QSP (official)
Based on the RiskyPlugins AI security review of the observed evidence.
Analysis record
- Analysed
- 10 months ago
- Version
- v0.1.4
- Artifact
- SHA256 6F7…408
- Source
- Findings (non-IoC)
No Findings
All security checks passed
Publisher Evidence
Limited evidenceQSPFoundation
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
10 evidence rows available.
No Threats Detected
This extension passed all security checks
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality strong.
The QSP (official) extension by QSPFoundation is a language support tool for the QuickSilver Programming language. The filesystem and process access required for language server functionality is justified by the extension's stated purpose of providing QSP language support in VS Code.
The 615 IOC findings are XIOC extractor false positives. The findings XIOC-DOMAIN-crl4.digicert.com, XIOC-DOMAIN-crl3.digicert.com, and XIOC-DOMAIN-ocsp.digicert.com are Certificate Revocation List and OCSP domains for DigiCert certificates—standard HTTPS infrastructure present in any extension using secure connections. The findings XIOC-DOMAIN-system.net.security, XIOC-DOMAIN-system.drawing.design, XIOC-DOMAIN-system.diagnostics.tools, and XIOC-DOMAIN-system.net.ping are .NET namespace strings (System.Net, System.Drawing, System.Diagnostics) misidentified as domains by the XIOC extractor's property access chain detection. The findings XIOC-DOMAIN-h.tm, XIOC-DOMAIN-8.gl, and XIOC-DOMAIN-v.me are short hex strings or property access patterns that match domain regex patterns but are not actual network destinations. The finding XIOC-DOMAIN-raw.githubusercontent.com is a legitimate GitHub CDN domain used for hosting assets.
No credential-access findings appear in the evidence. The findings_summary shows "secret":"0" findings, meaning no .env, .ssh, or cloud credential access was detected. The 31 code-smell findings are documented noise sources that match basic Node.js patterns and do not indicate malicious behavior.
The strongest counterargument is the 4 malware-signature findings. However, these likely originate from bundled dependencies in the extension's dist/ files or from overly broad YARA rules that match legitimate development patterns. With 615 IOC findings being clearly false positives and zero findings in the secret, obfuscation, network, or dependency categories, there is no evidence of malicious postinstall execution, credential theft, or data exfiltration. The extension's 1,411 user count and official publisher name (QSPFoundation) indicate legitimate adoption.
This extension requires no action. The findings result from XIOC extractor limitations and bundled dependency scanning, not malicious code.
Key Reasons
- 615 IOC findings are certificate infrastructure and .NET namespace strings, not actual network destinations
- Zero secret/credential findings detected in the extension
- Zero obfuscation and zero network exfiltration findings
- Official publisher name and legitimate user adoption (1,411 users)
- Language support extension purpose justifies file access
False Positive Considerations
- XIOC domain extraction from certificate CRL/OCSP infrastructure
- .NET namespace strings misidentified as domains
- Short hex strings matching domain regex patterns
- Bundled dependency scanning in dist/ files
Reviewed 2026-04-29; recommended action: suppress false positive; model confidence 85%.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace