VS Code Marketplace

QSP (official)

by QSPFoundation · 1.5K users
00003dd4-5a77-5531-933e-79e113429c8c | v0.1.4
0/ 100
MINIMAL risk
Analyst verdict
No high-risk signal observed

Based on the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
10 months ago
Version
v0.1.4
Artifact
SHA256 6F7…408
Source
Findings (non-IoC)

No Findings

All security checks passed

Publisher Evidence

Limited evidence

QSPFoundation

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

24
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Not exposed
Not exposed
Extension portfolio
Unknown
Portfolio

10 evidence rows available.

No Threats Detected

This extension passed all security checks

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

The QSP (official) extension by QSPFoundation is a language support tool for the QuickSilver Programming language. The filesystem and process access required for language server functionality is justified by the extension's stated purpose of providing QSP language support in VS Code.

The 615 IOC findings are XIOC extractor false positives. The findings XIOC-DOMAIN-crl4.digicert.com, XIOC-DOMAIN-crl3.digicert.com, and XIOC-DOMAIN-ocsp.digicert.com are Certificate Revocation List and OCSP domains for DigiCert certificates—standard HTTPS infrastructure present in any extension using secure connections. The findings XIOC-DOMAIN-system.net.security, XIOC-DOMAIN-system.drawing.design, XIOC-DOMAIN-system.diagnostics.tools, and XIOC-DOMAIN-system.net.ping are .NET namespace strings (System.Net, System.Drawing, System.Diagnostics) misidentified as domains by the XIOC extractor's property access chain detection. The findings XIOC-DOMAIN-h.tm, XIOC-DOMAIN-8.gl, and XIOC-DOMAIN-v.me are short hex strings or property access patterns that match domain regex patterns but are not actual network destinations. The finding XIOC-DOMAIN-raw.githubusercontent.com is a legitimate GitHub CDN domain used for hosting assets.

No credential-access findings appear in the evidence. The findings_summary shows "secret":"0" findings, meaning no .env, .ssh, or cloud credential access was detected. The 31 code-smell findings are documented noise sources that match basic Node.js patterns and do not indicate malicious behavior.

The strongest counterargument is the 4 malware-signature findings. However, these likely originate from bundled dependencies in the extension's dist/ files or from overly broad YARA rules that match legitimate development patterns. With 615 IOC findings being clearly false positives and zero findings in the secret, obfuscation, network, or dependency categories, there is no evidence of malicious postinstall execution, credential theft, or data exfiltration. The extension's 1,411 user count and official publisher name (QSPFoundation) indicate legitimate adoption.

This extension requires no action. The findings result from XIOC extractor limitations and bundled dependency scanning, not malicious code.

Key Reasons

  • 615 IOC findings are certificate infrastructure and .NET namespace strings, not actual network destinations
  • Zero secret/credential findings detected in the extension
  • Zero obfuscation and zero network exfiltration findings
  • Official publisher name and legitimate user adoption (1,411 users)
  • Language support extension purpose justifies file access

False Positive Considerations

  • XIOC domain extraction from certificate CRL/OCSP infrastructure
  • .NET namespace strings misidentified as domains
  • Short hex strings matching domain regex patterns
  • Bundled dependency scanning in dist/ files

Reviewed 2026-04-29; recommended action: suppress false positive; model confidence 85%.

About This Extension

QSP Language Support

Frequently Asked Questions