JetBrains Marketplace

Git Auto Prefix

by ede3595f-7df1-4deb-8c7c-06565a8e8872 · 31.2K users · 4.1 rating
0015c14b-a0f6-5f26-9a15-0af6d427b82b | v1.5.0
11/ 100
MINIMAL risk
No change since v1.4.1
Analyst verdict
No high-risk signal observed

Based on the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
3 days ago
Version
v1.5.0
Artifact
SHA256 168…65C
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

2 detail rows

Publisher Evidence

Limited evidence

ede3595f-7df1-4deb-8c7c-06565a8e8872

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

30
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Not exposed
Not exposed
Extension portfolio
1
Portfolio

13 evidence rows available.

Finding Categories

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

The Git Auto Prefix extension presents no security concerns. Analysis reveals only two metadata findings at info severity: HASH-8cd5810952704947 in commit-prefix-plugin/lib/searchableOptions-1.4.1.jar and HASH-0ce81008d5066e3a in commit-prefix-plugin/lib/instrumented-commit-prefix-plugin-1.4.1.jar. These are simply file hashes of bundled JAR dependencies, not security indicators.

The extension has zero findings across all security-relevant categories: no IOC matches, no malware signatures, no network activity flags, no obfuscation, no credential access, and no code-smell patterns. This clean profile is consistent with a legitimate Git integration tool.

As a Git plugin for JetBrains IDEs, the extension legitimately needs to read and write Git-related files and potentially execute Git commands. The bundled JAR files in the lib/ directory are standard for Java-based IDE extensions. With 29,018 users on the JetBrains marketplace and a verified developer (Thomas Repnik), this extension demonstrates legitimate adoption.

The strongest counterargument might be that any extension with file access could theoretically be misused. However, the absence of any security-relevant findings—including no suspicious network calls, no credential access patterns, and no obfuscation—combined with the high user count and JetBrains marketplace verification, makes malicious intent highly unlikely. The metadata findings are simply version hashes of bundled libraries, which is normal build output.

No credential-access findings target actual secrets like .env files, .ssh directories, or cloud credentials. The findings summary explicitly shows zero secret findings and zero network findings, indicating the extension does not exfiltrate data or communicate with suspicious endpoints. The code-smell category also shows zero findings, meaning no suspicious code patterns were detected.

This extension is a benign Git tool with no security concerns. The CVEQ system flagged it only because it exists in the ecosystem, not because of any actual security issues.

Key Reasons

  • Zero threat indicators across all security categories (IOC, malware, network, obfuscation, secrets, code-smell)
  • Only two metadata findings representing file hashes of bundled JAR dependencies
  • High user count (29,018) indicates legitimate adoption on JetBrains marketplace
  • No credential access or suspicious network activity detected

False Positive Considerations

  • Metadata hashes of bundled JAR files flagged as findings
  • No actual security-relevant findings despite system flagging

Reviewed 2026-05-23; recommended action: no action; model confidence 95%.

JetBrains version history

Risk trend by version

2 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
11
Change since first
No change
Change from previous
No change
Versions:
First analyzed version
1.4.1
Apr 5, 2026
Risk range
11 to 11
Across analyzed versions
Latest analyzed version
1.5.0
Jul 19, 2026
Selected version
minimal
Version
v1.5.0
2 months ago
Risk score
11
Findings
2
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

Automatically set the issue key (of the current branch name) as prefix for the commit message Choose your own delimiter between the issue key and commit message Wrap...

Frequently Asked Questions