SuiteCloud Extension for Visual Studio Code
The AI review rates the findings as likely false positive, but the risk score (49/100) still counts them.
Analysis record
- Analysed
- 1 months ago
- Version
- v4.0.0
- Artifact
- SHA256 05A…F3B
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
Publisher Evidence
LowOracle Corporation
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
11 evidence rows available.
Finding Categories
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality strong.
The SuiteCloud Extension for Visual Studio Code is a legitimate enterprise development tool published by Oracle with 41,117 users. This extension enables developers to work with the SuiteCloud Development Framework (SDF) for NetSuite development, which justifies its filesystem and network capabilities.
Filesystem and Process Access: The extension requires workspace file access to read and write SuiteCloud project files, which aligns with its stated purpose as a development framework. The dependency finding at /tmp/extract-a434ca635e5215a4d71cfcd776eb567beccb0b698c44d144ecbbfc720331312a-379818769/extension/package.json shows @oracle/suitecloud-cli@^3.1.2, a legitimate Oracle CLI tool required for SDF operations. This is expected behavior for a development framework extension.
Network Access: The 11 network findings are almost entirely from bundled dependencies, not extension code. Network calls at extension/node_modules/rxjs/dist/bundles/rxjs.umd.js:6230, extension/node_modules/rxjs/dist/esm5/internal/observable/dom/fetch.js:32, and extension/node_modules/xml2js/lib/xml2js.bc.js:5792 are from third-party libraries (rxjs, xml2js) included in the package. The only network call from actual extension code is at extension/dist/webviews/FeedbackFormWebviewController.js:98, which is a fetch call in a feedback form webview controller—reasonable functionality for collecting user feedback.
Credential Access: No credential-access findings target actual secrets. There are zero findings in the secret category, and no references to .env files, SSH keys, cloud credentials, or VS Code secret storage. The code-smell findings (75 total) match generic patterns in minified JavaScript and bundled dependencies, not actual credential theft behavior.
Strongest Counterargument: The 75 high-severity code-smell findings might suggest suspicious behavior. However, these are YARA code-smell rules that fire on almost any non-trivial JavaScript, particularly minified and bundled code. Per documented false-positive patterns, code-smell findings with severity low and finding_type=code-smell are noise and should not drive verdicts. These findings reflect the presence of standard Node.js patterns (fetch, exec, fs, crypto) in legitimate bundled libraries, not malicious intent.
Conclusion: This extension shows no evidence of postinstall payload execution, credential theft, source code exfiltration, or supply chain poisoning. The findings are consistent with expected behavior for a development framework extension with bundled dependencies. Oracle's verified publisher status and 41K+ user adoption further support the benign nature of this extension.
Key Reasons
- Verified Oracle publisher with 41,117 users
- Network findings from bundled dependencies, not extension code
- No credential access or malware signatures detected
- Code-smell findings are documented YARA noise patterns
- Filesystem access justified by SuiteCloud development framework purpose
False Positive Considerations
- Bundled dependencies (rxjs, xml2js) triggering network findings
- Code-smell YARA rules firing on minified JavaScript
- Webview fetch calls for feedback form functionality
- Oracle verified publisher with 41K+ users
Reviewed 2026-05-23; recommended action: suppress false positive; model confidence 85%.
VS Code version history
Risk trend by version
3 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
Oracle Developer Tools for VS Code (SQL and PLSQL)
Oracle Corporation
OCI Functions
Oracle Corporation
OCI Resource Manager
Oracle Corporation
Oracle Integration Cloud Rapid Adapter Builder
Oracle Corporation
OCI Toolkit for VS Code
Oracle Corporation
Oracle SQL Developer for VSCode
Oracle Corporation