Cap is a screen recorder for macOS and Windows built to replace Loom. It records your screen, camera and microphone in two ways: Instant Mode uploads while you record and hands you a share link the moment you stop, and Studio Mode records locally and opens an editor with backgrounds, zooms, trimming and captions before you export. Shared videos get comments, reactions, viewer analytics and AI-generated titles, summaries, chapters and transcripts, and there is an importer for an existing Loom library.
What puts it on this list is that you can own the whole pipeline. Recordings can stay on your machine, go to Cap's own cloud, or land in any S3-compatible bucket you connect (AWS, Cloudflare R2, Backblaze B2, MinIO), and the web side (dashboard, share pages, API and media server) can be self-hosted with one Docker Compose command. The desktop app is built with Tauri and Rust, which keeps it light compared with Electron recorders.
Cap is made by Cap Software, Inc. and has about 23,000 stars. Most of the code is AGPL-3.0, with the camera and screen-capture crates under MIT. The latest desktop release, 0.6.0, came out in September 2026.
- Repository: github.com/CapSoftware/Cap
- Licence: custom (Other)
- Language: Rust. Stars: 23K. Forks: 1,997. Last push: Oct 2, 2026.
- Scan: safe, Oct 1, 2026, commit a2a6bd8
Who it is for
Product, support and engineering teams who explain things on video every day, and anyone paying for Loom who would rather keep recordings in their own storage or on their own server.
Getting started
1. Desktop: download the app for macOS or Windows, sign in, and pick Instant or Studio Mode
open https://cap.so/download2. Self-host the web side: clone the repository and start the stack
git clone https://github.com/CapSoftware/Cap.git && cd Cap && docker compose up -d3. Open it, then read the login link from the logs (email is not configured yet)
open http://localhost:3000 && docker compose logs cap-web4. Point the desktop app at your server under Settings > Cap Server URL
# Settings > Cap Server URL > http://your-server:3000The Compose file ships with default secrets. Before exposing a self-hosted instance to the internet, set CAP_URL and S3_PUBLIC_URL to your own domains and replace those secrets, as the README warns.
Safety scan
We cloned CapSoftware/Cap at commit a2a6bd8 on Oct 1, 2026 and ran the checks described on the GitHub Tools page: credential patterns, decode-and-execute code, install-time scripts, committed binaries, risky CI workflows, every host the code talks to, known vulnerabilities in pinned dependencies, and project hygiene. A person read every hit. This is what we found.
- No secrets, no packed or self-decoding code and no bare-IP URLs across about 1.25 million lines of Rust and TypeScript in 4,589 files. The four pattern hits are one string: the curl | sh one-liner for Cap's own CLI installer (cap.so/install-cli.sh), shown as text on the download page, in agent documentation and in a test. Nothing in the repository runs it.
- One committed binary, crates/rnnoise/vendor/weights.bin (3.5 MB), is the RNNoise noise-suppression model from Xiph, generated with upstream's own tool; the crate's README records the upstream revision and the file's SHA-256 so it can be checked. The six Cargo build scripts compile native code for the desktop app, the CLI and crates such as rnnoise, as Rust projects normally do.
- We read the desktop analytics in apps/desktop/src/utils/analytics.ts. It sends explicit events to OpenPanel with screen views, outgoing links and element attributes turned off, and both the event calls and a send filter respect the enableTelemetry setting, which defaults to on. Recordings themselves go only where you configure them: Cap Cloud, your own S3-compatible bucket, or your own server.
- 61 known advisories, none critical (14 high). 57 sit in the main Cargo.lock: rust-openssl 0.10.73 (five high, memory-safety bugs in specific APIs such as AES key wrap and key derivation), quick-xml, quinn-proto and rustls-webpki, mostly denial of service on malformed input and fixed by version bumps. The npm advisory is braces in an agent-skills folder, not part of the app.
