leboncoin
Audited by Socket on Sep 11, 2026
2 alerts found:
Anomalyx2SUSPICIOUS. The skill is internally coherent for browser-based Leboncoin listing management and does not show third-party credential exfiltration or untrusted installer behavior, but it is high-impact automation on a real consumer account, uses session/cookie material, and explicitly emphasizes bot-detection evasion. Risk comes more from consequential account actions and stealthy automation than from confirmed malware.
The fragment appears to implement legitimate browser-scraper profile setup and local configuration management. It does not show malware, exfiltration, credential theft, or code execution. The main security and privacy risk is copying a complete browser profile, which may duplicate sensitive authentication material into the scraper directory. Environment-controlled paths also warrant validation and restrictive permissions. Review the omitted code to determine whether the copied profile or auth-state data is later exposed or transmitted.