IBM Functional Testing
The AI review rates the findings as likely false positive, but the risk score (65/100) still counts them.
Analysis record
- Analysed
- 3 days ago
- Version
- v3.0.1
- Artifact
- SHA256 466…788
- Source
- Findings (non-IoC)
Is IBM Functional Testing safe?
ibm-functionaltest generates Galasa functional tests inside your editor. IBM publishes it on OpenVSX to a small audience of around 34 users. The extension declares no editor permissions and no host permissions, so it does not ask for broad access to your workspace, though as a test generator it writes Java test files into your project. The one real network destination in the package is api.dataplatform.cloud.ibm.com, IBM's Cloud Pak for Data API, which is where a Galasa test run would send its results.
Eleven critical alerts all carry the same title, OBFUSCATION-NATIVE_BINARY_ADDON, and they point at files such as extension/prebuilds/keyring.darwin-arm64.node and its Linux and Windows counterparts. Those are compiled machine code from the keyring npm package, which stores a token in macOS Keychain, Windows Credential Manager or libsecret instead of a plaintext file. A scanner cannot pull readable strings out of compiled code, so the rule flags the file format rather than any hidden trick.
The rest of the alert volume is scanner noise. Endpoints like al.bo, ae.es, at.ch and csslineclass.info are fragments of minified JavaScript and Java test templates read as if they were web addresses. A large block of matches comes from bundled third party libraries, which is what shipped build output looks like.
Nothing in this package reads .env files, .git/config or SSH keys, and no malware signatures matched. The scrutiny of native binaries is fair, since they cannot be audited the way JavaScript can, but the files here are the platform builds of a keychain library named in their own paths.
No Findings
All security checks passed
Publisher Evidence
LowIBM
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
13 evidence rows available.
No Threats Detected
This extension passed all security checks
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality moderate.
ibm-functionaltest is IBM's generator for Galasa functional tests, published on OpenVSX to about 34 users. Every finding that carries critical severity is one rule: OBFUSCATION-NATIVE_BINARY_ADDON, applied eleven times to extension/prebuilds/keyring.darwin-arm64.node, keyring.darwin-x64.node, keyring.linux-x64-gnu.node, keyring.win32-x64-msvc.node and the other platform variants. Those are compiled prebuilt binaries shipped by the keyring npm module, which talks to the operating system credential store so the user does not need a compiler to install the extension. A .node file is machine code. The rule fires because string extraction fails on compiled code, which is the normal state of any native addon.
Filesystem and process access lines up with the stated job. The package declares no editor permissions and no host permissions, and nothing lands in the network, manifest-analysis or secret categories. A test generator writes Java files into the workspace and runs Gradle or Maven against them, and the evidence shows nothing wider than that.
The credential question deserves attention because keyring wraps the OS keychain, and a keychain wrapper is what a credential stealer would ship. Nothing here reads .env files, .git/config or SSH keys: the secret category is empty and no finding names those paths. The prebuilds are the library for putting an IBM Cloud API token in macOS Keychain, Windows Credential Manager or libsecret instead of a plaintext file.
The network endpoint list is mostly extractor noise. Entries like al.bo, ae.es, at.ch, 0ny.sa, csslineclass.info and data.rel.ro are substrings pulled out of minified JavaScript and Java test templates rather than real hosts. The one genuine destination is api.dataplatform.cloud.ibm.com, IBM's Cloud Pak for Data API, where a Galasa test run reports its results.
The strongest counterargument is that static analysis cannot read a native addon, so an unaudited binary in the package is a real blind spot, and keyring prebuilds are exactly the artifact a malicious extension would hide behind. That argument is sound about method and empty about evidence: across 467 findings there are zero malware signatures, zero reads of developer secrets, and no endpoint other than IBM's own API. The eleven critical labels describe the file format, not the behavior inside it.
Bundled dependency code accounts for the remaining volume. The 103 code-smell matches and 11 dependency findings sit in shipped libraries and template files, and those rules match ordinary JavaScript idioms in build output.
Key Reasons
- All 11 critical findings are OBFUSCATION-NATIVE_BINARY_ADDON on extension/prebuilds/keyring.*.node, which detects compiled machine code rather than hidden behavior
- No malware signatures, no secret-category findings, and no path-based findings for .env, .git/config or SSH keys
- The only real endpoint in the list is api.dataplatform.cloud.ibm.com, IBM's own Cloud Pak for Data API, consistent with Galasa test reporting
- Network endpoint entries such as al.bo, ae.es, at.ch and csslineclass.info are substrings of minified JS and Java templates, not contacts
- The extension is published by IBM on OpenVSX with a stated purpose that matches the file writes and process execution present
False Positive Considerations
- OBFUSCATION-NATIVE_BINARY_ADDON fires on compiled .node prebuilds in extension/prebuilds/ that cannot be string-scanned
- IoC extractor reads substrings of minified JavaScript and Java test templates as domains (al.bo, at.ch, csslineclass.info)
- 103 code-smell matches on bundled dependency JavaScript and templates
- 342 IoC entries dominated by hex fragments and CDN/infra noise rather than real destinations
Reviewed 2026-09-30; recommended action: suppress false positive; model confidence 85%.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace