6 min read

Cap: An Open-Source Loom Alternative (GitHub, Scanned)

Record your screen, edit it locally and share a link, with the option to host it all yourself.

Cap logo
✅
Scan: safe. Nothing malicious. Two things to know: the desktop app sends usage events to OpenPanel until you turn telemetry off in its settings, and its Rust dependencies carry several dozen known advisories, mostly denial-of-service bugs in parsers and network crates. Scanned Oct 1, 2026; the full report is below.

Cap is a screen recorder for macOS and Windows built to replace Loom. It records your screen, camera and microphone in two ways: Instant Mode uploads while you record and hands you a share link the moment you stop, and Studio Mode records locally and opens an editor with backgrounds, zooms, trimming and captions before you export. Shared videos get comments, reactions, viewer analytics and AI-generated titles, summaries, chapters and transcripts, and there is an importer for an existing Loom library.

What puts it on this list is that you can own the whole pipeline. Recordings can stay on your machine, go to Cap's own cloud, or land in any S3-compatible bucket you connect (AWS, Cloudflare R2, Backblaze B2, MinIO), and the web side (dashboard, share pages, API and media server) can be self-hosted with one Docker Compose command. The desktop app is built with Tauri and Rust, which keeps it light compared with Electron recorders.

Cap is made by Cap Software, Inc. and has about 23,000 stars. Most of the code is AGPL-3.0, with the camera and screen-capture crates under MIT. The latest desktop release, 0.6.0, came out in September 2026.

  • Repository: github.com/CapSoftware/Cap
  • Licence: custom (Other)
  • Language: Rust. Stars: 23K. Forks: 1,997. Last push: Oct 2, 2026.
  • Scan: safe, Oct 1, 2026, commit a2a6bd8

Who it is for

Product, support and engineering teams who explain things on video every day, and anyone paying for Loom who would rather keep recordings in their own storage or on their own server.

Getting started

1. Desktop: download the app for macOS or Windows, sign in, and pick Instant or Studio Mode

open https://cap.so/download

2. Self-host the web side: clone the repository and start the stack

git clone https://github.com/CapSoftware/Cap.git && cd Cap && docker compose up -d

3. Open it, then read the login link from the logs (email is not configured yet)

open http://localhost:3000 && docker compose logs cap-web

4. Point the desktop app at your server under Settings > Cap Server URL

# Settings > Cap Server URL > http://your-server:3000

The Compose file ships with default secrets. Before exposing a self-hosted instance to the internet, set CAP_URL and S3_PUBLIC_URL to your own domains and replace those secrets, as the README warns.

Safety scan

We cloned CapSoftware/Cap at commit a2a6bd8 on Oct 1, 2026 and ran the checks described on the GitHub Tools page: credential patterns, decode-and-execute code, install-time scripts, committed binaries, risky CI workflows, every host the code talks to, known vulnerabilities in pinned dependencies, and project hygiene. A person read every hit. This is what we found.

  • No secrets, no packed or self-decoding code and no bare-IP URLs across about 1.25 million lines of Rust and TypeScript in 4,589 files. The four pattern hits are one string: the curl | sh one-liner for Cap's own CLI installer (cap.so/install-cli.sh), shown as text on the download page, in agent documentation and in a test. Nothing in the repository runs it.
  • One committed binary, crates/rnnoise/vendor/weights.bin (3.5 MB), is the RNNoise noise-suppression model from Xiph, generated with upstream's own tool; the crate's README records the upstream revision and the file's SHA-256 so it can be checked. The six Cargo build scripts compile native code for the desktop app, the CLI and crates such as rnnoise, as Rust projects normally do.
  • We read the desktop analytics in apps/desktop/src/utils/analytics.ts. It sends explicit events to OpenPanel with screen views, outgoing links and element attributes turned off, and both the event calls and a send filter respect the enableTelemetry setting, which defaults to on. Recordings themselves go only where you configure them: Cap Cloud, your own S3-compatible bucket, or your own server.
  • 61 known advisories, none critical (14 high). 57 sit in the main Cargo.lock: rust-openssl 0.10.73 (five high, memory-safety bugs in specific APIs such as AES key wrap and key derivation), quick-xml, quinn-proto and rustls-webpki, mostly denial of service on malformed input and fixed by version bumps. The npm advisory is braces in an agent-skills folder, not part of the app.
  • 16 workflows, none using pull_request_target or write-all permissions; 6 of 37 third-party actions are pinned to a commit. Licence and contributing guide present; no security policy, Dependabot or CodeQL.

What the scanner counted

CheckResult
SecretsNone found.
Suspicious code4 pattern hits found and read; every one is listed under the raw findings.
Install-time code6 Cargo build scripts. 1 installer script
Committed binaries1 executable or compiled object committed; listed under the raw findings.
CI workflows16 workflows. None use pull_request_target. 31 of 37 third-party actions pinned to a tag rather than a commit.
Network hosts40 distinct hosts referenced from source; most often cap.so, www.loom.com, github.com, cap.test. No URLs to bare IP addresses.
Known vulnerabilities61 advisories across 2,041 pinned packages: 0 critical, 14 high, 15 moderate, 7 low, 25 unrated. .agents/skills/building/package-lock.json: 189 packages, 1 advisories; Cargo.lock: 1,249 packages, 57 advisories; apps/cli/skill/cap-demo/package-lock.json: 1 packages, 0 advisories; apps/desktop-gpui/Cargo.lock: 1,274 packages, 22 advisories.
Project hygieneHas licence file, contributing guide. Missing security policy, automated dependency updates, CodeQL.
OpenSSF ScorecardNot scored: the project is not in Scorecard's weekly index.

The raw findings

Every hit the scanner wrote out, with a link to the exact line at the scanned commit. Secrets candidates are redacted.

