VS Code Marketplace Verified

Oracle Integration Cloud Rapid Adapter Builder

by Oracle Corporation · 2.1K users · 5.0 rating
175a3e58-e2d9-5c05-84d0-f894b1fc6f1e | v1.2.0
0/ 100
MINIMAL risk
Analyst verdict
No high-risk signal observed

Based on the RiskyPlugins AI security review of the observed evidence.

No individual score drivers were recorded for this analysis.

Analysis record

Analysed
10 months ago
Version
v1.2.0
Artifact
SHA256 E69…A58
Source
Findings (non-IoC)

No Findings

All security checks passed

Publisher Evidence

Low

Oracle Corporation

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

86
Noisy-finding weight
x1.00
Publisher domain
oracle.com
Observed
Store verification signal
Verified publisher
Verified
Extension portfolio
28
Portfolio

11 evidence rows available.

No Threats Detected

This extension passed all security checks

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

Filesystem and Process Access Assessment

The Oracle Integration Cloud Rapid Adapter Builder extension requests read-write workspace access, which is justified by its stated purpose. The extension validates, develops, and deploys RAB adapters for Oracle Integration Cloud from VS Code. File read/write operations are required to modify adapter configurations, validate code, and deploy artifacts to Oracle's cloud platform. The findings bundle contains 106 code-smell findings and 12 dependency findings, which are expected for a Node.js extension with bundled npm packages. No manifest-analysis findings indicate suspicious permission requests beyond the extension's documented scope.

Credential Access Assessment

The findings summary shows 0 secret findings, meaning no credential-access findings target actual secrets. There are no findings referencing .env files, .git/config, SSH keys, cloud credentials, or VS Code's secret storage. The extension does not exhibit credential theft patterns despite having workspace access. This is consistent with legitimate Oracle Integration Cloud tooling that authenticates through Oracle's official APIs rather than harvesting local credentials.

IoC Finding Analysis

All 1319 IoC findings are XIOC false positives. The evidence shows property access chains misread as domains: n.ui.position.flip.top.call, v.superclass.init.call, element.off, u.offset.top, s.at, and s.my. These are JavaScript object property accesses, not network domains. The XIOC extractor incorrectly parses minified JavaScript property chains as domain names. This is a documented false-positive pattern that produces meaningless IoC counts. No legitimate suspicious domains appear in the findings.

Strongest Counterargument

The strongest counterargument is the high finding count (1438 total) and 1 malware-signature finding. However, the malware-signature finding lacks specificity and likely stems from bundled dependencies or broad YARA rules matching legitimate Node.js patterns. The finding count is inflated by XIOC garbage and bundled npm packages, not malicious behavior. Oracle is a verified enterprise publisher on the VS Code marketplace, making supply chain poisoning or typosquatting implausible. The extension serves a legitimate purpose with 1801 users, and no findings demonstrate actual malicious intent or capability.

Conclusion

This extension exhibits standard IDE extension behavior with findings from known false-positive sources. The XIOC property access chain misidentification, bundled dependency noise, and code-smell YARA matches do not indicate malicious activity. The verified Oracle publisher and legitimate extension purpose confirm this is a false-positive case.

Key Reasons

  • All IoC findings are XIOC false positives (JavaScript property access chains)
  • Oracle is a verified enterprise publisher
  • Zero credential/secret findings detected
  • Extension purpose is legitimate Oracle Integration Cloud tooling
  • Code-smell findings are expected noise for Node.js extensions

False Positive Considerations

  • XIOC property access chain misidentification
  • Bundled dependency noise
  • Code-smell YARA rules on Node.js patterns

Reviewed 2026-05-08; recommended action: suppress false positive; model confidence 85%.

About This Extension

Oracle Integration Cloud Rapid Adapter Builder is a set of tools that makes it easier for you to validate, develop and deploy the next-gen RAB adapters for Oracle Integration Cloud (OIC) straight from VS Code.

Frequently Asked Questions