Python Debugger (PyDev)
Based on the RiskyPlugins AI security review of the observed evidence.
Analysis record
- Analysed
- 10 months ago
- Version
- v0.3.0
- Artifact
- SHA256 C56…AB7
- Source
- Findings (non-IoC)
No Findings
All security checks passed
Publisher Evidence
Limited evidenceFabio Zadrozny
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
13 evidence rows available.
No Threats Detected
This extension passed all security checks
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality moderate.
Purpose Justification
This Python Debugger extension (PyDev) requires filesystem and process access to perform its core function: attaching to and debugging Python processes. The dependency list in /tmp/extract-c56ece48f0aa6e7f25d09506d54e798c261c0af1fc7a3b692c138da00005dab7-3732251710/extension/package.json includes vscode-languageclient (standard for VS Code language server extensions), tmp (temporary file handling for debug sessions), and http-proxy-agent/https-proxy-agent (remote debugging support). These are legitimate dependencies for a debugger that must spawn Python processes, read source files for breakpoints, and communicate with running code.
Credential Access Assessment
The YARA--credential_env_files finding appears in the malware-signature category, but the findings_summary shows "secret":"0" in the by_category breakdown. This indicates the credential finding is a code-smell rule matching generic environment variable patterns, not actual credential theft. Debuggers legitimately read environment variables to configure debug sessions. There are no findings targeting .env, .git/config, SSH keys, or cloud credentials specifically. The extension's stated purpose as a Python debugger justifies any environment variable access.
False Positive Drivers
The overwhelming evidence points to false positives: 780 of 789 total findings are code-smell severity, which the CVEQ platform documents as noise that should never drive verdicts. The YARA--postinstall_file_download and YARA--postinstall_file_manipulation findings both show file_path: unknown_file, suggesting extraction artifacts rather than actual malicious payloads. The threat_indicators field explicitly shows "malware-signature":"0", "ioc":"0", and "malware":"0" — no confirmed threats. The extension has 80,512 users, indicating established market presence inconsistent with supply chain attacks.
Strongest Counterargument
A security-conscious reviewer might argue that 780 high-severity findings warrant caution. However, severity labels in CVEQ are inflated by code-smell rules that match basic Node.js patterns like fetch, exec, and process.env — all legitimate for debuggers. The actual threat indicators (malware signatures, IoCs, obfuscation) all show zero matches. The high-severity count is an artifact of the scoring system's known bias toward code-smell volume, not actual malicious behavior. This extension's capabilities align precisely with its stated debugging purpose, and the findings represent expected IDE extension patterns rather than malicious intent.
Key Reasons
- 780 of 789 findings are code-smell noise, not actual threats
- threat_indicators shows zero malware-signatures, IoCs, and malware matches
- Extension dependencies are legitimate for Python debugging functionality
- 80,512 user count indicates established market presence
- Malware-signature findings reference unknown_file paths, suggesting extraction artifacts
False Positive Considerations
- Code-smell YARA rules matching basic Node.js patterns
- Severity inflation from code-smell volume
- Malware-signature findings with unknown_file paths
- Standard debugger dependencies triggering noise
Reviewed 2026-05-23; recommended action: suppress false positive; model confidence 85%.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
Python (PyDev)
Fabio Zadrozny
Profile Python with PyVmMonitor
Fabio Zadrozny
Eclipse/PyDev Windows Keymap
Fabio Zadrozny
Nakka - AI code agent
Nakka
Erilang
eritten kwame gyau
BOO UI编辑器
boo-best