VS Code Marketplace

GTK CSS

by Michele Pio Mischitelli · 832 users · 5.0 rating
70f24939-5e71-5f37-80b2-87911120ae1d | v1.5.0
31/ 100
LOW risk
No change since v1.3.0
Analyst verdict
No high-risk signal observed

Based on the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
6 months ago
Version
v1.5.0
Artifact
SHA256 A8D…DF8
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

5 detail rows

Publisher Evidence

Limited evidence

Michele Pio Mischitelli

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

34
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Not exposed
Not exposed
Extension portfolio
2
Portfolio

13 evidence rows available.

Finding Categories

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality weak.

Filesystem and Process Access Analysis

The GTK CSS extension is a syntax highlighting and IntelliSense provider for GTK-specific CSS properties. The findings_by_category field contains zero security findings, indicating CVEQ detected no suspicious code patterns, network calls, or file access behaviors. This extension's stated purpose requires no filesystem access beyond what VS Code provides for editor functionality, no process execution, and no network connectivity. Syntax highlighting extensions operate within the VS Code language service layer and do not spawn processes or read workspace files independently.

Credential Access Analysis

No credential-related findings exist in the evidence bundle. There are no matches for credential_* YARA rules, no evidence of .env file reads, no SSH key access, and no interaction with VS Code's secret storage. The extension's grammar-based functionality does not require credential access under any circumstances.

Strongest Counterargument

The extension has only 190 users, which is relatively low for a VS Code extension. However, GTK CSS is a specialized domain used by GTK application developers (GNOME, Linux desktop applications), representing a niche developer audience. Low download count combined with a specialized purpose does not indicate malicious intent. The developer name mpmischitelli appears on the VS Code marketplace, and while verification status is not provided in the evidence, the absence of any security findings is the primary indicator of safety.

Conclusion

This extension presents no security concerns. The empty findings bundle is the strongest evidence of safety. Syntax highlighting extensions like this one are among the lowest-risk IDE extension types, as they provide static language support without runtime code execution. No action is required.

Key Reasons

  • Zero security findings detected
  • Legitimate syntax highlighting purpose
  • No file or process access findings
  • No credential access findings

False Positive Considerations

  • No findings to evaluate
  • Syntax highlighting extension category

Reviewed 2026-04-22; recommended action: no action; model confidence 95%.

VS Code version history

Risk trend by version

3 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
31
Change since first
No change
Change from previous
No change
Versions:
First analyzed version
1.2.0
Mar 16, 2026
Risk range
31 to 31
Across analyzed versions
Latest analyzed version
1.5.0
Apr 5, 2026
Selected version
low
Version
v1.5.0
5 months ago
Risk score
31
Findings
5
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

Syntax highlighting and IntelliSense for GTK-specific CSS: @define-color, color functions (alpha, shade, mix), -gtk- properties, and GTK widget element selectors.

Frequently Asked Questions