VS Code Marketplace

KIDE Solution Explorer

by kide · 329 users
4eac5990-da43-5735-9e9a-00bb87c504ca | v9.2.2
50/ 100
MEDIUM risk
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (50/100) still counts them.

Analysis record

Analysed
4 months ago
Version
v9.2.2
Artifact
SHA256 18F…88F
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

9 detail rows

Publisher Evidence

Limited evidence

kide

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

29
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Not exposed
Not exposed
Extension portfolio
3
Portfolio

12 evidence rows available.

Finding Categories

1
Obfuscation

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

The extension declares itself as a solution‑explorer for Visual Studio Code, which legitimately needs to read *.sln, *.slnx and *.slnf files to present project hierarchies. The only observable filesystem accesses are reads of those solution files, matching the purpose of the tool. No findings reference write‑access or execution of arbitrary binaries. The sole process‑related indicator is the generic IoC entry "XIOC-DOMAIN-this.commands.run" (file path extracted_from_files), which merely reflects a method name used internally for command handling – a normal pattern for VS Code extensions and not an unsanctioned child‑process spawn.

Credential‑related findings are absent. The bundle reports zero entries under the secret category and no IoC titles referencing typical secret locations such as .env, .ssh, or cloud credential files. Consequently, the extension does not attempt to read or transmit real secrets.

The most prominent signal is a large set of IoC detections (e.g., "XIOC-DOMAIN-propertygroups.map", "XIOC-DOMAIN-o.data", "XIOC-DOMAIN-t.directory", "XIOC-DOMAIN-e.constructor.name", "XIOC-DOMAIN-this.productions", "XIOC-DOMAIN-this.save", "XIOC-DOMAIN-u.show", "XIOC-DOMAIN-f.next"), all extracted from generic JavaScript property chains inside bundled source files. These entries are classic false positives of the XIOC extractor, which treats ordinary object property access as “domains”. None of them correspond to real network destinations or malicious commands.

A potential counterargument could be that the volume of medium‑severity IoC findings implies concealed network activity. However, each IoC title maps to internal function or property names rather than DNS or IP strings, and the extractor’s own documentation classifies such patterns as noise. Moreover, the extension’s manifest does not request elevated permissions beyond workspace read access, and no network‑related findings were reported. Therefore, the IoC volume does not constitute evidence of exfiltration or command‑and‑control behavior.

In summary, the extension’s file and process interactions are consistent with its advertised functionality, there is no evidence of credential harvesting, and the IoC detections stem from known extractor noise. The overall assessment is that the findings represent false positives rather than malicious intent.

Key Reasons

  • Only read‑only access to solution files, matching extension purpose
  • No credential‑related findings detected
  • IoC entries are generic property names, typical extractor noise
  • No process‑execution or network calls observed

False Positive Considerations

  • IoC extractor garbage
  • Bundled dependency noise
  • Generic property‑name detections

Reviewed 2026-05-25; recommended action: no action; model confidence 92%.

About This Extension

KIDE Solution Explorer (sln, slnx, slnf) for Visual Studio Code.

Frequently Asked Questions