Pattern hits (4)
WhereRuleMatch
apps/web/__tests__/unit/agent-docs.test.ts:207download-piped-to-shell (test/example)"curl -fsSL https://cap.so/install-cli.sh | sh",
apps/web/components/pages/DownloadPage.tsx:29download-piped-to-shell: "curl -fsSL https://cap.so/install-cli.sh | sh";
apps/web/components/pages/agents/content.ts:47download-piped-to-shellunix: "curl -fsSL https://cap.so/install-cli.sh | sh",
apps/web/data/agent-prompt.ts:21download-piped-to-shell- macOS or Linux: curl -fsSL https://cap.so/install-cli.sh | sh
Installer scripts (1)
Committed binaries (1)
  • crates/rnnoise/vendor/weights.bin: .bin, 4 MB
Worst known vulnerabilities (24 of 61)
AdvisorySeverityPackageSummary
GHSA-vfj7-8cjw-p6xmhighbraces@3.0.3braces vulnerable to stack-exhaustion denial of service through deeply nested patterns
GHSA-vvp9-7p8x-rfvvhighlz4_flex@0.11.5lz4_flex's decompression can leak information from uninitialized memory or reused output buffer
GHSA-8c75-8mhr-p7r9highopenssl@0.10.73rust-openssl has incorrect bounds assertion in aes key wrap
GHSA-ghm9-cr32-g9qjhighopenssl@0.10.73rust-openssl: rustMdCtxRef::digest_final() writes past caller buffer with no length check
GHSA-hppc-g8h3-xhp3highopenssl@0.10.73rust-openssl: Unchecked callback length in PSK/cookie trampolines leaks adjacent memory to peer
GHSA-pqf5-4pqq-29f5highopenssl@0.10.73rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1
GHSA-xp3w-r5p5-63rrhighopenssl@0.10.73rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs
RUSTSEC-2026-0194highquick-xml@0.37.5Quadratic run time when checking a start tag for duplicate attribute names
RUSTSEC-2026-0195highquick-xml@0.37.5Unbounded namespace-declaration allocation in `NsReader` enables memory-exhaustion denial of service
RUSTSEC-2026-0194highquick-xml@0.38.3Quadratic run time when checking a start tag for duplicate attribute names
RUSTSEC-2026-0195highquick-xml@0.38.3Unbounded namespace-declaration allocation in `NsReader` enables memory-exhaustion denial of service
GHSA-4w2j-m93h-cj5jhighquinn-proto@0.11.13Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly
GHSA-6xvm-j4wr-6v98highquinn-proto@0.11.13Quinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsing
GHSA-82j2-j2ch-gfr8highrustls-webpki@0.103.6rustls-webpki: Denial of service via panic on malformed CRL BIT STRING
GHSA-xhj4-vrgc-hr34moderateactix-http@3.11.1actix-http has HTTP/1.1 CL.TE Request Smuggling
GHSA-434x-w66g-qw3rmoderatebytes@1.10.1bytes has integer overflow in BytesMut::reserve
GHSA-wrw7-89jp-8q8gmoderateglib@0.18.5Unsoundness in `Iterator` and `DoubleEndedIterator` impls for `glib::VariantStrIter`
GHSA-phqj-4mhp-q6mqmoderateopenssl@0.10.73rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers
GHSA-xv59-967r-8726moderateopenssl@0.10.73rust-openssl vulnerable to heap buffer overflow when encrypting with AES key-wrap-with-padding
GHSA-w9wp-h8wv-79jxmoderateopentelemetry_sdk@0.31.0opentelemetry_sdk has unbounded memory allocation in W3C Baggage propagation
GHSA-2mjx-qc3c-rqvcmoderaterustls@0.23.31TLS 1.3 handshake messages incorrectly accepted across encryption level boundaries
GHSA-pwjx-qhcg-rvj4moderaterustls-webpki@0.103.6webpki: CRLs not considered authoritative by Distribution Point due to faulty matching logic
GHSA-7gcf-g7xr-8hxjmoderateserde_with@3.14.0serde_with: KeyValueMap serialization panics on empty sequence or map entries
GHSA-3pv8-6f4r-ffg2moderatetar@0.4.44tar has a PAX header desynchronization issue

By the numbers

Stars23K
Forks1,997
Contributors81
Commits8,975
Open issues208
Open pull requests215
Releases83
Latest releasecap-v0.6.0
Licencecustom
Main languageRust
Project age2 years
Last pushOct 2, 2026
Tracked files4,589
Lines of code1.3M
Checkout size179 MB

Lines by language: Rust 529.1K, TypeScript 501.4K, JSON 162.2K, JavaScript 21.1K, Markdown 14.7K, CSS 6,947.

Questions

Is Cap free?

For personal use, yes: the desktop app is free with no time limit on local recordings. Commercial use of the desktop app needs a Desktop License at $29 a year or $58 once, and Cap Pro, which adds Cap's cloud sharing, is $12 per user a month. The source code is AGPL-3.0, so self-hosting the web platform costs only your own server and storage.

Can Cap import my Loom videos?

Yes. Cap has a Loom importer that brings existing Loom videos into your Cap library, so you can move without losing old recordings. Cap also offers a Loom video downloader among its free tools on cap.so.

Where are Cap recordings stored?

Where you choose. Studio Mode recordings stay on your computer until you export or share them. Shared videos go to Cap Cloud by default, or to an S3-compatible bucket you connect, such as AWS S3, Cloudflare R2, Backblaze B2 or MinIO, or to a fully self-hosted Cap instance.


This post is part of GitHub Tools, where every repository is cloned and scanned before it is written up. The scan is a snapshot of one commit on one day; the repository has moved on since, so check it before you install.