The Xiaomi MiClaw team recently launched a new system input method, but the engineers responsible for developing the input method may face low performance appraisals because the input method directly exposes the API platform token called by Xiaomi. After testing, NS netizens found that they only need to frantically click on the version number of the input method to open the debugging page. In the debugging page, Xiaomi has already written the API call address, model provider, API KEY, model name, prompt words, etc.

112392-1A.png112392-2.png

Judging from the prompt words, this input method seems to focus on voice input? The prompt says: You are a speech recognition post-processing assistant. Please correct typos and grammatical errors in the input text, add appropriate punctuation according to tone and grammar, and keep the original meaning unchanged. Only the corrected text is output, no explanation is required.

The API KEY has been tested when the netizen posted the post. The test shows that the KEY is real and effective and can be called on other platforms, and there are many types of models launched by Xiaomi. However, Xiaomi is estimated to have replaced the leaked KEY at this time.

In addition, the Xiaomi team also made a classic mistake: accidentally exposing the plain text KEY when submitting the code to GitHub. From the code, it can be seen that the API platform of the Dark Side of the Moon was leaked. The submission time of the code to which this KEY belongs was still January 2025, and no change records were seen after that.

Judging from these circumstances, these mistakes made by the Xiaomi team are indeed a bit low-level. I don’t know if they are the result of using AI-assisted coding. If a company of Xiaomi’s size will easily make such mistakes, it is estimated that we will see more similar things in the future.