OpenVSX Registry Verified

CL

by IBM
001f207c-c028-51c6-a5ae-fc10f5828800 | v1.2.7
23/ 100
LOW risk
No change since v1.2.6
Analyst verdict
No high-risk signal observed

Based on the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
5 days ago
Version
v1.2.7
Artifact
SHA256 592…86D
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

1 detail row

Publisher Evidence

Low

IBM

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

60
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Verified publisher
Verified
Extension portfolio
5
Portfolio

12 evidence rows available.

Finding Categories

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

This extension provides CLLE (CL Language Environment) language tools for IBM i development. The developer is IBM, a verified and trusted publisher in the ecosystem with over 10,000 users on OpenVSX.

The extension's filesystem and process access patterns are fully justified by its stated purpose. The presence of vscode-languageclient@^7.0.0 in extension/package.json confirms this is a language server extension, which legitimately requires reading source files to provide IntelliSense, syntax highlighting, and code completion. Language server extensions spawn processes to communicate with language servers—this is standard, expected behavior for development tools of this type. Files like extension/out/server.js and extension/out/extension.js are standard build outputs for language server implementations.

No credential theft patterns were detected. The analysis found zero instances of code accessing .env files, SSH keys, cloud credentials, or VS Code's secret storage. The extension does not exhibit the credential-access patterns that would indicate malicious intent. No findings reference sensitive paths like .ssh, .git/config, or cloud provider credential files.

The 32 "high" severity findings flagged by automated scanners are all code-smell type detections—these match generic JavaScript patterns like environment variable references and standard Node.js APIs. These are documented false positives that trigger on almost any non-trivial JavaScript code, including bundled dependencies. The actual threat indicators show zero malware signatures, zero suspicious network connections, zero obfuscation, and zero tool-poisoning indicators. The metadata findings (HASH entries in files like extension/LICENSE.txt, extension/tsconfig.base.json, [Content_Types].xml) are simply file hashes, not security concerns.

The strongest counterargument to this verdict would be the high count of "high" severity findings. However, these findings are explicitly documented as noise in IDE extension analysis—they match basic code patterns rather than malicious behavior. The nature of findings matters far more than their count or assigned severity labels. Code-smell findings on minified or bundled JavaScript are expected and do not indicate compromise.

This extension is a legitimate language tool from IBM with no evidence of malicious behavior. The findings result from standard code-scanning patterns applied to development tool code.

Key Reasons

  • Zero malware signatures, IoCs, or obfuscation indicators
  • IBM is a verified publisher with 10,000+ users
  • vscode-languageclient dependency confirms legitimate language server purpose
  • All 32 high-severity findings are code-smell type noise
  • No credential access or exfiltration patterns detected

False Positive Considerations

  • Code-smell YARA rules matching generic JavaScript patterns
  • Bundled vscode-languageclient dependency triggering scanner noise
  • Minified/bundled dist files from webpack build output
  • Severity inflation from code-smell counts

Reviewed 2026-05-23; recommended action: suppress false positive; model confidence 92%.

Open VSX version history

Risk trend by version

4 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
23
Change since first
-19
Change from previous
No change
Versions:
First analyzed version
1.2.4
Apr 18, 2026
Risk range
23 to 43
Across analyzed versions
Latest analyzed version
1.2.7
Sep 26, 2026
Selected version
low
Version
v1.2.7
5 days ago
Risk score
23
Findings
1
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

CLLE language tools

Frequently Asked Questions