recordly

Warn

Audited by Socket on Sep 19, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/install_recordly.sh

The fragment is a conventional application installer but has meaningful supply-chain risk because it clones or updates an unpinned remote repository and executes npm installation and build scripts. Removing macOS quarantine is a notable security weakness. There is no direct evidence of malware, credential theft, exfiltration, or sabotage in the supplied script; the primary risk depends on the contents and future state of the referenced repository and its dependencies.

Confidence: 97%Severity: 62%
Audit Metadata
Analyzed At
Sep 19, 2026, 02:42 PM
Package URL
pkg:socket/skills-sh/tdimino%2Fclaude-code-minoan%2Frecordly%2F@2d253d0dfe6f692a63fd2d53abd3d5bb9efb327e06a7a612caac4d3d0e9a2965
Security Audit — socket — recordly