VS Code Marketplace Verified

Gen Sage

by Gen · 2.4K users · 5.0 rating
073cdff8-42b1-56ae-b5c6-5b775a1a16ae | v0.13.0
73/ 100
HIGH risk
No change since v0.12.0
Risk verdict
Review before use

Score-based assessment (high risk, 73/100). No analyst review available.

Analysis record

Analysed
1 weeks ago
Version
v0.13.0
Artifact
SHA256 639…741
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

202 detail rows

YARA Rule Matches

17 rules
SeverityRuleHitsFilesMetadata
HIGHMimikatz Memory Rule 1

Detects password dumper mimikatz in memory

1
resources/threats/mitre.yaml
Florian Roth FP 5%
LOWcredential env files 14
dist/vscode_extension.jsdist/mcp-server.cjsdist/vscode_extension.js.map +11 more
-
LOWpostinstall persistence mechanism 11
resources/threats/persistence.yamldist/sage-hook.cjs.mapreadme.md +8 more
-
LOWcredential docker env 2
resources/threats/win-credentials.yamlresources/threats/credentials.yaml
-
LOWNoUseWeakRandom 2
dist/mcp-server.cjs.mapdist/mcp-server.cjs
-
LOWpostinstall file download 23
dist/model-download-worker.cjs.mapreadme.mddist/vscode_extension.js +20 more
-
LOWcredential ssh keys 1
resources/threats/credentials.yaml
-
LOWUsingCommandLineArguments 6
dist/sage-hook.cjs.mapdist/sage-hook.cjsdist/model-download-worker.cjs.map +3 more
-
LOWpostinstall obfuscation 18
readme.mdresources/threats/commands.yamlresources/threats/mac-obfuscation.yaml +15 more
-
LOWcredential aws credentials 3
resources/threats/credentials.yamlresources/threats/files.yamlresources/threats/win-credentials.yaml
-
LOWpostinstall crypto operations 14
dist/model-download-worker.cjsdist/mcp-server.cjs.mapdist/skill-upload-worker.cjs.map +11 more
-
LOWpostinstall file manipulation 25
resources/threats/commands.yamldist/skill-upload-worker.cjs.mapresources/threats/mac-commands.yaml +22 more
-
LOWpostinstall system command 40
resources/threats/_macros.yamlresources/threats/commands.yamlresources/threats/prompt-injection.yaml +37 more
-
LOWpostinstall registry modification 15
dist/sage-hook.cjsdist/skill-upload-worker.cjsdist/mcp-server.cjs +12 more
-
LOWpostinstall network communication 14
resources/threats/commands.yamlresources/threats/mitre.yamldist/mcp-server.cjs +11 more
-
LOWUsingShellInterpreterWhenExecutingOSCommands 5
dist/sage-hook.cjsdist/vscode_extension.jsdist/sage-hook.cjs.map +2 more
-
LOWcredential postgres credentials 3
resources/threats/files.yamlresources/threats/win-credentials.yamlresources/threats/credentials.yaml
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

81 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Publisher Evidence

Limited evidence

Gen

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

42
Noisy-finding weight
x1.00
Publisher domain
gendigital.com
Observed
Store verification signal
Not exposed
Not exposed
Extension portfolio
3
Portfolio

13 evidence rows available.

Finding Categories

1
Malware Signatures
5
Network
81
IoC Indicators

YARA Rules Matched

17 rules(197 hits)
Mimikatz Memory Rule 1 credential env files postinstall persistence mechanism credential docker env NoUseWeakRandom postinstall file download credential ssh keys UsingCommandLineArguments postinstall obfuscation credential aws credentials postinstall crypto operations postinstall file manipulation postinstall system command postinstall registry modification postinstall network communication UsingShellInterpreterWhenExecutingOSCommands +1 more

Security Analysis Summary

Security Analysis Overview

Gen Sage is a Visual Studio Code Marketplace extension published by Gen. Version 0.13.0 has been analyzed by the Risky Plugins security platform, receiving a risk score of 73.41/100 (HIGH risk) based on 283 security findings.

Risk Assessment

This extension presents high security risk. Significant concerns were identified during analysis. It is not recommended for use in sensitive or production environments without thorough review.

Findings Breakdown

  • High: 1 finding(s)
  • Medium: 86 finding(s)
  • Low: 196 finding(s)

What Was Analyzed

The security assessment covers multiple analysis categories:

  • Malware Detection: YARA rule matching against 2,400+ malware signatures
  • Secret Detection: Scanning for exposed API keys, tokens, and credentials
  • Static Analysis: Code-level security analysis for common vulnerability patterns
  • Network Analysis: Detection of suspicious network communications and endpoints
  • Obfuscation Detection: Identification of code obfuscation techniques

Developer Information

Gen Sage is published by Gen on the Visual Studio Code Marketplace marketplace. The extension has approximately 2K users.

Recommendation

This extension is not recommended for installation without thorough manual review. Consider alternatives with lower risk scores, or contact the developer to address the identified security concerns.

VS Code version history

Risk trend by version

6 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
73
Change since first
+2
Change from previous
No change
Versions:
First analyzed version
0.6.0
Mar 21, 2026
Risk range
52 to 73
Across analyzed versions
Latest analyzed version
0.13.0
Sep 12, 2026
Selected version
high
Version
v0.13.0
1 weeks ago
Risk score
73
Findings
283
Change vs previous
0

Pick any point on the chart to explore that version's code below.

About This Extension

Safety for Agents — protects AI agent tool calls against dangerous commands, malicious URLs, and harmful file writes.

Frequently Asked Questions