VS Code Marketplace Verified

GitHub Copilot Chat

by GitHub · 78.5M users · 2.8 rating
34534391-49b9-5e60-b377-eed3022c1100 | v0.48.1
70/ 100
HIGH risk
+18 since v0.45.1
Analyst verdict
Benign but powerful

From the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
2 weeks ago
Version
v0.48.1
Artifact
SHA256 785…1D6
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

50 detail rows
Showing 25 of 50 · highest severity first

Publisher Evidence

Low

GitHub

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

90
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Verified publisher
Verified
Extension portfolio
232
Portfolio

13 evidence rows available.

Finding Categories

5
Network

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

The GitHub Copilot Chat extension, developed by GitHub, provides AI chat features powered by Copilot. The extension has a large user base of 73,593,772 users. Upon reviewing the findings, it is evident that the extension has dependencies such as web-tree-sitter, @opentelemetry/exporter-metrics-otlp-http, @opentelemetry/api, @google/genai, minimatch, best-effort-json-parser, and vscode-tas-client. These dependencies are listed in the package.json file and are likely used for the extension's functionality. The network findings indicate that the extension makes fetch and socket_io network calls, which could be used for communicating with the Copilot service or for updating the extension. However, there are no malware signatures or IoC matches, and no credential-access findings target actual secrets. The strongest counterargument to the verdict is that the extension's network calls could potentially be used for malicious purposes. However, given the extension's purpose and the fact that it is developed by a trusted publisher, it is likely that these network calls are legitimate. The filesystem/process access is justified by the extension's stated purpose, as it needs to read and write files for its chat features. In conclusion, based on the findings, it appears that the extension is a legitimate development tool with broad access, but its intentions are benign.

Key Reasons

  • No malware signatures or IoC matches
  • No credential-access findings target actual secrets
  • Network calls are likely used for legitimate purposes

Reviewed 2026-05-23; recommended action: no action; model confidence 90%.

VS Code version history

Risk trend by version

17 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
70
Change since first
+20
Change from previous
+18
Versions:
First analyzed version
0.37.2026012303
Jan 23, 2026
Risk range
45 to 70
Across analyzed versions
Latest analyzed version
0.48.1
May 17, 2026
Selected version
high
Version
v0.48.1
4 months ago
Risk score
70
Findings
50
Change vs previous
+18

Pick any point on the chart to explore that version's code below.

About This Extension

AI chat features powered by Copilot

Frequently Asked Questions