recordly

Fail

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: HIGHPRIVILEGE_ESCALATIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
  • [PRIVILEGE_ESCALATION]: The installation script scripts/install_recordly.sh uses xattr -rd com.apple.quarantine to remove the macOS quarantine flag from the built application. This is a deliberate bypass of platform security controls designed to protect users from unverified software.\n- [REMOTE_CODE_EXECUTION]: The skill performs an npm install and npm run build after cloning an external repository (github.com/webadderall/Recordly). This executes potentially arbitrary lifecycle scripts and build commands from the remote source on the local system.\n- [EXTERNAL_DOWNLOADS]: The skill fetches various resources from remote servers: Clones application source code from a GitHub repository; fetches rendering libraries from the JSDelivr CDN; and downloads environment maps from Poly Haven.\n- [DYNAMIC_EXECUTION]: The installation process involves runtime compilation and building of the application source code using npm run build, which generates executable assets dynamically on the host machine.\n- [COMMAND_EXECUTION]: The skill relies on shell scripts to perform complex system operations including git clone, npm install, chmod, find, and application launching via open or direct execution of AppImage binaries.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 19, 2026, 02:41 PM
Security Audit — agent-trust-hub — recordly