayland
  • inter-process communication (needed for X11)
    --share=ipc
  • GPU acceleration
    --device=dri
  • audio
    --socket=pulseaudio
  • network
    --share=network
  • access to xdg-config/doubao-murmur
    --filesystem=xdg-config/doubao-murmur:create
  • notifications
    --talk-name=org.freedesktop.Notifications
  • portal Desktop
    --talk-name=org.freedesktop.portal.Desktop
  • system tray
    --talk-name=org.kde.StatusNotifierWatcher
  • sets environment variable GDK_BACKEND
    --env=GDK_BACKEND=x11

Who publishes this

Nobody has confirmed that the publisher controls this app id. Flatsonar warns before installing.

  • com.doubao.Murmur claims the domain doubao.com; only its owner can prove that
    publisher:namespace
  • the build has network access: it can download things the manifest does not list
    python-deps:build-options:--share=network
  • fetches from the network during the build (nothing to audit beforehand): pip3 install --no-cache-dir --prefix=/app websockets sounddevice python-xlib
    python-deps:build-commands

Maintenance

Recent activity on the upstream repository, or built and reviewed by Flathub.

No staleness signals: recent activity, or built and reviewed by Flathub.