- 16 workflows, none using pull_request_target or write-all permissions; 6 of 37 third-party actions are pinned to a commit. Licence and contributing guide present; no security policy, Dependabot or CodeQL.
What the scanner counted
| Check | Result |
|---|---|
| Secrets | None found. |
| Suspicious code | 4 pattern hits found and read; every one is listed under the raw findings. |
| Install-time code | 6 Cargo build scripts. 1 installer script |
| Committed binaries | 1 executable or compiled object committed; listed under the raw findings. |
| CI workflows | 16 workflows. None use pull_request_target. 31 of 37 third-party actions pinned to a tag rather than a commit. |
| Network hosts | 40 distinct hosts referenced from source; most often cap.so, www.loom.com, github.com, cap.test. No URLs to bare IP addresses. |
| Known vulnerabilities | 61 advisories across 2,041 pinned packages: 0 critical, 14 high, 15 moderate, 7 low, 25 unrated. .agents/skills/building/package-lock.json: 189 packages, 1 advisories; Cargo.lock: 1,249 packages, 57 advisories; apps/cli/skill/cap-demo/package-lock.json: 1 packages, 0 advisories; apps/desktop-gpui/Cargo.lock: 1,274 packages, 22 advisories. |
| Project hygiene | Has licence file, contributing guide. Missing security policy, automated dependency updates, CodeQL. |
| OpenSSF Scorecard | Not scored: the project is not in Scorecard's weekly index. |
The raw findings
Every hit the scanner wrote out, with a link to the exact line at the scanned commit. Secrets candidates are redacted.
Pattern hits (4)
| Where | Rule | Match |
|---|---|---|
| apps/web/__tests__/unit/agent-docs.test.ts:207 | download-piped-to-shell (test/example) | "curl -fsSL https://cap.so/install-cli.sh | sh", |
| apps/web/components/pages/DownloadPage.tsx:29 | download-piped-to-shell | : "curl -fsSL https://cap.so/install-cli.sh | sh"; |
| apps/web/components/pages/agents/content.ts:47 | download-piped-to-shell | unix: "curl -fsSL https://cap.so/install-cli.sh | sh", |
| apps/web/data/agent-prompt.ts:21 | download-piped-to-shell | - macOS or Linux: curl -fsSL https://cap.so/install-cli.sh | sh |
Installer scripts (1)
Committed binaries (1)
crates/rnnoise/vendor/weights.bin: .bin, 4 MB
Worst known vulnerabilities (24 of 61)
| Advisory | Severity | Package | Summary |
|---|---|---|---|
| GHSA-vfj7-8cjw-p6xm | high | braces@3.0.3 | braces vulnerable to stack-exhaustion denial of service through deeply nested patterns |
| GHSA-vvp9-7p8x-rfvv | high | lz4_flex@0.11.5 | lz4_flex's decompression can leak information from uninitialized memory or reused output buffer |
| GHSA-8c75-8mhr-p7r9 | high | openssl@0.10.73 | rust-openssl has incorrect bounds assertion in aes key wrap |
| GHSA-ghm9-cr32-g9qj | high | openssl@0.10.73 | rust-openssl: rustMdCtxRef::digest_final() writes past caller buffer with no length check |
| GHSA-hppc-g8h3-xhp3 | high | openssl@0.10.73 | rust-openssl: Unchecked callback length in PSK/cookie trampolines leaks adjacent memory to peer |
| GHSA-pqf5-4pqq-29f5 | high | openssl@0.10.73 | rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1 |
| GHSA-xp3w-r5p5-63rr | high | openssl@0.10.73 | rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs |
| RUSTSEC-2026-0194 | high | quick-xml@0.37.5 | Quadratic run time when checking a start tag for duplicate attribute names |
| RUSTSEC-2026-0195 | high | quick-xml@0.37.5 | Unbounded namespace-declaration allocation in `NsReader` enables memory-exhaustion denial of service |
| RUSTSEC-2026-0194 | high | quick-xml@0.38.3 | Quadratic run time when checking a start tag for duplicate attribute names |
| RUSTSEC-2026-0195 | high | quick-xml@0.38.3 | Unbounded namespace-declaration allocation in `NsReader` enables memory-exhaustion denial of service |
| GHSA-4w2j-m93h-cj5j | high | quinn-proto@0.11.13 | Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly |
| GHSA-6xvm-j4wr-6v98 | high | quinn-proto@0.11.13 | Quinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsing |
| GHSA-82j2-j2ch-gfr8 | high | rustls-webpki@0.103.6 | rustls-webpki: Denial of service via panic on malformed CRL BIT STRING |
| GHSA-xhj4-vrgc-hr34 | moderate | actix-http@3.11.1 | actix-http has HTTP/1.1 CL.TE Request Smuggling |
| GHSA-434x-w66g-qw3r | moderate | bytes@1.10.1 | bytes has integer overflow in BytesMut::reserve |
| GHSA-wrw7-89jp-8q8g | moderate | glib@0.18.5 | Unsoundness in `Iterator` and `DoubleEndedIterator` impls for `glib::VariantStrIter` |
| GHSA-phqj-4mhp-q6mq | moderate | openssl@0.10.73 | rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers |
| GHSA-xv59-967r-8726 | moderate | openssl@0.10.73 | rust-openssl vulnerable to heap buffer overflow when encrypting with AES key-wrap-with-padding |
| GHSA-w9wp-h8wv-79jx | moderate | opentelemetry_sdk@0.31.0 | opentelemetry_sdk has unbounded memory allocation in W3C Baggage propagation |
| GHSA-2mjx-qc3c-rqvc | moderate | rustls@0.23.31 | TLS 1.3 handshake messages incorrectly accepted across encryption level boundaries |
| GHSA-pwjx-qhcg-rvj4 | moderate | rustls-webpki@0.103.6 | webpki: CRLs not considered authoritative by Distribution Point due to faulty matching logic |
| GHSA-7gcf-g7xr-8hxj | moderate | serde_with@3.14.0 | serde_with: KeyValueMap serialization panics on empty sequence or map entries |
| GHSA-3pv8-6f4r-ffg2 | moderate | tar@0.4.44 | tar has a PAX header desynchronization issue |
By the numbers
| Stars | 23K |
|---|---|
| Forks | 1,997 |
| Contributors | 81 |
| Commits | 8,975 |
| Open issues | 208 |
| Open pull requests | 215 |
| Releases | 83 |
| Latest release | cap-v0.6.0 |
| Licence | custom |
| Main language | Rust |
| Project age | 2 years |
| Last push | Oct 2, 2026 |
| Tracked files | 4,589 |
| Lines of code | 1.3M |
| Checkout size | 179 MB |
Lines by language: Rust 529.1K, TypeScript 501.4K, JSON 162.2K, JavaScript 21.1K, Markdown 14.7K, CSS 6,947.
Questions
Is Cap free?
For personal use, yes: the desktop app is free with no time limit on local recordings. Commercial use of the desktop app needs a Desktop License at $29 a year or $58 once, and Cap Pro, which adds Cap's cloud sharing, is $12 per user a month. The source code is AGPL-3.0, so self-hosting the web platform costs only your own server and storage.
Can Cap import my Loom videos?
Yes. Cap has a Loom importer that brings existing Loom videos into your Cap library, so you can move without losing old recordings. Cap also offers a Loom video downloader among its free tools on cap.so.
Where are Cap recordings stored?
Where you choose. Studio Mode recordings stay on your computer until you export or share them. Shared videos go to Cap Cloud by default, or to an S3-compatible bucket you connect, such as AWS S3, Cloudflare R2, Backblaze B2 or MinIO, or to a fully self-hosted Cap instance.
This post is part of GitHub Tools, where every repository is cloned and scanned before it is written up. The scan is a snapshot of one commit on one day; the repository has moved on since, so check it before you install.
