C# Test Adapter
The AI review rates the findings as likely false positive, but the risk score (56/100) still counts them.
Analysis record
- Analysed
- 8 months ago
- Version
- v1.1.1
- Artifact
- SHA256 403…3BE
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
8 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| HIGH | NoUseWeakRandom When software generates predictable values in a context requiring unpredictability, it may be possible for an attacker to guess the next value that will be generated, and use this guess to impersonate another user or access sensitive information. As the Math.random() function relies on a weak pseudorandom number generator, this function should not be used for security-critical applications or for protecting sensitive data. In such context, a cryptographically strong pseudorandom number generator (CSPRNG) should be used instead. For more information checkout the CWE-338 (https://cwe.mitre.org/data/definitions/338.html) advisory. | 1 | out/main.js | FP 5% |
| HIGH | postinstall network communication Network communication detected | 1 | LICENSE.txt | Risky Plugins Authors FP 30% |
| HIGH | postinstall file manipulation File system manipulation detected | 3 | out/main.jsout/omnisharp/protocol.js.github/workflows/ci.yml | Risky Plugins Authors FP 20% |
| HIGH | postinstall persistence mechanism Persistence mechanism detected | 2 | out/adapter.jsout/main.js | Risky Plugins Authors FP 20% |
| HIGH | UsingShellInterpreterWhenExecutingOSCommands Arbitrary OS command injection vulnerabilities are more likely when a shell is spawned rather than a new process, indeed shell meta-chars can be used (when parameters are user-controlled for instance) to inject OS commands. For more information checkout the CWE-78 (https://cwe.mitre.org/data/definitions/78.html) advisory. | 1 | out/main.js | FP 10% |
| HIGH | postinstall system command System command execution detected | 5 | out/omnisharp/EventType.jsout/adapter.jsout/omnisharp/loggingEvents.js +2 more | Risky Plugins Authors FP 10% |
| HIGH | postinstall file download File download activity detected | 3 | out/omnisharp/loggingEvents.jsout/omnisharp/EventType.jsout/main.js | Risky Plugins Authors FP 30% |
| HIGH | postinstall obfuscation Code obfuscation techniques detected | 1 | out/main.js | Risky Plugins Authors FP 20% |
Publisher Evidence
Limited evidencesamirat
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
13 evidence rows available.
Finding Categories
YARA Rules Matched
8 rules(17 hits)AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality strong.
The extension’s purpose is to run C# tests from the VS Code sidebar. The only filesystem‑related findings are the dependency entries in package.json (e.g., DEP‑vscode-test-adapter-util‑^0.7.0 and DEP‑minimatch‑^3.0.4). These dependencies are required for test discovery and configuration, which is fully consistent with the advertised functionality, so the file‑access is justified. No process‑spawning code such as child_process.exec or similar appears in the scanned sources. Network‑related detections are all NET‑XMLHTTPREQUEST entries inside the bundled RxJS library files (e.g., extension/node_modules/rxjs/internal/observable/dom/AjaxObservable.js:22 and .../AjaxObservable.ts:26). RxJS includes generic AJAX helpers that reference XMLHttpRequest; these references are inert unless the extension actively uses them, which it does not for credential or data exfiltration. There are no secret‑access findings; the bundle contains zero entries under the secret category, confirming that the extension does not read .env, .ssh, or cloud credential files. The strongest counterargument could be that the presence of many XMLHttpRequest patterns indicates potential remote communication capability, which might be abused. However, because the calls are limited to library stubs within RxJS and no code invokes them to transmit workspace contents or credentials, the risk remains negligible, and the overall conclusion stays unchanged.
Key Reasons
- File access limited to legitimate dependencies for test execution
- Network calls are solely library stubs from RxJS, not active exfiltration
- No secret‑access findings detected
- All findings originate from bundled third‑party code
False Positive Considerations
- Bundled RxJS library generating many NET‑XMLHTTPREQUEST entries
- Low‑severity dependency listings in package.json
Reviewed 2026-05-23; recommended action: no action; model confidence 92%.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
Nakka - AI code agent
Nakka
BOO UI编辑器
boo-best
Erilang
eritten kwame gyau
VS Code Tools for WPF
LeXtudio Inc.
Spark & Hive Tools
Microsoft
Oracle Developer Tools for VS Code (SQL and PLSQL)
Oracle Corporation