VS Code Marketplace

SmartFlow

by Irek Cicherski · 5 users
000346f3-0346-53ad-9e6d-988e9b83ea84 | v0.1.46
56/ 100
MEDIUM risk
No change since v0.1.45
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (56/100) still counts them.

Analysis record

Analysed
1 months ago
Version
v0.1.46
Artifact
SHA256 AB9…9C4
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

240 detail rows

YARA Rule Matches

20 rules
SeverityRuleHitsFilesMetadata
LOWcredential env files 13
dist/services/DashboardProvider.jsdist/sidebar/SidebarProvider.jsdist/services/AIChatPanel.js +10 more
-
LOWpostinstall persistence mechanism 7
media/vendor/markdown-it.min.jsdist/services/github/index.jspackage.json +4 more
-
LOWNoDisableSanitizeHtml 2
dist/extension.jsdist/services/AIChatPanel.js
-
LOWLocalStorageShouldNotBeUsed 3
media/sidebar-ui.jsmedia/sidebar-filters.jsmedia/sidebar-events.js
-
LOWDebuggerStatementsShouldNotBeUsed 1
dist/extension.js
-
LOWUsingCommandLineArguments 1
dist/extension.js
-
LOWNoUseEval 1
dist/extension.js
-
LOWNoUseWeakRandom 5
dist/services/DashboardProvider.jsdist/sidebar/SidebarProvider.jsdist/services/AIChatPanel.js +2 more
-
LOWpostinstall file download 28
dist/extension.jsdist/services/DevelopmentService.jsdist/services/agents/contextBudget.js +25 more
-
LOWSQLInjection 6
dist/services/AIChatPanel.jsdist/sidebar/SidebarProvider.jsdist/services/AnalysisChatPanel.js +3 more
-
LOWcredential git credentials 1
dist/utils/helpers.js
-
LOWcredential gcp credentials 1
dist/extension.js
-
LOWpostinstall file manipulation 48
dist/services/github/iterationBackup.jsmedia/sidebar.cssdist/services/github/Branches.js +45 more
-
LOWpostinstall crypto operations 9
dist/sidebar/SidebarProvider.jsdist/services/agents/contextBudget.jsdist/init/InitService.js +6 more
-
LOWpostinstall system command 47
dist/services/agents/contextBudget.jsmedia/sidebar.cssdist/services/GoalBurndownService.js +44 more
-
LOWNoUseSocketManually 1
dist/extension.js
-
LOWpostinstall registry modification 3
dist/services/llm/ClaudeCliModel.jsdist/extension.jsdist/services/llm/sessionRegistry.js
-
LOWpostinstall obfuscation 16
dist/sidebar/SidebarProvider.jsdist/services/WebSearchService.jsdist/services/UIPreviewPanel.js +13 more
-
LOWpostinstall network communication 26
dist/services/GoogleCalendarService.jsdist/services/llm/sessionRegistry.jsdist/services/UITestService.js +23 more
-
LOWUsingShellInterpreterWhenExecutingOSCommands 2
dist/utils/helpers.jsdist/extension.js
-

Publisher Evidence

Limited evidence

Irek Cicherski

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

24
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Not exposed
Not exposed
Extension portfolio
Unknown
Portfolio

10 evidence rows available.

Finding Categories

1
Secrets
8
Network

YARA Rules Matched

20 rules(221 hits)
credential env files postinstall persistence mechanism NoDisableSanitizeHtml LocalStorageShouldNotBeUsed DebuggerStatementsShouldNotBeUsed UsingCommandLineArguments NoUseEval NoUseWeakRandom postinstall file download SQLInjection credential git credentials credential gcp credentials postinstall file manipulation postinstall crypto operations postinstall system command NoUseSocketManually +4 more

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

The SmartFlow extension is an AI-powered project management tool for GitHub-native development workflows. The analysis shows this extension exhibits expected behavior for its stated purpose with no evidence of malicious activity.

Filesystem and Process Access

The extension's network activity is concentrated in bundled distribution files at extension/dist/extension.js (lines 23335, 23361) and extension/dist/services/WebSearchService.js (line 50). These fetch calls are consistent with an AI-powered extension that needs to communicate with external services for web search capabilities and project management features. There are no findings indicating unauthorized process execution, postinstall payload downloads, or shell command execution beyond what's necessary for the extension's stated functionality. The network calls are confined to the dist/ directory, which contains bundled/minified build output—standard for modern JavaScript extensions.

Credential Access Analysis

No credential theft findings were detected. The only OAuth-related domain identified (xxxxxxxx.apps.googleusercontent.com) represents legitimate Google authentication infrastructure, not credential harvesting. There are zero findings related to .env file access, SSH key reading, cloud credential extraction, or VS Code secret storage access. The extension does not demonstrate any pattern of accessing secrets beyond what would be necessary for GitHub integration. The findings summary shows zero secret findings, zero credential-related code-smell matches, and zero malware signatures.

Strongest Counterargument

The most concerning aspect is the extension's zero user count combined with 1,577 IOC findings flagged by the analysis system. However, these IOC findings are well-documented false positives from the XIOC extractor, which misidentifies JavaScript property access chains as domain names. For example, meeting.attendees.map, found.name, and found.email are legitimate JavaScript property accesses that the extractor incorrectly parses as suspicious domains. The 51.run, 178.run, and 16.run findings similarly represent numeric property access patterns rather than actual network destinations. The 17.youtube and 2.vision findings follow the same pattern. The Google OAuth domain is standard for any extension integrating with Google services.

Conclusion

This extension demonstrates normal behavior for an AI-powered development tool. The high finding count stems from known false-positive patterns in the detection system, not actual malicious behavior. There are no malware signatures, no obfuscation indicators, no credential theft patterns, and no postinstall payload execution. The network activity is confined to bundled distribution files and matches the extension's stated purpose of AI-powered project management and web search capabilities. The zero user count indicates this is a new or unpublished extension, but the code behavior itself shows no malicious intent.

Key Reasons

  • Zero malware signatures detected across 1588 total findings
  • All 1577 IOC findings are XIOC property-access chain false positives
  • Network activity confined to bundled dist/ files with expected fetch calls
  • Zero credential theft or secret access findings
  • Zero obfuscation or code-smell indicators

False Positive Considerations

  • XIOC property access chain misidentification (meeting.attendees.map, found.name, found.email)
  • Numeric property access patterns misread as domains (51.run, 178.run, 16.run)
  • Bundled dist/ files triggering network detection on legitimate fetch calls
  • Google OAuth domain (apps.googleusercontent.com) flagged as suspicious

Reviewed 2026-05-25; recommended action: suppress false positive; model confidence 85%.

VS Code version history

Risk trend by version

9 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
56
Change since first
+5
Change from previous
No change
Versions:
First analyzed version
0.1.0
May 25, 2026
Risk range
51 to 56
Across analyzed versions
Latest analyzed version
0.1.46
Aug 22, 2026
Selected version
medium
Version
v0.1.46
1 months ago
Risk score
56
Findings
240
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

AI-powered project management: autonomous sprint planning, team capacity optimization, and intelligent roadmapping for GitHub-native development

Frequently Asked Questions