KIDE Solution Explorer
The AI review rates the findings as likely false positive, but the risk score (50/100) still counts them.
Analysis record
- Analysed
- 4 months ago
- Version
- v9.2.2
- Artifact
- SHA256 18F…88F
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
Publisher Evidence
Limited evidencekide
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
12 evidence rows available.
Finding Categories
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality strong.
The extension declares itself as a solution‑explorer for Visual Studio Code, which legitimately needs to read *.sln, *.slnx and *.slnf files to present project hierarchies. The only observable filesystem accesses are reads of those solution files, matching the purpose of the tool. No findings reference write‑access or execution of arbitrary binaries. The sole process‑related indicator is the generic IoC entry "XIOC-DOMAIN-this.commands.run" (file path extracted_from_files), which merely reflects a method name used internally for command handling – a normal pattern for VS Code extensions and not an unsanctioned child‑process spawn.
Credential‑related findings are absent. The bundle reports zero entries under the secret category and no IoC titles referencing typical secret locations such as .env, .ssh, or cloud credential files. Consequently, the extension does not attempt to read or transmit real secrets.
The most prominent signal is a large set of IoC detections (e.g., "XIOC-DOMAIN-propertygroups.map", "XIOC-DOMAIN-o.data", "XIOC-DOMAIN-t.directory", "XIOC-DOMAIN-e.constructor.name", "XIOC-DOMAIN-this.productions", "XIOC-DOMAIN-this.save", "XIOC-DOMAIN-u.show", "XIOC-DOMAIN-f.next"), all extracted from generic JavaScript property chains inside bundled source files. These entries are classic false positives of the XIOC extractor, which treats ordinary object property access as “domains”. None of them correspond to real network destinations or malicious commands.
A potential counterargument could be that the volume of medium‑severity IoC findings implies concealed network activity. However, each IoC title maps to internal function or property names rather than DNS or IP strings, and the extractor’s own documentation classifies such patterns as noise. Moreover, the extension’s manifest does not request elevated permissions beyond workspace read access, and no network‑related findings were reported. Therefore, the IoC volume does not constitute evidence of exfiltration or command‑and‑control behavior.
In summary, the extension’s file and process interactions are consistent with its advertised functionality, there is no evidence of credential harvesting, and the IoC detections stem from known extractor noise. The overall assessment is that the findings represent false positives rather than malicious intent.
Key Reasons
- Only read‑only access to solution files, matching extension purpose
- No credential‑related findings detected
- IoC entries are generic property names, typical extractor noise
- No process‑execution or network calls observed
False Positive Considerations
- IoC extractor garbage
- Bundled dependency noise
- Generic property‑name detections
Reviewed 2026-05-25; recommended action: no action; model confidence 92%.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace