Is chat-recall safe?
Probably. Read the findings first.
Use with care. Some checks failed or could not be verified.
What to know before installing
- highcurl | sh in a script
- highShell command built from a string (injection risk)
Public scan report
scanner v0.1.3 · 2026-09-19 · same rubric, same numbers if you re-run it
2 high
- Code scan97 source files scanned1/25
- Live reliabilityremote reachable in 653ms (auth required)20/20
- –Tool poisoningtools not inspected (endpoint requires auth); not countedn/a
- Auth qualityOAuth resource metadata advertised on 40115/15
- Maintenancelast push 3 days ago15/15
- Maintainer identityregistry namespace matches repository owner7/10
Findings (2)
- highcurl | sh in a script
install.curl-pipedist/cli.js: …chat-recall (or re-run the installer: curl -fsSL ${targets[0].serverUrl.replace(/\/+$/, "")}/install | sh)`)); } if (check) { const own =… - highShell command built from a string (injection risk)
exec.shell-concatdist/cli.js: …function git(toplevel, args) { return execSync(`git ${args}`, { cwd: toplevel, stdio: …
Overall 68/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON