Based on the RiskyPlugins AI security review of the observed evidence.
Analysis record
- Analysed
- 2 weeks ago
- Version
- v0.10.6
- Artifact
- SHA256 EF2…9E8
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
Publisher Evidence
LowShopify
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
12 evidence rows available.
Finding Categories
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality strong.
This extension is a VS Code plugin for connecting with the Ruby LSP, published by Shopify, a well-known and trusted company in the developer tooling space. The extension has 26,553,300 users, indicating widespread adoption and community trust.
Filesystem and Process Access Justification: The two findings in this scan are dependency declarations (DEP-vscode-languageclient-^9.0.1 and DEP-vscode-jsonrpc-^8.2.1 in /extension/package.json). These are the standard libraries required for any VS Code language server extension to communicate with the Language Server Protocol. Language servers legitimately need to read source code files to provide intellisense, code completion, diagnostics, and navigation features. This is the core purpose of the extension as stated in its description. No findings indicate unauthorized file access beyond what a language server requires.
Credential Access: The scan shows zero secret findings and zero credential-access findings. There is no evidence of attempts to read .env files, .git/config, SSH keys, cloud credentials, or VS Code secret storage. The threat_indicators field shows "secret":"0", confirming no credential theft patterns were detected.
Strongest Counterargument: A skeptic might argue that any extension with workspace access could potentially exfiltrate code. However, this extension has zero malware signatures ("malware-signature":"0"), zero IoC hits ("ioc":"0"), zero obfuscation findings ("obfuscation":"0"), and zero network activity flags ("network":"0"). The absence of these indicators, combined with Shopify's reputation and 26+ million users, makes malicious intent implausible. The only findings are legitimate dependency declarations that any VS Code extension requires.
This is a clean scan of a legitimate development tool. The automated scanner flagged normal package.json dependencies as findings, but these represent expected behavior for a language server extension, not security concerns.
Key Reasons
- Zero malware signatures, IoC hits, or obfuscation findings detected
- Only findings are standard VS Code language server dependencies in package.json
- Published by Shopify, a well-known legitimate company
- 26+ million users indicates widespread trust and adoption
- No credential access or suspicious network activity detected
False Positive Considerations
- Dependency findings flagged as security issues when they are normal package.json declarations
- No actual malicious patterns detected in code or network activity
- Standard VS Code language server libraries misidentified as security findings
Reviewed 2026-05-23; recommended action: no action; model confidence 95%.
Open VSX version history
Risk trend by version
5 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace