bongacams-downloader

Warn

Audited by Socket on Apr 10, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill’s capabilities mostly align with its stated purpose: a browser extension that captures media from user-opened Bongacams pages and saves files locally. The main security concern is install trust: users are asked to install a proprietary extension build from GitHub releases without visible checksum/signature verification, which creates moderate supply-chain risk. No clear evidence shows malicious behavior, credential harvesting beyond expected licensing, or third-party interception of site content, so this is better classified as suspicious/moderate-risk rather than malware.

Confidence: 80%Severity: 56%
Audit Metadata
Analyzed At
Apr 10, 2026, 10:12 PM
Package URL
pkg:socket/skills-sh/serpdownloaders%2Fskills%2Fbongacams-downloader%2F@838f22cbe76032a29a2e59b6525cb2cb8a75f18f