OpenVSX Registry Verified

ZenStack Language Tools

72a1271b-13e5-522e-b95f-6da3d438547a | v2.22.0
56/ 100
MEDIUM risk
Analyst verdict
Benign but powerful

From the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
8 months ago
Version
v2.22.0
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

71 detail rows
Showing 25 of 38 · highest severity first

YARA Rule Matches

15 rules
SeverityRuleHitsFilesMetadata
HIGHUsingCommandLineArguments

Command line arguments can be dangerous just like any other user input. They should never be used without being first validated and sanitized. Remember also that any user can retrieve the list of processes running on a system, which makes the arguments provided to them visible. Thus passing sensitive information via command line arguments should be considered as insecure. This rule raises an issue when on every program entry points (main methods) when command line arguments are used. The goal is to guide security code reviews. Sanitize all command line arguments before using them. For more information checkout the CWE-88 (https://cwe.mitre.org/data/definitions/88.html) advisory.

2
bundle/extension.jsbundle/language-server/main.js
FP 20%
HIGHpostinstall crypto operations

Cryptographic operations detected

3
bundle/extension.jsbundle/language-server/main.jsbundle/res/stdlib.zmodel
Risky Plugins Authors FP 30%
HIGHDebuggerStatementsShouldNotBeUsed

The debugger statement can be placed anywhere in procedures to suspend execution. Using the debugger statement is similar to setting a breakpoint in the code. By definition such statement must absolutely be removed from the source code to prevent any unexpected behavior or added vulnerability to attacks in production. For more information checkout the CWE-489 (https://cwe.mitre.org/data/definitions/489.html) advisory.

1
bundle/language-server/main.js
FP 10%
HIGHNoUseWeakRandom

When software generates predictable values in a context requiring unpredictability, it may be possible for an attacker to guess the next value that will be generated, and use this guess to impersonate another user or access sensitive information. As the Math.random() function relies on a weak pseudorandom number generator, this function should not be used for security-critical applications or for protecting sensitive data. In such context, a cryptographically strong pseudorandom number generator (CSPRNG) should be used instead. For more information checkout the CWE-338 (https://cwe.mitre.org/data/definitions/338.html) advisory.

2
bundle/language-server/main.jsbundle/extension.js
FP 5%
HIGHpostinstall persistence mechanism

Persistence mechanism detected

1
bundle/language-server/main.js
Risky Plugins Authors FP 20%
HIGHpostinstall system command

System command execution detected

5
bundle/res/zmodel-preview-release-notes.htmlpackage.jsonbundle/extension.js +2 more
Risky Plugins Authors FP 10%
HIGHpostinstall network communication

Network communication detected

3
bundle/language-server/main.jsbundle/extension.jsLICENSE.txt
Risky Plugins Authors FP 30%
HIGHUsingShellInterpreterWhenExecutingOSCommands

Arbitrary OS command injection vulnerabilities are more likely when a shell is spawned rather than a new process, indeed shell meta-chars can be used (when parameters are user-controlled for instance) to inject OS commands. For more information checkout the CWE-78 (https://cwe.mitre.org/data/definitions/78.html) advisory.

2
bundle/extension.jsbundle/language-server/main.js
FP 10%
HIGHpostinstall file manipulation

File system manipulation detected

4
bundle/language-server/main.jsbundle/extension.jsbundle/res/stdlib.zmodel +1 more
Risky Plugins Authors FP 20%
HIGHNoUseEval

The eval function is extremely dangerous. Because if any user input is not handled correctly and passed to it, it will be possible to execute code remotely in the context of your application (RCE - Remote Code Executuion). For more information checkout the CWE-94 (https://cwe.mitre.org/data/definitions/94.html) advisory.

1
bundle/language-server/main.js
FP 10%
HIGHpostinstall file download

File download activity detected

2
bundle/extension.jsbundle/language-server/main.js
Risky Plugins Authors FP 30%
HIGHpostinstall obfuscation

Code obfuscation techniques detected

2
bundle/extension.jsbundle/language-server/main.js
Risky Plugins Authors FP 20%
HIGHpostinstall registry modification

Windows registry modification detected

2
bundle/extension.jsbundle/language-server/main.js
Risky Plugins Authors FP 30%
HIGHRedirectToUnknownPath

Sanitizing untrusted URLs is an important technique for preventing attacks such as request forgeries and malicious redirections. Often, this is done by checking that the host of a URL is in a set of allowed hosts. For more information checkout the CWE-20 (https://cwe.mitre.org/data/definitions/20.html) advisory.

1
bundle/language-server/main.js
FP 30%
HIGHcredential env files

Environment configuration file path detected

2
bundle/extension.jsbundle/language-server/main.js
Risky Plugins Authors FP 10%

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

5,191 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Publisher Evidence

Low

zenstack

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

55
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Verified publisher
Verified
Extension portfolio
2
Portfolio

12 evidence rows available.

Finding Categories

33
Malware Signatures
5,191
IoC Indicators

YARA Rules Matched

15 rules(33 hits)
UsingCommandLineArguments postinstall crypto operations DebuggerStatementsShouldNotBeUsed NoUseWeakRandom postinstall persistence mechanism postinstall system command postinstall network communication UsingShellInterpreterWhenExecutingOSCommands postinstall file manipulation NoUseEval postinstall file download postinstall obfuscation postinstall registry modification RedirectToUnknownPath credential env files

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality weak.

Security Analysis: ZenStack Language Tools

Extension Overview

ZenStack Language Tools is a development extension published by "zenstack" on the OpenVSX marketplace with 1,232 users. The extension's stated purpose is "FullStack enhancement for Prisma ORM: seamless integration from database to UI." ZenStack is a well-known open-source project that provides schema-based authorization and full-stack development capabilities for Prisma ORM applications.

Filesystem and Process Access Assessment

The evidence bundle contains an empty findings_by_category object, meaning no security findings were detected during the CVEQ analysis. Language server extensions like ZenStack legitimately require filesystem read access to provide syntax highlighting, IntelliSense, code navigation, and schema validation for Prisma database files. Process execution may be required to spawn language server processes or execute schema validation commands. Without specific findings to cite, there is no evidence of unjustified access patterns.

Credential Access Assessment

No credential-access findings were detected in this analysis. The empty findings_by_category indicates the extension does not trigger YARA rules related to credential theft (credential_* rules), nor does it show suspicious patterns of reading sensitive files like .env, .git/config, SSH keys, or cloud credentials. This is consistent with a legitimate language tool that focuses on schema parsing and code intelligence rather than secret management.

Strongest Counterargument

The strongest counterargument to this verdict is that the empty findings_by_category could indicate incomplete analysis data rather than a genuinely clean scan. The "version: unknown" field in the evidence suggests potential data collection gaps. However, this does not outweigh the evidence that ZenStack is a legitimate, well-established open-source project with a clear development purpose. The extension's name directly matches the known ZenStack project, and its description accurately reflects the tool's function.

Conclusion

ZenStack Language Tools represents a legitimate development tool with no detected security concerns. Language extensions inherently require broad workspace access to function correctly, and this extension's access patterns align with its stated purpose of providing Prisma ORM integration. No malicious patterns, exfiltration mechanisms, or credential theft indicators were found.

Recommendation

No security action required. The extension can be safely used for Prisma ORM development workflows.

Key Reasons

  • No security findings detected in analysis
  • Legitimate open-source Prisma ORM tool
  • Extension purpose matches known ZenStack project
  • No credential access or exfiltration patterns found

False Positive Considerations

  • empty_findings_bundle
  • language_server_expected_behavior
  • legitimate_open_source_project

Reviewed 2026-04-22; recommended action: no action; model confidence 85%.

About This Extension

FullStack enhancement for Prisma ORM: seamless integration from database to UI

Frequently Asked Questions