bongacams-downloader
Warn
Audited by Socket on Apr 10, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
The skill’s capabilities mostly align with its stated purpose: a browser extension that captures media from user-opened Bongacams pages and saves files locally. The main security concern is install trust: users are asked to install a proprietary extension build from GitHub releases without visible checksum/signature verification, which creates moderate supply-chain risk. No clear evidence shows malicious behavior, credential harvesting beyond expected licensing, or third-party interception of site content, so this is better classified as suspicious/moderate-risk rather than malware.
Confidence: 80%Severity: 56%
Audit Metadata