OpenVSX Registry Verified

Claude Code for VS Code

18dcd624-61be-550a-b1b4-4a3d83ff877b | v2.1.283
44/ 100
MEDIUM risk
-28 since v2.1.269
71 → 44 · false positives removed
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (44/100) still counts them.

Analysis record

Analysed
1 weeks ago
Version
v2.1.89
Artifact
SHA256 F46…50C
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

2 detail rows

Publisher Evidence

Low

Anthropic

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

50
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Verified publisher
Verified
Extension portfolio
1
Portfolio

13 evidence rows available.

Finding Categories

2
Network

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

Claude Code for VS Code is published by Anthropic, the well-known AI company behind the Claude language model. With over 17 million users, this is one of the most widely adopted VS Code extensions in existence. The extension's stated purpose is to integrate Claude Code functionality into the VS Code IDE, enabling developers to use AI-assisted coding without leaving their development environment.

The filesystem and process access findings are absent from this analysis. The only detection is a single network finding: NET-FETCH-extension/resources/claude-code/cli.js-53 showing a fetch call at line 53 of cli.js. This is expected and necessary behavior for an AI assistant extension that must communicate with Anthropic's Claude Code service to process user requests and return AI-generated code suggestions. A fetch call in a CLI module for an AI integration is the core functionality, not suspicious activity.

Credential access findings are completely absent. The findings summary shows "secret":"0", meaning no credential-related detections were found. There are no findings targeting .env files, .git/config, SSH keys, or VS Code's secret storage. The extension does not request or access any credentials beyond what would be necessary for authenticating with Anthropic's own services, which is standard for AI assistant integrations.

The strongest counterargument to this verdict would be that any network call from an IDE extension could potentially exfiltrate data. However, this argument fails because: (1) Anthropic is a verified publisher with established trust in the developer community, (2) the fetch call is located in cli.js within the resources/claude-code/ directory, indicating it is part of the official Claude Code client integration, (3) there are zero malware signatures, zero IoC hits, zero obfuscation findings, and zero code-smell detections in the entire analysis, and (4) the extension has 17+ million users with no reported security incidents. The network finding represents the extension doing exactly what it is designed to do: communicate with the Claude Code service.

All other finding categories show zero detections: no malware signatures, no obfuscation, no supply chain indicators, no tool poisoning, and no suspicious dependencies. The evidence quality is strong because the findings are minimal, specific, and consistent with the extension's documented purpose. This is a benign extension flagged only for performing its intended network communication.

Key Reasons

  • Single network fetch call in cli.js is expected behavior for AI assistant extension
  • Zero malware signatures, IoC hits, or credential access findings
  • Published by Anthropic, a verified and well-known AI company
  • 17+ million users indicate widespread legitimate adoption
  • No obfuscation, code-smell, or dependency findings detected

False Positive Considerations

  • Network fetch calls flagged as findings despite being core functionality
  • AI assistant extensions require network communication to function

Reviewed 2026-05-23; recommended action: suppress false positive; model confidence 95%.

Open VSX version history

Risk trend by version

4 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
44
Change since first
+12
Change from previous
-28
Versions:
First analyzed version
2.1.84
Mar 26, 2026
Risk range
31 to 71
Across analyzed versions
Latest analyzed version
2.1.89
Sep 19, 2026
Selected version
medium
Version
v2.1.89
1 weeks ago
Risk score
44
Findings
2
Change vs previous
-28

Pick any point on the chart to explore that version's code below.

About This Extension

Claude Code for VS Code: Harness the power of Claude Code without leaving your IDE

Frequently Asked Questions