VS Code Marketplace Verified

Nakka - AI code agent

by Nakka · 3 users
138bd8b2-c28c-5032-a9cd-d2840648308a | v1.0.0
100/ 100
CRITICAL risk
Risk verdict
Do not install

Score-based assessment (critical risk, 100/100). No analyst review available.

Analysis record

Analysed
6 days ago
Version
v1.0.0
Artifact
SHA256 2F4…2BC
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

337 detail rows
Showing 25 of 76 · highest severity first

YARA Rule Matches

27 rules
SeverityRuleHitsFilesMetadata
HIGHsupply chain sourcemap appended iife 1
out/extension.js
-
LOWcredential macos keychain 1
out/extension.js
-
LOWpostinstall persistence mechanism 7
out/extension.jsout/start_ollama.shgui/assets/MonacoDiff.js +4 more
-
LOWcredential env files 4
gui/assets/index.jsout/extension.jsgui/assets/MonacoDiff.js +1 more
-
LOWAPT1 WEBC2 Y21K 1
out/extension.js
-
LOWRedirectToUnknownPath 1
out/extension.js
-
LOWpostinstall file download 16
out/start_ollama.shconfig_schema.jsonout/tree-sitter-wasms/tree-sitter-elixir.wasm +13 more
-
LOWNoUseWeakRandom 9
gui/assets/MonacoDiff.jsgui/assets/cytoscape.esm.jsout/extension.js +6 more
-
LOWNoUseEval 1
out/extension.js
-
LOWcredential git credentials 1
gui/assets/index.js
-
LOWSQLInjection 2
gui/assets/MonacoDiff.jsgui/assets/index.js
-
LOWBolonyokte 1
out/extension.js
-
LOWUsingCommandLineArguments 2
buildtarget.jsout/extension.js
-
LOWLocalStorageShouldNotBeUsed 2
gui/assets/index.jsout/extension.js
-
LOWDebuggerStatementsShouldNotBeUsed 9
nakka_rc_schema.jsongui/assets/handlebars.jsgui/assets/index.js +6 more
-
LOWServerHostnameNotVerified 1
out/extension.js
-
LOWpostinstall environment access 33
gui/assets/ChevronRightIcon.jsgui/assets/dagre-KLK3FWXG.jsgui/assets/layout.js +30 more
-
LOWpostinstall crypto operations 39
out/tree-sitter-wasms/tree-sitter-ocaml.wasmgui/assets/c4Diagram-IC4MRINW.jsgui/assets/xychartDiagram-JWTSCODW.js +36 more
-
LOWpostinstall file manipulation 41
out/llamaTokenizer.mjsgui/assets/MonacoDiff.jsout/tree-sitter-wasms/tree-sitter-rust.wasm +38 more
-
LOWNoUseSocketManually 1
out/extension.js
-
LOWpostinstall registry modification 5
NOTICEgui/assets/index.jsgui/assets/treemap-KZPCXAKY.js +2 more
-
LOWpostinstall obfuscation 17
out/llamaTokenizer.mjsgui/assets/xychartDiagram-JWTSCODW.jsout/extension.js +14 more
-
LOWpostinstall network communication 19
out/llamaTokenizer.mjsreadme.mdgui/assets/MonacoDiff.js +16 more
-
LOWpostinstall system command 41
extension.vsixmanifestgui/assets/c4Diagram-IC4MRINW.jsout/tree-sitter-wasms/tree-sitter-objc.wasm +38 more
-
LOWOriginsNotVerified 4
gui/assets/indexConsole.jsgui/assets/index.jsgui/assets/MonacoDiff.js +1 more
-
LOWUsingShellInterpreterWhenExecutingOSCommands 1
out/extension.js
-
LOWcredential postgres credentials 1
out/extension.js
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

8,937 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Publisher Evidence

Limited evidence

Nakka

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

32
Noisy-finding weight
x1.00
Publisher domain
nakka.in
Observed
Store verification signal
Not exposed
Not exposed
Extension portfolio
1
Portfolio

13 evidence rows available.

Finding Categories

1
Malware Signatures
26
Obfuscation
5
Network
8,937
IoC Indicators

YARA Rules Matched

27 rules(261 hits)
supply chain sourcemap appended iife credential macos keychain postinstall persistence mechanism credential env files APT1 WEBC2 Y21K RedirectToUnknownPath postinstall file download NoUseWeakRandom NoUseEval credential git credentials SQLInjection Bolonyokte UsingCommandLineArguments LocalStorageShouldNotBeUsed DebuggerStatementsShouldNotBeUsed ServerHostnameNotVerified +11 more

Security Analysis Summary

Security Analysis Overview

Nakka - AI code agent is a Visual Studio Code Marketplace extension published by Nakka. Version 1.0.0 has been analyzed by the Risky Plugins security platform, receiving a risk score of 100/100 (CRITICAL risk) based on 9274 security findings.

Risk Assessment

This extension presents critical security risk. Severe issues were detected, potentially including malware indicators, exposed secrets, or dangerous behaviors. Installation is strongly discouraged until these issues are addressed.

Findings Breakdown

  • Critical: 6 finding(s)
  • High: 4 finding(s)
  • Medium: 8959 finding(s)
  • Low: 305 finding(s)

What Was Analyzed

The security assessment covers multiple analysis categories:

  • Malware Detection: YARA rule matching against 2,400+ malware signatures
  • Secret Detection: Scanning for exposed API keys, tokens, and credentials
  • Static Analysis: Code-level security analysis for common vulnerability patterns
  • Network Analysis: Detection of suspicious network communications and endpoints
  • Obfuscation Detection: Identification of code obfuscation techniques

Developer Information

Nakka - AI code agent is published by Nakka on the Visual Studio Code Marketplace marketplace. The extension has approximately 3 users.

Recommendation

This extension is not recommended for installation without thorough manual review. Consider alternatives with lower risk scores, or contact the developer to address the identified security concerns.

About This Extension

An AI coding agent that reads, searches, runs commands and edits code — with three permission modes deciding how much it does on its own. Anthropic, OpenAI-compatible or Ollama.

Frequently Asked Questions