OpenVSX Registry

Arcane Forge

001ea8f7-8614-5e76-ba8e-7e68e2c0522b | v0.0.2
49/ 100
MEDIUM risk
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (49/100) still counts them.

Analysis record

Analysed
6 months ago
Version
v0.0.2
Artifact
SHA256 7EC…F16
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

23 detail rows

YARA Rule Matches

6 rules
SeverityRuleHitsFilesMetadata
LOWcredential env files 2
out/extension.jsout/auth/browserLoginHandler.js
-
LOWpostinstall file download 5
out/sync/syncService.jspackage.jsonreadme.md +2 more
-
LOWpostinstall crypto operations 6
out/sync/syncService.jsout/sync/fileHasher.jschangelog.md +3 more
-
LOWpostinstall file manipulation 5
out/sync/syncService.jsreadme.mdout/extension.js +2 more
-
LOWpostinstall obfuscation 1
out/auth/authService.js
-
LOWpostinstall system command 3
LICENSE.txtreadme.mdextension.vsixmanifest
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

61 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Publisher Evidence

Limited evidence

ArcaneForgeAI

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

20
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Not exposed
Not exposed
Extension portfolio
1
Portfolio

13 evidence rows available.

Finding Categories

1
Network
61
IoC Indicators

YARA Rules Matched

6 rules(22 hits)
credential env files postinstall file download postinstall crypto operations postinstall file manipulation postinstall obfuscation postinstall system command

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality weak.

Security Analysis: Arcane Forge (OpenVSX)

Filesystem and Process Access Assessment

The evidence bundle for this extension contains no security findings across any category. The findings_by_category object is empty, meaning the CVEQ analysis did not detect any YARA code-smell patterns, IoC indicators, obfuscation artifacts, credential access patterns, or postinstall execution behaviors. Without specific findings to cite, I cannot assess whether filesystem or process access is justified by the extension's stated purpose of syncing knowledge base files into VS Code workspaces. The absence of findings does not confirm benign behavior—it indicates the static analysis found no security-relevant patterns to flag.

Credential Access Findings

No credential-access findings were detected in the evidence bundle. There are no references to .env files, .git/config, SSH keys, cloud credentials, or VS Code secret storage access. The credential_* YARA rules did not trigger on any code in this extension. This absence could mean the extension legitimately avoids credential handling, or it could mean the analysis did not identify credential-related code patterns.

Strongest Counterargument

The strongest counterargument to the likely_false_positive verdict is the lack of positive evidence. An empty findings bucket could indicate:

  1. The extension is genuinely clean with no security-relevant code patterns
  2. The analysis was incomplete or the extension uses patterns not covered by current detection rules
  3. The extension is minimal and does not trigger any detection heuristics

This uncertainty does not change the conclusion because the task requires deriving verdicts from available evidence. With zero findings to cite, I cannot claim malicious behavior. The extension's version (0.0.2) and user count (330) suggest it is a relatively new, low-adoption tool, which is consistent with a legitimate niche utility rather than a supply chain attack vector.

Limitations

This analysis is constrained by the absence of findings. I cannot cite specific file paths, finding titles, or code behaviors because none exist in the provided evidence bundle. A runtime analysis or manual code review would provide more definitive assessment of whether the extension's file sync functionality operates as intended without security risks.

Key Reasons

  • No security findings detected in evidence bundle
  • Empty findings_by_category indicates no malicious patterns identified
  • Extension appears to be a legitimate utility with no flagged behaviors

False Positive Considerations

  • No findings detected in evidence bundle
  • Empty findings_by_category prevents pattern analysis
  • Cannot assess behavior without code-level findings

Reviewed 2026-04-22; recommended action: no action; model confidence 65%.

About This Extension

Sync Arcane Forge knowledge base files into VS Code workspaces.

Frequently Asked Questions