VS Code Marketplace Verified

ZenStack V3 Language Tools

by ZenStack Modeling Tools · 1.1K users · 5.0 rating
62a856f2-42a9-5028-9bf3-60f3402e3073 | v3.9.2
49/ 100
MEDIUM risk
+3 since v3.8.0
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (49/100) still counts them.

Analysis record

Analysed
1 months ago
Version
v3.9.2
Artifact
SHA256 C4E…325
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

47 detail rows

YARA Rule Matches

15 rules
SeverityRuleHitsFilesMetadata
LOWcredential env files 3
dist/language-server.cjsdist/extension.cjsdist/esm-DsUIqUfc.cjs
-
LOWcredential vscode credentials 1
readme.md
-
LOWpostinstall persistence mechanism 1
dist/language-server.cjs
-
LOWpostinstall crypto operations 4
dist/language-server.cjsres/stdlib.zmodeldist/esm-DsUIqUfc.cjs +1 more
-
LOWpostinstall file manipulation 5
dist/language-server.cjsdist/extension.cjsres/stdlib.zmodel +2 more
-
LOWpostinstall system command 6
dist/extension.cjsdist/language-server.cjsres/zmodel-v3-preview-release-notes.html +3 more
-
LOWpostinstall environment access 2
dist/language-server.cjsdist/extension.cjs
-
LOWpostinstall registry modification 2
dist/language-server.cjsdist/extension.cjs
-
LOWpostinstall obfuscation 3
dist/language-server.cjsdist/extension.cjsdist/esm-DsUIqUfc.cjs
-
LOWpostinstall network communication 3
dist/language-server.cjsdist/extension.cjsdist/esm-DsUIqUfc.cjs
-
LOWUsingShellInterpreterWhenExecutingOSCommands 2
dist/language-server.cjsdist/extension.cjs
-
LOWpostinstall file download 3
dist/language-server.cjsdist/extension.cjsdist/esm-DsUIqUfc.cjs
-
LOWNoUseWeakRandom 2
dist/language-server.cjsdist/extension.cjs
-
LOWDebuggerStatementsShouldNotBeUsed 1
dist/extension.cjs
-
LOWUsingCommandLineArguments 1
dist/extension.cjs
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

63 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Publisher Evidence

Low

ZenStack Modeling Tools

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

72
Noisy-finding weight
x1.00
Publisher domain
zenstack.dev
Observed
Store verification signal
Verified publisher
Verified
Extension portfolio
3
Portfolio

12 evidence rows available.

Finding Categories

63
IoC Indicators

YARA Rules Matched

15 rules(39 hits)
credential env files credential vscode credentials postinstall persistence mechanism postinstall crypto operations postinstall file manipulation postinstall system command postinstall environment access postinstall registry modification postinstall obfuscation postinstall network communication UsingShellInterpreterWhenExecutingOSCommands postinstall file download NoUseWeakRandom DebuggerStatementsShouldNotBeUsed UsingCommandLineArguments

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

Security Analysis: ZenStack V3 Language Tools

Extension Overview

The ZenStack V3 Language Tools extension (version 3.0.14) provides language support for the ZenStack ZModel language in VS Code. Published by developer "zenstack" on the VS Code marketplace, this extension has approximately 562 users according to the evidence bundle. The extension description states it is a "VSCode extension for ZenStack (v3) ZModel language." The extension UUID is 62a856f2-42a9-5028-9bf3-60f3402e3073.

Findings Assessment

The evidence bundle contains zero security findings across all categories. The findings_by_category object is empty, indicating no YARA matches, no IoC detections, no obfuscation patterns, no credential access indicators, and no postinstall payload detections were found during CVEQ analysis. This is distinct from extensions with high finding counts that turn out to be false positives - this extension produced no findings whatsoever.

Filesystem and Process Access

Language tool extensions require filesystem access to read source files and process execution to spawn language servers. The ZenStack extension's stated purpose as a "language tools" extension justifies these capabilities for legitimate operation. However, no specific findings document actual file access or process spawning behavior in this evidence bundle. The empty findings bucket means there is no evidence of either legitimate or suspicious access patterns captured by the security scanner. Extensions that read workspace files for language features typically generate YARA findings for file system operations, but none appear here.

Credential Access Analysis

No credential-access findings exist in this bundle. The empty findings bucket means there are no detections of .env file reads, SSH key access, cloud credential handling, or secret storage interactions. Without findings to analyze, there is no evidence of credential theft or excessive secret access. Standard IDE extension credential patterns show no matches in the security analysis.

Counterargument Assessment

The strongest counterargument to this verdict is the absence of findings could indicate incomplete analysis rather than a clean extension. If the CVEQ analysis failed to execute properly on this extension, malicious behavior could remain undetected. However, the extension metadata is complete (name, developer, version, user count, UUID), suggesting the analysis infrastructure processed this extension successfully.

Conclusion

With zero security findings and metadata consistent with a legitimate language tool, this extension shows no evidence of malicious behavior. The empty findings bucket represents a clean scan rather than missing data. The extension's purpose aligns with expected IDE extension capabilities for language support tools.

Key Reasons

  • Zero security findings in evidence bundle
  • Extension metadata consistent with legitimate language tool
  • No credential access or postinstall payload detections

False Positive Considerations

  • Empty findings bucket - no detections to classify as false positives
  • Standard language tool extension with no suspicious patterns

Reviewed 2026-04-25; recommended action: no action; model confidence 85%.

VS Code version history

Risk trend by version

3 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
49
Change since first
+3
Change from previous
+3
Versions:
First analyzed version
3.6.1
Apr 27, 2026
Risk range
46 to 49
Across analyzed versions
Latest analyzed version
3.9.2
Aug 29, 2026
Selected version
medium
Version
v3.9.2
1 months ago
Risk score
49
Findings
110
Change vs previous
+3

Pick any point on the chart to explore that version's code below.

About This Extension

VSCode extension for ZenStack (v3) ZModel language

Frequently Asked Questions