ZenStack Language Tools
From the RiskyPlugins AI security review of the observed evidence.
Analysis record
- Analysed
- 8 months ago
- Version
- v2.22.0
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
15 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| HIGH | UsingCommandLineArguments Command line arguments can be dangerous just like any other user input. They should never be used without being first validated and sanitized. Remember also that any user can retrieve the list of processes running on a system, which makes the arguments provided to them visible. Thus passing sensitive information via command line arguments should be considered as insecure. This rule raises an issue when on every program entry points (main methods) when command line arguments are used. The goal is to guide security code reviews. Sanitize all command line arguments before using them. For more information checkout the CWE-88 (https://cwe.mitre.org/data/definitions/88.html) advisory. | 2 | bundle/extension.jsbundle/language-server/main.js | FP 20% |
| HIGH | postinstall crypto operations Cryptographic operations detected | 3 | bundle/extension.jsbundle/language-server/main.jsbundle/res/stdlib.zmodel | Risky Plugins Authors FP 30% |
| HIGH | DebuggerStatementsShouldNotBeUsed The debugger statement can be placed anywhere in procedures to suspend execution. Using the debugger statement is similar to setting a breakpoint in the code. By definition such statement must absolutely be removed from the source code to prevent any unexpected behavior or added vulnerability to attacks in production. For more information checkout the CWE-489 (https://cwe.mitre.org/data/definitions/489.html) advisory. | 1 | bundle/language-server/main.js | FP 10% |
| HIGH | NoUseWeakRandom When software generates predictable values in a context requiring unpredictability, it may be possible for an attacker to guess the next value that will be generated, and use this guess to impersonate another user or access sensitive information. As the Math.random() function relies on a weak pseudorandom number generator, this function should not be used for security-critical applications or for protecting sensitive data. In such context, a cryptographically strong pseudorandom number generator (CSPRNG) should be used instead. For more information checkout the CWE-338 (https://cwe.mitre.org/data/definitions/338.html) advisory. | 2 | bundle/language-server/main.jsbundle/extension.js | FP 5% |
| HIGH | postinstall persistence mechanism Persistence mechanism detected | 1 | bundle/language-server/main.js | Risky Plugins Authors FP 20% |
| HIGH | postinstall system command System command execution detected | 5 | bundle/res/zmodel-preview-release-notes.htmlpackage.jsonbundle/extension.js +2 more | Risky Plugins Authors FP 10% |
| HIGH | postinstall network communication Network communication detected | 3 | bundle/language-server/main.jsbundle/extension.jsLICENSE.txt | Risky Plugins Authors FP 30% |
| HIGH | UsingShellInterpreterWhenExecutingOSCommands Arbitrary OS command injection vulnerabilities are more likely when a shell is spawned rather than a new process, indeed shell meta-chars can be used (when parameters are user-controlled for instance) to inject OS commands. For more information checkout the CWE-78 (https://cwe.mitre.org/data/definitions/78.html) advisory. | 2 | bundle/extension.jsbundle/language-server/main.js | FP 10% |
| HIGH | postinstall file manipulation File system manipulation detected | 4 | bundle/language-server/main.jsbundle/extension.jsbundle/res/stdlib.zmodel +1 more | Risky Plugins Authors FP 20% |
| HIGH | NoUseEval The eval function is extremely dangerous. Because if any user input is not handled correctly and passed to it, it will be possible to execute code remotely in the context of your application (RCE - Remote Code Executuion). For more information checkout the CWE-94 (https://cwe.mitre.org/data/definitions/94.html) advisory. | 1 | bundle/language-server/main.js | FP 10% |
| HIGH | postinstall file download File download activity detected | 2 | bundle/extension.jsbundle/language-server/main.js | Risky Plugins Authors FP 30% |
| HIGH | postinstall obfuscation Code obfuscation techniques detected | 2 | bundle/extension.jsbundle/language-server/main.js | Risky Plugins Authors FP 20% |
| HIGH | postinstall registry modification Windows registry modification detected | 2 | bundle/extension.jsbundle/language-server/main.js | Risky Plugins Authors FP 30% |
| HIGH | RedirectToUnknownPath Sanitizing untrusted URLs is an important technique for preventing attacks such as request forgeries and malicious redirections. Often, this is done by checking that the host of a URL is in a set of allowed hosts. For more information checkout the CWE-20 (https://cwe.mitre.org/data/definitions/20.html) advisory. | 1 | bundle/language-server/main.js | FP 30% |
| HIGH | credential env files Environment configuration file path detected | 2 | bundle/extension.jsbundle/language-server/main.js | Risky Plugins Authors FP 10% |
Network Indicators
Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.
Network indicators are queued for lazy loading
Scroll this section into view to load the detailed rows.
Publisher Evidence
Lowzenstack
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
12 evidence rows available.
Finding Categories
YARA Rules Matched
15 rules(33 hits)AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality weak.
Security Analysis: ZenStack Language Tools
Extension Overview
ZenStack Language Tools is a development extension published by "zenstack" on the OpenVSX marketplace with 1,232 users. The extension's stated purpose is "FullStack enhancement for Prisma ORM: seamless integration from database to UI." ZenStack is a well-known open-source project that provides schema-based authorization and full-stack development capabilities for Prisma ORM applications.
Filesystem and Process Access Assessment
The evidence bundle contains an empty findings_by_category object, meaning no security findings were detected during the CVEQ analysis. Language server extensions like ZenStack legitimately require filesystem read access to provide syntax highlighting, IntelliSense, code navigation, and schema validation for Prisma database files. Process execution may be required to spawn language server processes or execute schema validation commands. Without specific findings to cite, there is no evidence of unjustified access patterns.
Credential Access Assessment
No credential-access findings were detected in this analysis. The empty findings_by_category indicates the extension does not trigger YARA rules related to credential theft (credential_* rules), nor does it show suspicious patterns of reading sensitive files like .env, .git/config, SSH keys, or cloud credentials. This is consistent with a legitimate language tool that focuses on schema parsing and code intelligence rather than secret management.
Strongest Counterargument
The strongest counterargument to this verdict is that the empty findings_by_category could indicate incomplete analysis data rather than a genuinely clean scan. The "version: unknown" field in the evidence suggests potential data collection gaps. However, this does not outweigh the evidence that ZenStack is a legitimate, well-established open-source project with a clear development purpose. The extension's name directly matches the known ZenStack project, and its description accurately reflects the tool's function.
Conclusion
ZenStack Language Tools represents a legitimate development tool with no detected security concerns. Language extensions inherently require broad workspace access to function correctly, and this extension's access patterns align with its stated purpose of providing Prisma ORM integration. No malicious patterns, exfiltration mechanisms, or credential theft indicators were found.
Recommendation
No security action required. The extension can be safely used for Prisma ORM development workflows.
Key Reasons
- No security findings detected in analysis
- Legitimate open-source Prisma ORM tool
- Extension purpose matches known ZenStack project
- No credential access or exfiltration patterns found
False Positive Considerations
- empty_findings_bundle
- language_server_expected_behavior
- legitimate_open_source_project
Reviewed 2026-04-22; recommended action: no action; model confidence 85%.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
ZenStack Language Tools
ZenStack
zenstack-v3
zenstack
ZenStack V3 Language Tools
ZenStack Modeling Tools
ZenStack V2 Language Tools
ZenStack Modeling Tools
quark-lang
quarkproject
jcl-check-support
BroadcomMFD