VS Code Marketplace

C# Test Adapter

by samirat · 13.1K users
0000d506-e2c9-5ace-a6f6-9df6ce99597b | v1.1.1
56/ 100
MEDIUM risk
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (56/100) still counts them.

Analysis record

Analysed
8 months ago
Version
v1.1.1
Artifact
SHA256 403…3BE
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

32 detail rows

YARA Rule Matches

8 rules
SeverityRuleHitsFilesMetadata
HIGHNoUseWeakRandom

When software generates predictable values in a context requiring unpredictability, it may be possible for an attacker to guess the next value that will be generated, and use this guess to impersonate another user or access sensitive information. As the Math.random() function relies on a weak pseudorandom number generator, this function should not be used for security-critical applications or for protecting sensitive data. In such context, a cryptographically strong pseudorandom number generator (CSPRNG) should be used instead. For more information checkout the CWE-338 (https://cwe.mitre.org/data/definitions/338.html) advisory.

1
out/main.js
FP 5%
HIGHpostinstall network communication

Network communication detected

1
LICENSE.txt
Risky Plugins Authors FP 30%
HIGHpostinstall file manipulation

File system manipulation detected

3
out/main.jsout/omnisharp/protocol.js.github/workflows/ci.yml
Risky Plugins Authors FP 20%
HIGHpostinstall persistence mechanism

Persistence mechanism detected

2
out/adapter.jsout/main.js
Risky Plugins Authors FP 20%
HIGHUsingShellInterpreterWhenExecutingOSCommands

Arbitrary OS command injection vulnerabilities are more likely when a shell is spawned rather than a new process, indeed shell meta-chars can be used (when parameters are user-controlled for instance) to inject OS commands. For more information checkout the CWE-78 (https://cwe.mitre.org/data/definitions/78.html) advisory.

1
out/main.js
FP 10%
HIGHpostinstall system command

System command execution detected

5
out/omnisharp/EventType.jsout/adapter.jsout/omnisharp/loggingEvents.js +2 more
Risky Plugins Authors FP 10%
HIGHpostinstall file download

File download activity detected

3
out/omnisharp/loggingEvents.jsout/omnisharp/EventType.jsout/main.js
Risky Plugins Authors FP 30%
HIGHpostinstall obfuscation

Code obfuscation techniques detected

1
out/main.js
Risky Plugins Authors FP 20%

Publisher Evidence

Limited evidence

samirat

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

45
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Not exposed
Not exposed
Extension portfolio
7
Portfolio

13 evidence rows available.

Finding Categories

17
Malware Signatures
10
Network

YARA Rules Matched

8 rules(17 hits)
NoUseWeakRandom postinstall network communication postinstall file manipulation postinstall persistence mechanism UsingShellInterpreterWhenExecutingOSCommands postinstall system command postinstall file download postinstall obfuscation

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

The extension’s purpose is to run C# tests from the VS Code sidebar. The only filesystem‑related findings are the dependency entries in package.json (e.g., DEP‑vscode-test-adapter-util‑^0.7.0 and DEP‑minimatch‑^3.0.4). These dependencies are required for test discovery and configuration, which is fully consistent with the advertised functionality, so the file‑access is justified. No process‑spawning code such as child_process.exec or similar appears in the scanned sources. Network‑related detections are all NET‑XMLHTTPREQUEST entries inside the bundled RxJS library files (e.g., extension/node_modules/rxjs/internal/observable/dom/AjaxObservable.js:22 and .../AjaxObservable.ts:26). RxJS includes generic AJAX helpers that reference XMLHttpRequest; these references are inert unless the extension actively uses them, which it does not for credential or data exfiltration. There are no secret‑access findings; the bundle contains zero entries under the secret category, confirming that the extension does not read .env, .ssh, or cloud credential files. The strongest counterargument could be that the presence of many XMLHttpRequest patterns indicates potential remote communication capability, which might be abused. However, because the calls are limited to library stubs within RxJS and no code invokes them to transmit workspace contents or credentials, the risk remains negligible, and the overall conclusion stays unchanged.

Key Reasons

  • File access limited to legitimate dependencies for test execution
  • Network calls are solely library stubs from RxJS, not active exfiltration
  • No secret‑access findings detected
  • All findings originate from bundled third‑party code

False Positive Considerations

  • Bundled RxJS library generating many NET‑XMLHTTPREQUEST entries
  • Low‑severity dependency listings in package.json

Reviewed 2026-05-23; recommended action: no action; model confidence 92%.

About This Extension

Run C# tests in the sidebar of Visual Studio Code

Frequently Asked Questions