VS Code Marketplace Verified

Pyrefly - Python Language Tooling

by Meta · 86.0K users · 5.0 rating
131e5f92-82bd-5dd3-8593-116df6f4d2c3 | v1.3.9002
42/ 100
MEDIUM risk
No change since v1.3.9001
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (42/100) still counts them.

Analysis record

Analysed
Yesterday
Version
v1.3.9002
Artifact
SHA256 39D…D21
Source
Findings (non-IoC)

Is Pyrefly - Python Language Tooling safe?

Pyrefly is Meta's Python extension for VS Code. It gives you autocomplete, type checking and code navigation by running Pyrefly, an open source language server. This extension declares no special permissions, and the scan found no network endpoints, so nothing in its manifest grants it access to credentials, other extensions or anything outside your workspace.

The findings all come from generic YARA rules that look for Node.js patterns. YARA--UsingShellInterpreterWhenExecutingOSCommands and YARA--postinstall_system_command both match extension/dist/extension.js, the bundled code that launches the language server, and the same system command rule also matches extension/package.json. If those matches were real, they would mean the extension runs shell commands you never asked for. Here they line up with the one command a language server must run to start. The clearest tell is YARA--postinstall_network_communication matching extension/LICENSE.txt, a plain license text file with no network code in it at all.

Nothing in the scan found code reading .env files, SSH keys or cloud credentials, and no malware signature or suspicious domain turned up. The matches come from the scanner tripping on minified build output, on a scripts entry in a manifest, and on rule names written for npm install scripts rather than for a language server.

No Findings

All security checks passed

Publisher Evidence

Low

Meta

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

88
Noisy-finding weight
x1.00
Publisher domain
meta.com
Observed
Store verification signal
Verified publisher
Verified
Extension portfolio
6
Portfolio

12 evidence rows available.

No Threats Detected

This extension passed all security checks

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

Pyrefly is Meta's Python language tooling extension: autocomplete, type checking and code navigation backed by an open source language server. That shape explains nearly everything the scan flagged.

The code-smell matches all land in bundled build output or boilerplate text. YARA--postinstall_system_command, YARA--postinstall_obfuscation and YARA--UsingShellInterpreterWhenExecutingOSCommands fire on extension/dist/extension.js, the webpack bundle of the extension host code. A rule set that looks for child_process patterns and shell invocation will match any bundle that spawns a subprocess, and spawning a subprocess is this extension's entire job. The same system command rule also matches resources/find_pyrefly.py, a helper whose filename states its purpose: locate the Pyrefly server binary so the extension can launch it. It matches extension/package.json too, which is the rule firing on the presence of a scripts block rather than on any executed command.

The clearest sign these are lexical matches rather than behaviour is YARA--postinstall_network_communication matching extension/LICENSE.txt. A license file has no network behaviour to detect, so whatever the rule keys on there is text.

Credential access is absent. There are no secret findings of any kind: nothing reads .env files, .ssh keys, .git/config or cloud credential stores, and nothing touches VS Code secret storage. No network endpoints were extracted, no IP or domain indicators were extracted, and no malware signature matched. The dependency entries, [email protected], underscore@^1.13.8 and serialize-javascript@^7.0.5, are ordinary packages for a VS Code language client.

Filesystem and process access here is the job, not a deviation from it. A language server has to read the workspace to type check it and has to run a Python process to do the analysis. The extension publishes under Meta, ships version 1.3.9002 to roughly 86,000 users on the VS Code marketplace, and its name is not a clone of a more popular package.

The strongest counterargument is that dist/extension.js genuinely does contain shell interpreter usage, so the capability exists and a future version could point that capability somewhere it should not go. Capability is not intent. Almost every language extension on the marketplace spawns processes, and the rules that fired belong to the generic postinstall family that the scanner applies to any Node.js bundle. Nothing in this scan shows code reaching outside the workspace, contacting an unknown host, or collecting credentials.

Key Reasons

  • All 12 code-smell matches are low-severity generic postinstall_* YARA rules hitting dist/extension.js, package.json and resources/find_pyrefly.py, which is bundled build output and language server bootstrap code
  • YARA--postinstall_network_communication matching extension/LICENSE.txt shows the rule family is matching plain text, not behaviour
  • Zero secret findings: no .env, .ssh, .git/config or credential store access, and no VS Code secret storage use
  • Zero network endpoints, zero IoC, zero obfuscation and zero malware signatures across 18 findings
  • Official Meta publisher, ~86,000 installs, non-typosquatting name, standard dependencies ([email protected])

False Positive Considerations

  • Generic postinstall_* YARA rules matching any bundled Node.js code that spawns processes
  • YARA rule firing on LICENSE.txt text as postinstall_network_communication
  • Code-smell findings in minified dist/extension.js webpack output
  • Dependency enumeration of standard packages labeled as low-severity findings

Reviewed 2026-10-01; recommended action: suppress false positive; model confidence 90%.

VS Code version history

Risk trend by version

21 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
42
Change since first
No change
Change from previous
No change
Versions:
First analyzed version
0.48.2
Jan 18, 2026
Risk range
31 to 72
Across analyzed versions
Latest analyzed version
1.3.9002
Sep 30, 2026
Selected version
medium
Version
v1.3.9002
Yesterday
Risk score
42
Findings
18
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

Python autocomplete, typechecking, code navigation and more! Powered by Pyrefly, an open-source language server

Frequently Asked Questions