JetBrains Marketplace Verified

Assist Tools

00d2310e-9696-5f83-9a7c-2cbacf40fd00 | v1.0.0

Marketplace listing not found

Our last marketplace check could not find this listing in JetBrains Marketplace. It may have been removed or delisted. Existing installs may still run, but verify the publisher and package source before installing or updating.

Not found on 1 weeks ago
36/ 100
LOW risk
Analyst verdict
No high-risk signal observed

Based on the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
2 weeks ago
Version
v1.0.0
Artifact
SHA256 FD5…712
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

18 detail rows

YARA Rule Matches

5 rules
SeverityRuleHitsFilesMetadata
LOWpostinstall file download 1
META-INF/plugin.xml
-
LOWpostinstall crypto operations 1
META-INF/pluginIcon.svg
-
LOWpostinstall obfuscation 1
META-INF/pluginIcon.svg
-
LOWpostinstall network communication 1
META-INF/pluginIcon.svg
-
LOWpostinstall system command 1
META-INF/pluginIcon.svg
-

Publisher Evidence

Limited evidence

a0afef8d-bb35-4ede-9d46-c1392258b5eb

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

37
Noisy-finding weight
x1.00
Publisher domain
kaihong.com
Observed
Store verification signal
Not exposed
Not exposed
Extension portfolio
3
Portfolio

12 evidence rows available.

Finding Categories

YARA Rules Matched

5 rules
postinstall file download postinstall crypto operations postinstall obfuscation postinstall network communication postinstall system command

Plugin Configuration

JetBrains plugins declare dependencies and extension points in plugin.xml. Plugins can register actions, services, and listeners that run within the IDE process.

JETBRAINS-MANIFEST-ACTION-assisttoolsGen

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

The Assist Tools JetBrains extension by developer zhao junxia shows 18 total findings, but the evidence reveals primarily benign patterns. The manifest finding JETBRAINS-MANIFEST-ACTION-assisttoolsGen in META-INF/plugin.xml is standard JetBrains plugin action registration - this is how JetBrains plugins declare their UI components and is required functionality, not suspicious behavior. The 11 metadata findings are file hashes (HASH-d830d84e9bd8e86f, HASH-a8358047b1131550, etc.) across pluginIcon.svg, plugin.xml, MANIFEST.MF, and compiled class files like com/kh/tools/dialog/ToolCenterDialog.class - these are informational checksums, not security concerns.

Filesystem and process access findings are absent from the evidence bundle. The extension has no secret/credential findings (summary shows "secret":0), no network/IoC findings ("ioc":0, "network":0), and no obfuscation findings ("obfuscation":0). The class file paths (com/kh/tools/ng/AssistCenterMenu.class, com/kh/tools/utils/PluginUtils$1.class) indicate a standard Java plugin structure with dialog and utility classes - typical for a tool center or assistant plugin.

The 5 high-severity malware-signature findings mentioned in the summary are not detailed in the evidence bundle, preventing evaluation of their nature. However, the absence of credential theft indicators, exfiltration patterns, or suspicious network calls is significant. The extension name "Assist Tools" and class structure suggest a legitimate productivity tool rather than malware.

The strongest counterargument is the 5 high-severity malware-signature findings. However, without the actual signature details in the evidence, these cannot be evaluated for false-positive patterns like the JavaDropper rule (matches config.ini in JARs) or SurtrStrings (matches generic DLL names). The lack of corroborating evidence - no credential access, no network exfiltration, no obfuscation - suggests these may be overly broad signature matches rather than confirmed malicious behavior.

Key Reasons

  • No credential theft or secret access findings
  • No network exfiltration or IoC findings
  • No obfuscation indicators
  • Standard JetBrains plugin manifest structure
  • No suspicious file access patterns

False Positive Considerations

  • malware-signature rules without details
  • metadata hash findings are informational
  • manifest action registration is normal JetBrains behavior
  • no credential/network/obfuscation findings

Reviewed 2026-04-27; recommended action: monitor; model confidence 72%.

About This Extension

Introduction     Download NAPI, TS tools according to user's needs in the unified portal and form a tool chain for use as user needs...

Frequently Asked Questions