JCL Language Support
The AI review rates the findings as likely false positive, but the risk score (60/100) still counts them.
Analysis record
- Analysed
- Yesterday
- Version
- v3.1.0
- Artifact
- SHA256 CDB…9D3
- Source
- Findings (non-IoC)
Is JCL Language Support safe?
The jcl-language-support extension provides syntax coloring and code editing features for JCL, a language used in mainframe environments. It is published by BroadcomMFD and connects to official documentation and community resources. The network endpoints in the bundle include techdocs.broadcom.com and join.slack.com, which the extension uses to link users to support pages and project channels. It does not request any special host permissions from the editor.
Static analysis flagged four network findings in the file extension/dist/connection/connection.js with the title NET-JQUERY_AJAX. If these were malicious, they would indicate the extension was sending your code to an unauthorized server. However, these findings simply show the extension using standard web requests to talk to its own backend services, which is exactly what a language tool needs to do to fetch documentation or connect to a mainframe environment.
The scanner also flagged dozens of indicators of compromise that turned out to be standard editor commands like progress.report and client.info, rather than actual web addresses. The code-smell alerts came from the bundled build files in the dist folder, which is normal for extensions built with modern JavaScript tools. Because the network traffic goes only to verified Broadcom and Open Mainframe Project domains, and the publisher is a known enterprise software company, the alerts are just scanner noise from standard programming patterns.
No Findings
All security checks passed
Publisher Evidence
LowBroadcomMFD
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
12 evidence rows available.
No Threats Detected
This extension passed all security checks
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality strong.
The jcl-language-support extension, published by BroadcomMFD, provides rich language support for JCL code within the Code4z ecosystem. An examination of the static analysis findings reveals no indicators of malicious behavior. The 39 indicators of compromise (IoC) flagged by the scanner are almost entirely false positives generated by the extraction tool misidentifying VS Code API method calls as network domains. For example, strings like progress.report, client.info, semantictokensprovider.full.delta, and window.showdocument.support are standard Language Server Protocol (LSP) and VS Code extension API invocations, not external URLs.
The actual network endpoints observed in the bundle point exclusively to legitimate infrastructure owned or used by the publisher and its affiliated projects. Connections to techdocs.broadcom.com, www.openmainframeproject.org, artwork.openmainframeproject.org, and join.slack.com are expected for an extension that links to official documentation, project branding, and community support channels. The four network findings titled NET-JQUERY_AJAX-extension/dist/connection/connection.js and its web counterpart simply indicate that the extension uses standard HTTP requests to communicate with its backend services, which is the core function of a language support extension connecting to a mainframe environment.
Filesystem and process access findings are absent from this bundle. The extension declares no special host permissions or explicit workspace permissions in its manifest. As a language server, it inherently requires read access to workspace files to provide syntax coloring, code completion, and diagnostics for JCL, which is entirely justified by its stated purpose. There are no findings related to credential theft, secret scanning, or access to sensitive files like .env or .ssh directories.
The 39 code-smell findings and 3 dependency findings originate from the extension/dist/ directory. This directory contains bundled and minified JavaScript output from the build process, which routinely triggers generic YARA rules for basic Node.js patterns. These are well-documented noise sources in IDE extension analysis and do not represent intentional obfuscation or malicious payloads.
The strongest counterargument to a benign verdict is the presence of external network calls in extension/dist/connection/connection.js. An extension making outbound connections could theoretically exfiltrate source code. However, the specific domains resolved in the bundle belong to Broadcom and the Open Mainframe Project, a Linux Foundation initiative. There are no connections to unknown third-party analytics services, personal domains, or generic command-and-control infrastructure. The publisher, BroadcomMFD, is a verified enterprise entity, and the extension's 14,898 users on OpenVSX reflect its established use in the mainframe development community. The findings are entirely consistent with a legitimate, enterprise-grade language tool.
Key Reasons
- IoC findings are VS Code API methods like progress.report misidentified as network domains
- Network endpoints point to legitimate Broadcom and Open Mainframe Project infrastructure
- Code-smell findings originate from bundled dist files which is standard build output
- Published by BroadcomMFD a verified enterprise developer
False Positive Considerations
- VS Code API methods misidentified as IoC domains
- Bundled dependency noise in dist files
- Legitimate enterprise publisher domains
Reviewed 2026-10-01; recommended action: suppress false positive; model confidence 95%.
Open VSX version history
Risk trend by version
2 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace