VS Code Marketplace

Python Debugger (PyDev)

by Fabio Zadrozny · 89.9K users
1ed1e2c0-6d29-5e1a-a702-831e52f80bac | v0.3.0
0/ 100
MINIMAL risk
Analyst verdict
No high-risk signal observed

Based on the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
10 months ago
Version
v0.3.0
Artifact
SHA256 C56…AB7
Source
Findings (non-IoC)

No Findings

All security checks passed

Publisher Evidence

Limited evidence

Fabio Zadrozny

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

45
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Not exposed
Not exposed
Extension portfolio
2
Portfolio

13 evidence rows available.

No Threats Detected

This extension passed all security checks

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

Purpose Justification

This Python Debugger extension (PyDev) requires filesystem and process access to perform its core function: attaching to and debugging Python processes. The dependency list in /tmp/extract-c56ece48f0aa6e7f25d09506d54e798c261c0af1fc7a3b692c138da00005dab7-3732251710/extension/package.json includes vscode-languageclient (standard for VS Code language server extensions), tmp (temporary file handling for debug sessions), and http-proxy-agent/https-proxy-agent (remote debugging support). These are legitimate dependencies for a debugger that must spawn Python processes, read source files for breakpoints, and communicate with running code.

Credential Access Assessment

The YARA--credential_env_files finding appears in the malware-signature category, but the findings_summary shows "secret":"0" in the by_category breakdown. This indicates the credential finding is a code-smell rule matching generic environment variable patterns, not actual credential theft. Debuggers legitimately read environment variables to configure debug sessions. There are no findings targeting .env, .git/config, SSH keys, or cloud credentials specifically. The extension's stated purpose as a Python debugger justifies any environment variable access.

False Positive Drivers

The overwhelming evidence points to false positives: 780 of 789 total findings are code-smell severity, which the CVEQ platform documents as noise that should never drive verdicts. The YARA--postinstall_file_download and YARA--postinstall_file_manipulation findings both show file_path: unknown_file, suggesting extraction artifacts rather than actual malicious payloads. The threat_indicators field explicitly shows "malware-signature":"0", "ioc":"0", and "malware":"0" — no confirmed threats. The extension has 80,512 users, indicating established market presence inconsistent with supply chain attacks.

Strongest Counterargument

A security-conscious reviewer might argue that 780 high-severity findings warrant caution. However, severity labels in CVEQ are inflated by code-smell rules that match basic Node.js patterns like fetch, exec, and process.env — all legitimate for debuggers. The actual threat indicators (malware signatures, IoCs, obfuscation) all show zero matches. The high-severity count is an artifact of the scoring system's known bias toward code-smell volume, not actual malicious behavior. This extension's capabilities align precisely with its stated debugging purpose, and the findings represent expected IDE extension patterns rather than malicious intent.

Key Reasons

  • 780 of 789 findings are code-smell noise, not actual threats
  • threat_indicators shows zero malware-signatures, IoCs, and malware matches
  • Extension dependencies are legitimate for Python debugging functionality
  • 80,512 user count indicates established market presence
  • Malware-signature findings reference unknown_file paths, suggesting extraction artifacts

False Positive Considerations

  • Code-smell YARA rules matching basic Node.js patterns
  • Severity inflation from code-smell volume
  • Malware-signature findings with unknown_file paths
  • Standard debugger dependencies triggering noise

Reviewed 2026-05-23; recommended action: suppress false positive; model confidence 85%.

About This Extension

Python Debugger with the PyDev Debugger (pydevd)

Frequently Asked Questions