qsp-ext
Based on the RiskyPlugins AI security review of the observed evidence.
Analysis record
- Analysed
- 10 months ago
- Version
- v0.1.2
- Artifact
- SHA256 236…35C
- Source
- Findings (non-IoC)
No Findings
All security checks passed
Publisher Evidence
Limited evidenceQSPFoundation
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
10 evidence rows available.
No Threats Detected
This extension passed all security checks
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality moderate.
Security Analysis: qsp-ext (QSP Language Support)
Filesystem and Process Access Justification
The extension is described as "QSP Language Support" for VS Code. Language support extensions legitimately require file read access to parse and provide syntax highlighting for the target language. No findings in the evidence bundle indicate filesystem access beyond what is expected for a language extension. There are no postinstall_* YARA findings, no credential_* findings, and no code-smell findings related to arbitrary process execution or shell command spawning. The 31 code-smell findings mentioned in the summary are classified as low-severity and match expected patterns for non-trivial JavaScript code.
Credential Access Findings
The findings bundle contains zero secret or credential findings. The findings_summary shows "secret":"0" and there are no findings in the evidence targeting .env, .git/config, SSH keys, or VS Code secret storage. None of the 615 IOC findings reference actual credential files or sensitive configuration paths. All credential-related YARA rules would appear in the code-smell category, which contains only 31 low-severity findings typical of legitimate codebases.
IOC Finding Analysis
All 615 IOC findings are XIOC extractor false positives, following documented garbage patterns:
- File extensions misread as domains:
XIOC-DOMAIN-changelog.md,XIOC-DOMAIN-readme.md,XIOC-DOMAIN-license.md,XIOC-DOMAIN-8.gl,XIOC-DOMAIN-myapplication.app - Property chains misread as domains:
XIOC-DOMAIN-microsoft.visualstudio.services.links.support,XIOC-DOMAIN-ksystem.int - Legitimate URLs:
XIOC-URL-https://stackoverflow.com/a/13653180/3922220,XIOC-URL-https://github.com/nodejs/node/issues/7657,XIOC-URL-https://gist.github.com/LeverOne/1308368,XIOC-DOMAIN-www.w3.org
These are all documented XIOC false positive patterns. None represent actual network destinations or malicious infrastructure.
Strongest Counterargument
The strongest counterargument is the 0 user count combined with 35 high-severity findings and 4 malware signatures without context. An extension with no downloads could indicate a newly published malicious tool or a supply chain attack vector. However, the malware signature findings lack detail about what they match, and the high-severity findings are not enumerated in the evidence. Without specific evidence of postinstall payload execution, credential theft, or data exfiltration, the 615 IOC findings being exclusively XIOC artifacts dominates the assessment. The zero user count alone does not establish malicious intent.
Conclusion
The findings are consistent with a legitimate language support extension that has not gained traction. The overwhelming volume of findings comes from XIOC extraction artifacts, not actual malicious behavior. Suppressing these false positives would reduce the finding count from 650 to approximately 35 (the high-severity findings requiring context).
Key Reasons
- All 615 IOC findings are XIOC false positives (file extensions, property chains, legitimate URLs)
- Zero secret/credential findings in the evidence bundle
- No postinstall payload execution or arbitrary command execution findings
- 31 code-smell findings are low-severity and expected for non-trivial JavaScript
- Extension purpose (language support) justifies file read access
False Positive Considerations
- XIOC file extension misread as domain (changelog.md, readme.md, license.md, 8.gl, myapplication.app)
- XIOC property chain misread as domain (microsoft.visualstudio.services.links.support, ksystem.int)
- XIOC legitimate URLs flagged as IoC (stackoverflow.com, github.com, w3.org)
- Code-smell findings from standard JavaScript patterns
Reviewed 2026-04-29; recommended action: suppress false positive; model confidence 75%.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace