Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomegoAi
Findings · 3
+9 more findings locked
HIGH FINDINGS · 3
  1. 01Auth token transmitted in URL query parameters across all API calls, exposing credentials in server logs, browser history, and network intermediaries
  2. 02LinkedIn session cookies (including li_at auth cookie and JSESSIONID) accessed via chrome.cookies API and used to make authenticated API requests impersonating the user
  3. 03Comprehensive LinkedIn profile data (name, headline, experience, education, skills, recommendations, activities, interests, direct messages, contact info) scraped from DOM and exfiltrated to goai-app.com server
+9 more findings locked
OTHER EXTENSIONS

Is goAi safe?

High risk

No summary available.

kingskaterv0.547Chrome Web Store
75Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+9 more findings not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026hclgifmeonilohjeienjloglbhbjeebb

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact