Firebase SQL Connect
The AI review rates the findings as likely false positive, but the risk score (44/100) still counts them.
Analysis record
- Analysed
- 2 weeks ago
- Version
- v2.4.3
- Artifact
- SHA256 3D3…42D
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
Publisher Evidence
Lowgooglecloudtools
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
12 evidence rows available.
Finding Categories
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality strong.
Filesystem and Process Access Justification
This extension, published by googlecloudtools on OpenVSX with over 426,000 users, shows no evidence of problematic filesystem or process access. The 13 dependency findings are all standard npm packages required for VS Code extension development. For example, DEP-vscode-languageclient-8.1.0 is the official VS Code language client library needed for any language service extension. Dependencies like DEP-react-dom-^18.2.0 and DEP-@vscode/webview-ui-toolkit-^1.2.1 are standard for building the extension's user interface. The DEP-graphql-language-service-server-file:graphql-language-service-server-2.14.8.tgz and DEP-graphql-language-service-file:graphql-language-service-5.4.0.tgz packages are expected for an extension providing GraphQL language features.
Credential Access Findings
There are zero credential or secret access findings in this extension. The findings summary shows "secret":"0" with no matches for credential theft patterns. The extension does not reference .env files, SSH keys, cloud credentials, or VS Code secret storage. This is a strong positive signal for a Firebase-related extension, which would legitimately need to access Firebase credentials through official authentication flows rather than scanning for secrets.
Network Activity
The single network finding NET-AXIOS-extension/dist/templates/extensions/javascript/integration-test.js-1 detects an axios call in an integration test file. This is not production code but test infrastructure. Integration tests commonly use HTTP clients like axios to verify API connectivity. The finding is classified as medium severity by the scanner, but the file path clearly indicates this is test code, not runtime behavior. There are no other network findings, and zero IoC (indicator of compromise) matches.
Strongest Counterargument
The strongest argument against this verdict would be the medium-severity network finding. However, this does not change the conclusion because: (1) the file path extension/dist/templates/extensions/javascript/integration-test.js explicitly identifies this as test code, (2) there are no corresponding production code network calls, (3) the extension has zero malware signatures, zero obfuscation findings, and zero credential access findings, and (4) the publisher is googlecloudtools, Google's official cloud tools organization with 426,000+ users. The finding count of 14 is entirely composed of 13 dependency findings and 1 test file network call—this is expected noise for any VS Code extension.
Conclusion
This is a legitimate Google-published extension with normal VS Code extension patterns. All findings are explainable as standard dependencies and test infrastructure. No malicious behavior indicators are present.
Key Reasons
- Official googlecloudtools publisher with 426,000+ users
- Zero malware signatures and zero IoC matches
- All 13 dependency findings are standard VS Code extension packages
- Single network finding is in integration test file, not production code
- Zero credential or secret access findings
False Positive Considerations
- Dependency findings are standard npm packages, not malicious code
- Network finding is in integration test file, not production code
- Zero malware signatures, zero IoCs, zero credential findings
- Official Google publisher with 426,000+ users
Reviewed 2026-05-23; recommended action: no action; model confidence 95%.
Open VSX version history
Risk trend by version
8 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
datacloud
googlecloudtools
Google Cloud Data Agent Kit
Google Cloud
workbench-notebooks
googlecloudtools
Workbench Notebooks
Google Cloud
Firebase SQL Connect
Google Cloud
cloudcode
googlecloudtools