The AI review rates the findings as likely false positive, but the risk score (51/100) still counts them.
Analysis record
- Analysed
- 2 weeks ago
- Version
- v1.17.8
- Artifact
- SHA256 1D1…029
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
Publisher Evidence
LowGitHub
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
13 evidence rows available.
Finding Categories
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality strong.
CodeQL for Visual Studio Code Security Analysis
This extension is GitHub's official CodeQL integration for Visual Studio Code. CodeQL is a well-established static analysis tool used by developers to find security vulnerabilities in their codebases.
Filesystem and Process Access Justification
The extension's network activity is fully justified by its stated purpose. Network calls detected in extension/out/webview.js (lines 51388, 52147, 52611, 52137) and extension/out/extension.js (lines 1928, 1962) use standard fetch and XMLHttpRequest APIs. CodeQL requires these connections to synchronize queries with GitHub's CodeQL servers, download query packs, and upload analysis results. This network behavior is expected for a tool that integrates with cloud-based analysis services.
The extension declares zip-a-folder@^3.1.6 as a dependency, which is used for packaging analysis results and query packs. This is a standard Node.js package with no security concerns. Filesystem access for reading source code is the core function of a static analysis tool.
Credential and Secret Access
No credential-access findings were detected. The analysis found zero secret-related findings, and there are no indications of the extension reading .env files, SSH keys, cloud credentials, or VS Code's secret storage. This is appropriate behavior for a code analysis tool that does not need to access developer credentials.
Strongest Counterargument
The most significant concern would be the 57 code-smell findings flagged at high severity. However, these findings stem from YARA rules that match basic Node.js patterns like fetch, exec, fs, and process.env references. According to CVEQ's documented false-positive patterns, code-smell findings are classified as noise and should not drive security verdicts. The extension's network activity, while flagged as medium severity, represents legitimate communication with GitHub's CodeQL infrastructure rather than suspicious data exfiltration.
Conclusion
This extension demonstrates no malicious indicators. The 128 total findings consist entirely of expected behavior: legitimate network calls for cloud integration, standard dependency declarations, and YARA code-smell noise. The extension is published by GitHub, has over 48,000 users, and performs its stated function of static code analysis without any evidence of credential theft, data exfiltration, or supply chain compromise. The zero IoC matches, zero malware signatures, and zero obfuscation findings confirm this is a legitimate development tool.
Key Reasons
- Official GitHub extension with 48,247 users
- Zero IoC, malware signatures, or secret findings
- Network calls are expected for CodeQL cloud integration
- Code-smell findings are documented YARA noise
- No credential theft or data exfiltration indicators
False Positive Considerations
- Code-smell YARA rules matching standard Node.js patterns
- Network calls flagged as suspicious despite being legitimate for cloud integration
- Dependency scanning generating findings on standard npm packages
- Metadata hash entries flagged as findings
Reviewed 2026-05-23; recommended action: suppress false positive; model confidence 95%.
Open VSX version history
Risk trend by version
2 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace