VS Code Marketplace Verified

SuiteCloud Extension for Visual Studio Code

by Oracle Corporation · 45.0K users · 4.3 rating
17e93f7c-2d2b-5e3a-bfe7-43b3b48a2997 | v4.0.0
49/ 100
MEDIUM risk
No change since v3.1.3
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (49/100) still counts them.

Analysis record

Analysed
1 months ago
Version
v4.0.0
Artifact
SHA256 05A…F3B
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

4 detail rows

Publisher Evidence

Low

Oracle Corporation

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

92
Noisy-finding weight
x1.00
Publisher domain
oracle.com
Observed
Store verification signal
Verified publisher
Verified
Extension portfolio
28
Portfolio

11 evidence rows available.

Finding Categories

3
Network

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

The SuiteCloud Extension for Visual Studio Code is a legitimate enterprise development tool published by Oracle with 41,117 users. This extension enables developers to work with the SuiteCloud Development Framework (SDF) for NetSuite development, which justifies its filesystem and network capabilities.

Filesystem and Process Access: The extension requires workspace file access to read and write SuiteCloud project files, which aligns with its stated purpose as a development framework. The dependency finding at /tmp/extract-a434ca635e5215a4d71cfcd776eb567beccb0b698c44d144ecbbfc720331312a-379818769/extension/package.json shows @oracle/suitecloud-cli@^3.1.2, a legitimate Oracle CLI tool required for SDF operations. This is expected behavior for a development framework extension.

Network Access: The 11 network findings are almost entirely from bundled dependencies, not extension code. Network calls at extension/node_modules/rxjs/dist/bundles/rxjs.umd.js:6230, extension/node_modules/rxjs/dist/esm5/internal/observable/dom/fetch.js:32, and extension/node_modules/xml2js/lib/xml2js.bc.js:5792 are from third-party libraries (rxjs, xml2js) included in the package. The only network call from actual extension code is at extension/dist/webviews/FeedbackFormWebviewController.js:98, which is a fetch call in a feedback form webview controller—reasonable functionality for collecting user feedback.

Credential Access: No credential-access findings target actual secrets. There are zero findings in the secret category, and no references to .env files, SSH keys, cloud credentials, or VS Code secret storage. The code-smell findings (75 total) match generic patterns in minified JavaScript and bundled dependencies, not actual credential theft behavior.

Strongest Counterargument: The 75 high-severity code-smell findings might suggest suspicious behavior. However, these are YARA code-smell rules that fire on almost any non-trivial JavaScript, particularly minified and bundled code. Per documented false-positive patterns, code-smell findings with severity low and finding_type=code-smell are noise and should not drive verdicts. These findings reflect the presence of standard Node.js patterns (fetch, exec, fs, crypto) in legitimate bundled libraries, not malicious intent.

Conclusion: This extension shows no evidence of postinstall payload execution, credential theft, source code exfiltration, or supply chain poisoning. The findings are consistent with expected behavior for a development framework extension with bundled dependencies. Oracle's verified publisher status and 41K+ user adoption further support the benign nature of this extension.

Key Reasons

  • Verified Oracle publisher with 41,117 users
  • Network findings from bundled dependencies, not extension code
  • No credential access or malware signatures detected
  • Code-smell findings are documented YARA noise patterns
  • Filesystem access justified by SuiteCloud development framework purpose

False Positive Considerations

  • Bundled dependencies (rxjs, xml2js) triggering network findings
  • Code-smell YARA rules firing on minified JavaScript
  • Webview fetch calls for feedback form functionality
  • Oracle verified publisher with 41K+ users

Reviewed 2026-05-23; recommended action: suppress false positive; model confidence 85%.

VS Code version history

Risk trend by version

3 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
49
Change since first
-5
Change from previous
No change
Versions:
First analyzed version
3.1.2
Apr 3, 2026
Risk range
49 to 54
Across analyzed versions
Latest analyzed version
4.0.0
Aug 22, 2026
Selected version
medium
Version
v4.0.0
1 months ago
Risk score
49
Findings
4
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

Develop and deploy SuiteCloud Projects with SuiteCloud Development Framework (SDF).

Frequently Asked Questions