OpenVSX Registry Verified

viiv

00067dd3-60bd-5d0d-9b32-683584cbc23c | v0.3.7
0/ 100
MINIMAL risk
Analyst verdict
No high-risk signal observed

Based on the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
10 months ago
Version
v0.3.7
Source
Findings (non-IoC)

No Findings

All security checks passed

Publisher Evidence

Low

wenijinew

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

50
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Verified publisher
Verified
Extension portfolio
1
Portfolio

13 evidence rows available.

No Threats Detected

This extension passed all security checks

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

The viiv extension is a VS Code theme described as putting developers into focus mode. Theme extensions do not require filesystem access, process execution, or network connectivity to function—they only modify color schemes and UI elements. The evidence bundle contains zero findings that indicate actual file access, process spawning, or network activity.

The 181 IoC findings are classic XIOC extractor false positives. The finding XIOC-DOMAIN-variable.other.definition.java is a syntax highlighting token name from a theme configuration file, not a network domain. Similarly, XIOC-DOMAIN-support.type.property, XIOC-DOMAIN-variable.parameter.java, and XIOC-DOMAIN-storage.type.token.java are all syntax token identifiers that the extractor misread as domain names. The finding XIOC-DOMAIN-u.save is a property access chain (likely minified JavaScript), not a domain. These patterns match the documented false positive behavior where the XIOC extractor treats property chains and syntax tokens as domains.

The 301 code-smell findings (severity=high in the bundle, but classified as code-smell/low in CVEQ rules) match basic Node.js patterns in bundled or minified code. The guidelines explicitly state that code-smell findings should NEVER drive a verdict because they fire on almost any non-trivial JavaScript. There are zero findings in the secret, malware, or network categories.

The strongest counterargument is the high total finding count of 583, which could suggest malicious behavior at first glance. This does not change the conclusion because finding COUNT is noise while finding NATURE is signal. Every single IoC finding is a syntax token or property chain. Every single code-smell finding matches expected patterns in bundled code. There are no postinstall payload executions, no credential access to .env or .ssh files, no exfiltration patterns, and no supply chain indicators. The extension is a theme with no legitimate need for the capabilities that would generate actual malicious findings.

This extension requires no action beyond suppressing the false positive findings in CVEQ.

Key Reasons

  • All 181 IoC findings are syntax tokens or property chains misidentified as domains
  • Zero malware signatures or actual network activity findings
  • Extension is a theme with no need for filesystem/process/network access
  • 301 code-smell findings match expected patterns in bundled code

False Positive Considerations

  • XIOC domain extractor misreading syntax tokens as domains
  • Code-smell rules firing on bundled/minified JavaScript
  • Property access chains misidentified as domains
  • Theme extension has no legitimate need for flagged capabilities

Reviewed 2026-05-03; recommended action: suppress false positive; model confidence 85%.

About This Extension

A VsCode theme that puts developers into focus mode quickly.

Frequently Asked Questions