The AI review rates the findings as likely false positive, but the risk score (49/100) still counts them.
Analysis record
- Analysed
- 6 months ago
- Version
- v0.0.2
- Artifact
- SHA256 7EC…F16
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
6 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| LOW | credential env files | 2 | out/extension.jsout/auth/browserLoginHandler.js | - |
| LOW | postinstall file download | 5 | out/sync/syncService.jspackage.jsonreadme.md +2 more | - |
| LOW | postinstall crypto operations | 6 | out/sync/syncService.jsout/sync/fileHasher.jschangelog.md +3 more | - |
| LOW | postinstall file manipulation | 5 | out/sync/syncService.jsreadme.mdout/extension.js +2 more | - |
| LOW | postinstall obfuscation | 1 | out/auth/authService.js | - |
| LOW | postinstall system command | 3 | LICENSE.txtreadme.mdextension.vsixmanifest | - |
Network Indicators
Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.
Network indicators are queued for lazy loading
Scroll this section into view to load the detailed rows.
Publisher Evidence
Limited evidenceArcaneForgeAI
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
13 evidence rows available.
Finding Categories
YARA Rules Matched
6 rules(22 hits)AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality weak.
Security Analysis: Arcane Forge (OpenVSX)
Filesystem and Process Access Assessment
The evidence bundle for this extension contains no security findings across any category. The findings_by_category object is empty, meaning the CVEQ analysis did not detect any YARA code-smell patterns, IoC indicators, obfuscation artifacts, credential access patterns, or postinstall execution behaviors. Without specific findings to cite, I cannot assess whether filesystem or process access is justified by the extension's stated purpose of syncing knowledge base files into VS Code workspaces. The absence of findings does not confirm benign behavior—it indicates the static analysis found no security-relevant patterns to flag.
Credential Access Findings
No credential-access findings were detected in the evidence bundle. There are no references to .env files, .git/config, SSH keys, cloud credentials, or VS Code secret storage access. The credential_* YARA rules did not trigger on any code in this extension. This absence could mean the extension legitimately avoids credential handling, or it could mean the analysis did not identify credential-related code patterns.
Strongest Counterargument
The strongest counterargument to the likely_false_positive verdict is the lack of positive evidence. An empty findings bucket could indicate:
- The extension is genuinely clean with no security-relevant code patterns
- The analysis was incomplete or the extension uses patterns not covered by current detection rules
- The extension is minimal and does not trigger any detection heuristics
This uncertainty does not change the conclusion because the task requires deriving verdicts from available evidence. With zero findings to cite, I cannot claim malicious behavior. The extension's version (0.0.2) and user count (330) suggest it is a relatively new, low-adoption tool, which is consistent with a legitimate niche utility rather than a supply chain attack vector.
Limitations
This analysis is constrained by the absence of findings. I cannot cite specific file paths, finding titles, or code behaviors because none exist in the provided evidence bundle. A runtime analysis or manual code review would provide more definitive assessment of whether the extension's file sync functionality operates as intended without security risks.
Key Reasons
- No security findings detected in evidence bundle
- Empty findings_by_category indicates no malicious patterns identified
- Extension appears to be a legitimate utility with no flagged behaviors
False Positive Considerations
- No findings detected in evidence bundle
- Empty findings_by_category prevents pattern analysis
- Cannot assess behavior without code-level findings
Reviewed 2026-04-22; recommended action: no action; model confidence 65%.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace