VS Code Marketplace

qsp-ext

by QSPFoundation · 51 downloads
4d6de833-f379-51db-b3b8-a0b7676e8f9c | v0.1.2
0/ 100
MINIMAL risk
Analyst verdict
No high-risk signal observed

Based on the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
10 months ago
Version
v0.1.2
Artifact
SHA256 236…35C
Source
Findings (non-IoC)

No Findings

All security checks passed

Publisher Evidence

Limited evidence

QSPFoundation

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

24
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Not exposed
Not exposed
Extension portfolio
Unknown
Portfolio

10 evidence rows available.

No Threats Detected

This extension passed all security checks

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

Security Analysis: qsp-ext (QSP Language Support)

Filesystem and Process Access Justification

The extension is described as "QSP Language Support" for VS Code. Language support extensions legitimately require file read access to parse and provide syntax highlighting for the target language. No findings in the evidence bundle indicate filesystem access beyond what is expected for a language extension. There are no postinstall_* YARA findings, no credential_* findings, and no code-smell findings related to arbitrary process execution or shell command spawning. The 31 code-smell findings mentioned in the summary are classified as low-severity and match expected patterns for non-trivial JavaScript code.

Credential Access Findings

The findings bundle contains zero secret or credential findings. The findings_summary shows "secret":"0" and there are no findings in the evidence targeting .env, .git/config, SSH keys, or VS Code secret storage. None of the 615 IOC findings reference actual credential files or sensitive configuration paths. All credential-related YARA rules would appear in the code-smell category, which contains only 31 low-severity findings typical of legitimate codebases.

IOC Finding Analysis

All 615 IOC findings are XIOC extractor false positives, following documented garbage patterns:

  • File extensions misread as domains: XIOC-DOMAIN-changelog.md, XIOC-DOMAIN-readme.md, XIOC-DOMAIN-license.md, XIOC-DOMAIN-8.gl, XIOC-DOMAIN-myapplication.app
  • Property chains misread as domains: XIOC-DOMAIN-microsoft.visualstudio.services.links.support, XIOC-DOMAIN-ksystem.int
  • Legitimate URLs: XIOC-URL-https://stackoverflow.com/a/13653180/3922220, XIOC-URL-https://github.com/nodejs/node/issues/7657, XIOC-URL-https://gist.github.com/LeverOne/1308368, XIOC-DOMAIN-www.w3.org

These are all documented XIOC false positive patterns. None represent actual network destinations or malicious infrastructure.

Strongest Counterargument

The strongest counterargument is the 0 user count combined with 35 high-severity findings and 4 malware signatures without context. An extension with no downloads could indicate a newly published malicious tool or a supply chain attack vector. However, the malware signature findings lack detail about what they match, and the high-severity findings are not enumerated in the evidence. Without specific evidence of postinstall payload execution, credential theft, or data exfiltration, the 615 IOC findings being exclusively XIOC artifacts dominates the assessment. The zero user count alone does not establish malicious intent.

Conclusion

The findings are consistent with a legitimate language support extension that has not gained traction. The overwhelming volume of findings comes from XIOC extraction artifacts, not actual malicious behavior. Suppressing these false positives would reduce the finding count from 650 to approximately 35 (the high-severity findings requiring context).

Key Reasons

  • All 615 IOC findings are XIOC false positives (file extensions, property chains, legitimate URLs)
  • Zero secret/credential findings in the evidence bundle
  • No postinstall payload execution or arbitrary command execution findings
  • 31 code-smell findings are low-severity and expected for non-trivial JavaScript
  • Extension purpose (language support) justifies file read access

False Positive Considerations

  • XIOC file extension misread as domain (changelog.md, readme.md, license.md, 8.gl, myapplication.app)
  • XIOC property chain misread as domain (microsoft.visualstudio.services.links.support, ksystem.int)
  • XIOC legitimate URLs flagged as IoC (stackoverflow.com, github.com, w3.org)
  • Code-smell findings from standard JavaScript patterns

Reviewed 2026-04-29; recommended action: suppress false positive; model confidence 75%.

About This Extension

QSP Language Support

Frequently Asked Questions