VS Code Marketplace Verified

IBM Functional Testing

by IBM · 1 downloads
17e1ba75-7b38-57de-9cc4-eb1fb8b0f2a0 | v3.0.1
65/ 100
MEDIUM risk
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (65/100) still counts them.

No individual score drivers were recorded for this analysis.

Analysis record

Analysed
3 days ago
Version
v3.0.1
Artifact
SHA256 466…788
Source
Findings (non-IoC)

Is IBM Functional Testing safe?

IBM Functional Testing generates Galasa functional tests inside VS Code. It declares no special permissions and no host permissions, so it works through the normal editor API. The one network endpoint that fits its job is api.dataplatform.cloud.ibm.com, IBM's own Cloud Pak for Data API, and sending test configuration there is what the extension is for.

The findings that drove the score come mostly from one package. Eleven of them point at files like extension/prebuilds/keyring.darwin-arm64.node and extension/prebuilds/keyring.win32-x64-msvc.node. Those are prebuilt native addons from the keyring library, which stores secrets in the operating system's keychain. Machine code is unreadable to a scanner that matches text patterns, so the files get marked as obfuscated. They hide nothing that any normal .node file does not.

The rest is noise of a specific kind. Hundreds of entries are tagged as network indicators, and the values include accountcreationtest.java and constants.java, which are Java source filenames read as if they were web addresses, plus fragments like at.ch and al.bo pulled out of minified code. No malware signature matched, and nothing in the findings touches .env files, SSH keys, or git config.

So the extension handles credentials through the standard keychain binding and talks to an IBM domain, which is what a cloud testing tool does. None of the findings show a hidden download, a startup payload, or a read of your secrets that the stated job does not require. Install counts are still very low, so there is little track record from other users yet, but nothing points to this extension doing anything besides generating tests.

No Findings

All security checks passed

Publisher Evidence

Low

IBM

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

86
Noisy-finding weight
x1.00
Publisher domain
ibm.com
Observed
Store verification signal
Verified publisher
Verified
Extension portfolio
71
Portfolio

11 evidence rows available.

No Threats Detected

This extension passed all security checks

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

IBM Functional Testing generates Galasa functional tests inside VS Code and is published by IBM. The manifest lists no permissions and no host permissions, so the extension works through the ordinary VS Code API surface rather than any broad platform grant. Only one network endpoint in the list has the shape of a real address, api.dataplatform.cloud.ibm.com, IBM's Cloud Pak for Data API. A tool that generates and runs tests against IBM's platform needs to reach that host. The remaining entries are not endpoints: accountcreationtest.java and constants.java are Java source filenames parsed as hostnames, at.ch and al.bo are two-letter fragments lifted from minified strings, csslineclass.info is a CSS class name split on a dot, and collect.pro and cache.pro are property-access chains. That accounts for the bulk of the 342 indicator entries and tells you nothing about what the code does on the wire.

The eleven critical-severity hits all name one file family: extension/prebuilds/keyring.darwin-arm64.node, extension/prebuilds/keyring.win32-x64-msvc.node, and the rest of the platform builds under extension/prebuilds/. These are prebuilt native addons shipped by the keyring npm package, which stores secrets in the operating system keychain. The scanner labels them OBFUSCATION-NATIVE_BINARY_ADDON because compiled machine code is unreadable to a text-pattern engine. Every extension that ships a native addon produces this same finding. A .node file is not packed, encrypted, or self-modifying, and nothing in these eleven entries shows otherwise.

Credential access is where the verdict could have gone the other way. There are zero secret findings. Nothing reads .env, .ssh, .git/config, or cloud credential files. The only credential-adjacent component is the keyring addon, and it handles secrets the correct way, through the OS keychain binding, which is exactly what an IBM Cloud-authenticated test tool needs. Process and filesystem access are equally ordinary: test generation writes Java test files into the workspace and invokes the build. The malware and malware-signature categories are both empty, so no postinstall payload, dropper, or shell execution matched anywhere in the package.

The strongest counterargument is the combination of native keychain binaries and a live IBM Cloud endpoint. Those two together mean this extension can hold account credentials and reach the network, and if the publisher were unverified or the addons had been swapped, that pairing would justify a much harder look. IBM publishes the extension, the addons come from a widely used library, and no tampering indicator, unsigned binary flag, or outbound host outside IBM's domain shows up. The zero install count means there is no community track record to lean on yet, which is worth monitoring rather than treating as a signal of intent.

Key Reasons

  • All 11 critical findings are OBFUSCATION-NATIVE_BINARY_ADDON hits on prebuilt keyring .node addons under extension/prebuilds/, which are machine code by definition and unreadable to a text scanner.
  • Zero malware, malware-signature, secret, and tool-poisoning matches; no postinstall or dropper behavior anywhere in the package.
  • The 342 network indicators are parsing artifacts such as accountcreationtest.java, constants.java, at.ch, al.bo, and csslineclass.info, while the only real host is api.dataplatform.cloud.ibm.com, IBM's own platform API.
  • Published by IBM with no declared permissions or host permissions; the keyring addon is the standard OS keychain binding an IBM Cloud-authenticated tool needs.

False Positive Considerations

  • OBFUSCATION-NATIVE_BINARY_ADDON firing on compiled keyring .node prebuilds for every platform
  • IoC extractor reading Java filenames and minified-code fragments as hostnames
  • Low-severity code-smell volume across bundled dependencies
  • IoC count inflating severity despite containing no routable or suspicious host

Reviewed 2026-09-30; recommended action: no action; model confidence 86%.

About This Extension

Generate Galasa Functional tests

Frequently Asked Questions