OpenVSX Registry Verified

Google Cloud Data Agent Kit

432746b4-3162-5578-bf26-b28283ff9f3e | v0.11.0
86/ 100
CRITICAL risk
+21 since v0.5.2
Analyst verdict
Do not install

The AI review rates the findings as likely false positive, but the risk score (86/100) still counts them.

Analysis record

Analysed
2 weeks ago
Version
v0.11.0
Artifact
SHA256 F88…65E
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

448 detail rows
Showing 25 of 31 · highest severity first

YARA Rule Matches

22 rules
SeverityRuleHitsFilesMetadata
LOWcredential env files 23
antigravity/skills/building-data-apps/examples/fastapi_chat.pyantigravity/skills/gcp-managed-airflow-recommendations/scripts/workload_cpu_usage.pyantigravity/skills/gcp-managed-airflow-recommendations/scripts/workload_memory_usage.py +20 more
-
LOWpostinstall persistence mechanism 13
antigravity/skills/google-cloud-storage-basics/references/gcsfuse.mdantigravity/skills/gcp-managed-airflow-migrations/SKILL.mdantigravity/skills/gcp-composer-troubleshooting/SKILL.md +10 more
-
LOWCreatingCookiesWithoutTheHttpOnlyFlag 1
datacloud_vscode.js
-
LOWNoDisableSanitizeHtml 1
datacloud_vscode.js
-
LOWDebuggerStatementsShouldNotBeUsed 3
dataproc/notebook_renderers/sparkmonitor_renderer.jswebview/app_bundle.jsdatacloud_vscode.js
-
LOWUsingCommandLineArguments 1
mcp_servers/cli/mcp_proxy_bundle.js
-
LOWpostinstall file download 50
antigravity/skills/google-cloud-storage-fuse/references/performance-diagnosis.mdantigravity/skills/gcs-security-assessment/scripts/preflight_permissions.pyantigravity/skills/google-cloud-storage-basics/references/mcp-usage.md +47 more
-
LOWHavingAPermissiveCrossOriginResourceSharingPolicy 1
antigravity/skills/building-data-apps/examples/express_chat.ts
-
LOWcredential gcp credentials 3
mcp_servers/cli/mcp_proxy_bundle.jsdatacloud_vscode.jsantigravity/skills/google-cloud-storage-basics/references/mcp-usage.md
-
LOWNoUseEval 3
datacloud_vscode.jssql_editor/exthost/bigquery/server_bin.cjsdataproc/notebook_renderers/sparkmonitor_renderer.js
-
LOWSQLInjection 3
dataproc/notebook_renderers/sparkmonitor_renderer.jsdatacloud_vscode.jswebview/app_bundle.js
-
LOWNoUseWeakRandom 4
dataproc/notebook_renderers/sparkmonitor_renderer.jssql_editor/exthost/bigquery/server_bin.cjsdatacloud_vscode.js +1 more
-
LOWpostinstall network communication 55
antigravity/skills/google-cloud-storage-basics/references/cli-api-usage.mdantigravity/skills/gcp-pipeline-orchestration/references/orchestration-pipelines-schema.mdantigravity/skills/gcp-spark/SKILL.md +52 more
-
LOWpostinstall system command 97
antigravity/skills/dataform-bigquery/SKILL.mdantigravity/skills/gcp-dataflow/references/streaming_job_health.mdantigravity/skills/schema-mapping/SKILL.md +94 more
-
LOWUsingShellInterpreterWhenExecutingOSCommands 3
sql_editor/exthost/bigquery/server_bin.cjsdist/agents/hooks/telemetry_hook.jsdatacloud_vscode.js
-
LOWpostinstall crypto operations 36
antigravity/skills/google-cloud-storage-bucket-architect/references/log_storage.mdantigravity/skills/google-cloud-storage-bucket-architect/references/sensitive_data.mdantigravity/skills/gcs-security-assessment/references/bucket_classification.md +33 more
-
LOWCreatingCookiesWithoutTheSecureFlag 1
datacloud_vscode.js
-
LOWpostinstall file manipulation 63
antigravity/skills/gcs-security-assessment/references/toxic_combinations.mdantigravity/skills/google-cloud-storage-bucket-architect/references/backup_dr.mdCHANGELOG.md +60 more
-
LOWpostinstall obfuscation 45
antigravity/skills/ml-best-practices/SKILL.mdantigravity/skills/gcs-security-assessment/references/phases/classification.mdantigravity/skills/schema-mapping/SKILL.md +42 more
-
LOWpostinstall registry modification 8
datacloud_vscode.jssql_editor/exthost/bigquery/server_bin.cjswebview/app_bundle.js +5 more
-
LOWNoUseSocketManually 1
datacloud_vscode.js
-
LOWpostinstall environment access 2
bigquery/resources/declarative_pipelines_serverless_template.ymlbigquery/resources/declarative_pipelines_clustered_template.yml
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

10,243 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Publisher Evidence

Low

googlecloudtools

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

50
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Verified publisher
Verified
Extension portfolio
1
Portfolio

13 evidence rows available.

