Rexx Language Support
The AI review rates the findings as likely false positive, but the risk score (54/100) still counts them.
Analysis record
- Analysed
- 2 weeks ago
- Version
- v0.0.24
- Artifact
- SHA256 E41…ACA
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
9 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| LOW | postinstall crypto operations | 2 | dist/desktop/extension.jsdist/web/extension.js | - |
| LOW | postinstall file manipulation | 5 | LICENSE.txtlanguage-configuration.jsonsyntaxes/rexx.tmLanguage +2 more | - |
| LOW | postinstall registry modification | 1 | syntaxes/rexx.tmLanguage | - |
| LOW | postinstall obfuscation | 2 | dist/desktop/extension.jsdist/web/extension.js | - |
| LOW | postinstall network communication | 5 | LICENSE.txtREADME.mdsyntaxes/rexx.tmLanguage +2 more | - |
| LOW | postinstall system command | 5 | README.mdsyntaxes/rexx.tmLanguagedist/desktop/extension.js +2 more | - |
| LOW | postinstall file download | 3 | syntaxes/rexx.tmLanguagedist/desktop/extension.jsdist/web/extension.js | - |
| LOW | NoUseWeakRandom | 2 | dist/desktop/extension.jsdist/web/extension.js | - |
| LOW | credential env files | 2 | dist/desktop/extension.jsdist/web/extension.js | - |
Publisher Evidence
LowBroadcom
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
12 evidence rows available.
Finding Categories
YARA Rules Matched
9 rules(27 hits)AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality moderate.
Rexx Language Support Security Analysis
This extension provides language support for Rexx, a scripting language. The analysis reveals standard patterns expected for language support extensions with no evidence of malicious behavior.
Filesystem and Process Access
The extension's network activity appears in extension/dist/desktop/extension.js and extension/dist/web/extension.js files. These are bundled output directories containing minified JavaScript. The NET-FETCH findings (lines 2, 4, 14) and NET-SOCKET_IO findings (lines 4, 9) in these files represent standard network operations for language extensions. Fetch calls commonly retrieve language server binaries, documentation, or update manifests. Socket.io is the standard protocol for communicating with language servers in VS Code extensions.
This network activity is justified by the extension's stated purpose of providing "rich language support" for Rexx code. Language support extensions must download language server components and maintain persistent connections for features like code completion, error checking, and documentation lookup.
Credential Access
No credential-related findings were detected. The secret: 0 count in the threat indicators confirms the extension does not access .env files, SSH keys, cloud credentials, or VS Code's secret storage. The only dependency identified is @vscode/[email protected] in extension/package.json, which is the official VS Code telemetry package used for anonymous usage statistics.
Malware and Obfuscation
Zero malware signatures matched the extension code. No obfuscation patterns were detected, including no invisible Unicode characters in locale files or suspicious minification techniques. The code structure is consistent with legitimate VS Code extensions.
Strongest Counterargument
The six medium-severity network findings might suggest suspicious data transmission. However, these findings originate from bundled dist/ files using standard protocols (fetch, socket.io) that language extensions require. The absence of any actual IOCs (IP addresses or suspicious domains), combined with the lack of credential access or obfuscation, indicates these are false positives from automated detection rules that flag any network activity.
Conclusion
This extension demonstrates the normal behavior profile of a language support tool. The network activity serves legitimate language server communication purposes, no credentials are accessed, and no malware signatures were found. The findings represent expected patterns for VS Code language extensions rather than security concerns.
Key Reasons
- No malware signatures or obfuscation detected
- Network activity uses standard protocols for language servers
- No credential access findings
- Extension has 10,547 users indicating adoption
- Findings are in bundled dist/ directories
False Positive Considerations
- Network findings in dist/ bundled output files
- Socket.io usage is standard for language server communication
- Fetch calls are normal for language extensions
- No actual IOCs or suspicious domains detected
Reviewed 2026-06-02; recommended action: no action; model confidence 85%.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace