recordly
Warn
Audited by Socket on Sep 19, 2026
1 alert found:
AnomalyAnomalyscripts/install_recordly.sh
LOWAnomalyLOW
scripts/install_recordly.sh
The fragment is a conventional application installer but has meaningful supply-chain risk because it clones or updates an unpinned remote repository and executes npm installation and build scripts. Removing macOS quarantine is a notable security weakness. There is no direct evidence of malware, credential theft, exfiltration, or sabotage in the supplied script; the primary risk depends on the contents and future state of the referenced repository and its dependencies.
Confidence: 97%Severity: 62%
Audit Metadata