Finding Categories

7
Obfuscation
15
Network
10,243
IoC Indicators

YARA Rules Matched

22 rules(417 hits)
credential env files postinstall persistence mechanism CreatingCookiesWithoutTheHttpOnlyFlag NoDisableSanitizeHtml DebuggerStatementsShouldNotBeUsed UsingCommandLineArguments postinstall file download HavingAPermissiveCrossOriginResourceSharingPolicy credential gcp credentials NoUseEval SQLInjection NoUseWeakRandom postinstall network communication postinstall system command UsingShellInterpreterWhenExecutingOSCommands postinstall crypto operations +6 more

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality weak.

The Google Cloud Data Agent Kit extension presents a security profile with no detected threats across all analyzed categories. The findings_by_category bucket is completely empty, indicating no IoC matches, no YARA code-smell detections, and no credential or exfiltration patterns were identified in the codebase.

Filesystem and Process Access Justification

No filesystem or process access findings were detected in this analysis. For a Google Cloud integration extension, legitimate operations would typically include reading configuration files, executing cloud CLI commands, and accessing workspace files for data processing. The absence of detected process spawning or file access patterns suggests either the extension uses standard VS Code APIs that do not trigger security rules, or the analysis coverage was limited. A typical Google Cloud IDE extension would legitimately need to read .json configuration files, execute gcloud commands, and access workspace files for data agent functionality. Without findings in the findings_by_category bucket, no specific process execution or filesystem access patterns were flagged.

Credential Access Analysis

No credential-access findings were detected. This is notable because Google Cloud integrations typically need to access authentication tokens, service account keys, or environment variables for cloud connectivity. The absence of credential-related YARA matches could indicate the extension uses VS Code's built-in credential management APIs, authentication is handled through OAuth flows without direct credential file access, or the extension is incomplete in its current 0.1.0 version. No findings in the credential category suggest no direct access to .env files, .git/config, SSH keys, or cloud credentials was detected.

Strongest Counterargument

The primary concern is this extension's publication profile: version 0.1.0 with zero users on OpenVSX. New extensions with no user base represent elevated supply chain risk, as attackers can publish malicious extensions before detection. However, without actual security findings (no postinstall payloads, no credential theft patterns, no exfiltration code), there is no evidence of malicious intent. The publisher name "googlecloudtools" suggests legitimate Google Cloud affiliation, though this should be verified against official Google Cloud marketplace listings.

Evidence Quality Assessment

The evidence quality is weak due to the completely empty findings bucket. A comprehensive IDE extension analysis typically produces at least some code-smell findings from bundled dependencies, IoC matches from CDN/npm domains, or obfuscation detections from minified JavaScript. The absence of any findings suggests either an exceptionally clean codebase or incomplete analysis coverage. Given no findings to cite from the findings_by_category bucket, the analysis cannot identify specific security concerns.

Recommendation

Monitor this extension for updates and user adoption. The lack of security findings is positive, but the new publication date and zero user count warrant observation before widespread adoption.

Key Reasons

  • No security findings in findings_by_category bucket
  • Publisher name suggests legitimate Google Cloud affiliation
  • Zero findings across all security categories
  • New extension requires monitoring despite clean profile

False Positive Considerations

  • empty_findings_bucket
  • new_extension_zero_users
  • analysis_coverage_uncertainty

Reviewed 2026-04-22; recommended action: monitor; model confidence 75%.

Open VSX version history

Risk trend by version

7 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
86
Change since first
+21
Change from previous
+21
Versions:
First analyzed version
0.1.0
Apr 21, 2026
Risk range
65 to 86
Across analyzed versions
Latest analyzed version
0.11.0
Sep 12, 2026
Selected version
critical
Version
v0.11.0
2 weeks ago
Risk score
86
Findings
10702
Change vs previous
+21

Pick any point on the chart to explore that version's code below.

About This Extension

Bring the full power of Google Cloud Data Agent Kit (starter pack) to your intelligent IDE

Frequently Asked Questions