OpenVSX Registry Verified

Translator's Copilot

08910e45-9261-5c3e-9cf3-8276c25d12cd | v1.1.4
0/ 100
MINIMAL risk
Analyst verdict
No high-risk signal observed

Based on the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
10 months ago
Version
v1.1.4
Source
Findings (non-IoC)

No Findings

All security checks passed

Publisher Evidence

Low

project-accelerate

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

65
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Verified publisher
Verified
Extension portfolio
11
Portfolio

12 evidence rows available.

No Threats Detected

This extension passed all security checks

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

The Translator's Copilot extension (developer: project-accelerate, OpenVSX) shows 3749 total findings, but the nature of these findings indicates false positives rather than malicious activity.

Filesystem/Process Access Justification: There are no findings in the evidence bundle showing filesystem access, process execution, or workspace reads. The extension's stated purpose as a "minimalist AI Copilot for translation assistance" does not require broad filesystem access, and no findings demonstrate such access exists. The absence of code-smell findings related to child_process.exec, fs module usage, or workspace file operations means there is no evidence of unjustified capability.

Credential Access Findings: The secret category shows 0 findings. There are no credential_* YARA rule matches, no evidence of .env file reads, no SSH key access, and no cloud credential access. This is critical - a credential theft extension would show findings in the secret category, which this extension lacks entirely.

IoC Analysis: All 3189 IoC findings reference legitimate Bible text resource domains: ebible.org (Electronic Bible Society), png.bible, and inscript.org. These URLs (e.g., http://ebible.org/apwNT/, http://png.bible/apr/, http://inscript.org/arbwbtc/) are appropriate for a translation tool that would need to fetch Bible text in various languages. These are not command-and-control servers, not data exfiltration endpoints, and not suspicious domains. The IoC extractor flagged these because they are URLs, not because they are malicious.

Obfuscation and Code-Smell Noise: The 264 obfuscation findings and 261 code-smell findings are expected patterns from minified/bundled JavaScript. As documented in the false-positive patterns, "Minified/bundled JavaScript (webpack, esbuild, rollup output) is NOT obfuscation" and "code-smell findings (severity=low, finding_type=code-smell) are NOISE." These findings fire on any non-trivial JavaScript and do not indicate malicious intent.

Strongest Counterargument: The high finding count (3749 total) could suggest risk. However, the scoring system has known biases where "IoC volume and code-smell counts disproportionately inflate scores." The verdict must be based on finding nature, not count. Zero malware signatures, zero credential theft findings, zero network exfiltration findings, and legitimate Bible resource URLs confirm this is a false positive.

The extension exhibits no high-risk patterns: no postinstall payload execution, no credential theft, no suspicious network activity, and no supply chain indicators.

Key Reasons

  • All IoC findings are legitimate Bible text resource domains appropriate for translation tool
  • Zero credential theft or secret access findings
  • Zero malware signatures or malware findings
  • Obfuscation and code-smell findings are expected minified code noise
  • No evidence of postinstall payload execution or data exfiltration

False Positive Considerations

  • Bible text resource domains (ebible.org, png.bible, inscript.org) flagged as IoC
  • Minified/bundled JavaScript triggering obfuscation YARA rules
  • Code-smell findings from standard Node.js patterns
  • Score inflation from high IoC count without malicious context

Reviewed 2026-04-27; recommended action: suppress false positive; model confidence 85%.

About This Extension

A minimalist AI Copilot for translation assistance.

Frequently Asked Questions