leboncoin

Warn

Audited by Socket on Sep 11, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is internally coherent for browser-based Leboncoin listing management and does not show third-party credential exfiltration or untrusted installer behavior, but it is high-impact automation on a real consumer account, uses session/cookie material, and explicitly emphasizes bot-detection evasion. Risk comes more from consequential account actions and stealthy automation than from confirmed malware.

Confidence: 86%Severity: 66%
AnomalyLOW
src/config.ts

The fragment appears to implement legitimate browser-scraper profile setup and local configuration management. It does not show malware, exfiltration, credential theft, or code execution. The main security and privacy risk is copying a complete browser profile, which may duplicate sensitive authentication material into the scraper directory. Environment-controlled paths also warrant validation and restrictive permissions. Review the omitted code to determine whether the copied profile or auth-state data is later exposed or transmitted.

Confidence: 95%Severity: 55%
Audit Metadata
Analyzed At
Sep 11, 2026, 10:28 AM
Package URL
pkg:socket/skills-sh/maxgfr%2Fleboncoin-cdp%2Fleboncoin%2F@cdd4f3fb1094e793f8b27c52ab875afcfee81a34
Security Audit — socket — leboncoin