OpenVSX Registry Verified

Cataclysm DDA JSON Formatter

0003a5ed-c3ee-5c17-b66e-812e7576ff82 | v1.0.8
0/ 100
MINIMAL risk
Analyst verdict
No high-risk signal observed

Based on the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
10 months ago
Version
v1.0.8
Source
Findings (non-IoC)

No Findings

All security checks passed

Publisher Evidence

Low

cdda-toys

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

50
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Verified publisher
Verified
Extension portfolio
1
Portfolio

13 evidence rows available.

No Threats Detected

This extension passed all security checks

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality weak.

Security Analysis: Cataclysm DDA JSON Formatter

Extension Overview

The "Cataclysm DDA JSON Formatter" extension from developer "cdda-toys" on OpenVSX serves a specific, narrow purpose: formatting JSON data files for the Cataclysm DDA game. With 1,719 users, this extension has moderate adoption in its niche.

Filesystem and Process Access Assessment

No filesystem or process access findings were detected in the evidence bundle. The findings_by_category object is completely empty, indicating the CVEQ analysis pipeline generated zero security findings for this extension. This absence is significant because:

  • No YARA code-smell rules fired on the extension code
  • No suspicious process spawning was detected (which would be expected if this extension executed arbitrary commands)
  • No file access patterns beyond normal IDE extension behavior were flagged

For a JSON formatter extension, legitimate behavior would include reading workspace files for formatting and writing formatted output back. However, no findings exist to evaluate whether this access is justified or excessive. The empty findings category means the automated analysis found no security-relevant code patterns.

Credential Access Assessment

No credential-access findings were detected. The evidence bundle contains no findings related to:

  • .env file access
  • .git/config or SSH key reads
  • Cloud credential access
  • VS Code secret storage access
  • API key or environment variable manipulation

This is consistent with the extension's stated purpose. A JSON formatter for game data files has no legitimate reason to access developer credentials, and the analysis confirms no such access patterns were detected.

Strongest Counterargument

The strongest argument against this verdict is the absence of version information in the evidence bundle (version: "unknown"). Without knowing which specific version was analyzed, there is uncertainty about whether the analyzed code matches what users would install. Additionally, the extension is hosted on OpenVSX rather than the official VS Code marketplace, which has less stringent publisher verification.

However, this counterargument does not change the conclusion because:

  1. The absence of version data is a data quality issue, not a security finding
  2. OpenVSX legitimately hosts many VS Code extensions, including mirrors
  3. No actual security findings exist to warrant concern regardless of version
  4. The developer name "cdda-toys" aligns with the extension's purpose (Cataclysm DDA tools)

Conclusion

This extension shows no evidence of malicious behavior. The empty findings bundle indicates the CVEQ analysis pipeline detected no security-relevant code patterns. Any risk score generated for this extension is likely inflated by the scoring system's known biases toward finding volume rather than finding nature. Without YARA matches, IoC detections, or code-smell findings, there is no technical basis for concern.

Recommendation: No action required. This appears to be a legitimate niche tool for a specific game's data files with no detected security issues.

Key Reasons

  • Zero security findings in evidence bundle
  • Extension purpose aligns with expected behavior (JSON formatting)
  • No credential access or exfiltration patterns detected
  • Developer name matches extension purpose
  • No YARA, IoC, or code-smell findings to investigate

False Positive Considerations

  • Empty findings bundle - no security detections generated
  • Scoring system bias toward finding volume over nature
  • No code-smell or YARA matches to drive risk assessment

Reviewed 2026-04-22; recommended action: no action; model confidence 90%.

About This Extension

JSON formatter for Cataclysm DDA data files

Frequently Asked Questions