Codex Translation Editor
The AI review rates the findings as likely false positive, but the risk score (50/100) still counts them.
Analysis record
- Analysed
- 1 weeks ago
- Version
- v0.34.0
- Artifact
- SHA256 928…9F4
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
19 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| LOW | LocalStorageShouldNotBeUsed | 10 | webviews/codex-webviews/dist/MissingToolsWarning/index.js.mapwebviews/codex-webviews/dist/PublishProject/index.js.mapwebviews/codex-webviews/dist/StartupFlow/index.js.map +7 more | - |
| LOW | postinstall persistence mechanism | 13 | webviews/codex-webviews/dist/CellLabelImporterView/index.js.mapwebviews/codex-webviews/dist/StartupFlow/index.js.mapwebviews/codex-webviews/dist/StartupFlow/index.js +10 more | - |
| LOW | credential env files | 19 | webviews/codex-webviews/dist/PublishProject/index.js.mapwebviews/codex-webviews/dist/CommentsView/index.js.mapwebviews/codex-webviews/dist/StartupFlow/index.js.map +16 more | - |
| LOW | credential vscode credentials | 2 | out/extension.jspackage.json | - |
| LOW | NoUseEval | 1 | out/extension.js | - |
| LOW | NoUseWeakRandom | 35 | webviews/codex-webviews/dist/InterfaceSettings/index.jswebviews/codex-webviews/dist/CommentsView/index.js.mapwebviews/codex-webviews/dist/MissingToolsWarning/index.js.map +32 more | - |
| LOW | postinstall file download | 36 | webviews/codex-webviews/dist/MissingToolsWarning/index.js.mapwebviews/codex-webviews/dist/NewSourceUploader/index.jswebviews/codex-webviews/dist/AutomatedTesting/index.js +33 more | - |
| LOW | credential git credentials | 1 | out/extension.js | - |
| LOW | UntrustedContentShouldNotBeIncluded | 2 | webviews/codex-webviews/dist/CodexCellEditor/index.jswebviews/codex-webviews/dist/CodexCellEditor/index.js.map | - |
| LOW | UsingIntrusivePermissionsWithGeolocation | 6 | webviews/codex-webviews/dist/MissingToolsWarning/index.js.mapwebviews/codex-webviews/dist/EditableReactTable/index.js.mapwebviews/codex-webviews/dist/MainMenu/index.js.map +3 more | - |
| LOW | SQLInjection | 7 | webviews/codex-webviews/dist/SystemMessageReview/index.jswebviews/codex-webviews/dist/StartupFlow/index.jswebviews/codex-webviews/dist/CodexCellEditor/index.js +4 more | - |
| LOW | postinstall file manipulation | 35 | webviews/codex-webviews/dist/SplashScreen/index.js.mapwebviews/codex-webviews/dist/MissingToolsWarning/index.js.mapwebviews/codex-webviews/dist/AutomatedTesting/index.js +32 more | - |
| LOW | postinstall crypto operations | 36 | webviews/codex-webviews/dist/AutomatedTesting/index.jswebviews/codex-webviews/dist/NavigationView/index.jswebviews/codex-webviews/dist/SplashScreen/index.js +33 more | - |
| LOW | postinstall system command | 38 | webviews/codex-webviews/dist/CopilotSettings/index.jsreadme.mdwebviews/codex-webviews/dist/CommentsView/index.js +35 more | - |
| LOW | postinstall registry modification | 12 | webviews/codex-webviews/dist/EditableReactTable/index.js.mapwebviews/codex-webviews/dist/CellLabelImporterView/index.js.mapwebviews/codex-webviews/dist/CellLabelImporterView/index.js +9 more | - |
| LOW | postinstall obfuscation | 36 | webviews/codex-webviews/dist/MissingToolsWarning/index.js.mapwebviews/codex-webviews/dist/NewSourceUploader/index.jswebviews/codex-webviews/dist/AutomatedTesting/index.js +33 more | - |
| LOW | postinstall network communication | 34 | webviews/codex-webviews/dist/MissingToolsWarning/index.js.mapwebviews/codex-webviews/dist/AutomatedTesting/index.jswebviews/codex-webviews/dist/NavigationView/index.js +31 more | - |
| LOW | OriginsNotVerified | 11 | webviews/codex-webviews/dist/SystemMessageReview/index.jswebviews/codex-webviews/dist/SplashScreen/index.jswebviews/codex-webviews/dist/CommentsView/index.js +8 more | - |
| LOW | UsingShellInterpreterWhenExecutingOSCommands | 1 | out/extension.js | - |
Publisher Evidence
Lowproject-accelerate
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
12 evidence rows available.
Finding Categories
YARA Rules Matched
19 rules(335 hits)AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality strong.
The Codex Translation Editor extension declares support for .codex notebooks and translation source files, which justifies its network behavior. The 48 network findings consist entirely of fetch calls in extension/out/4.extension.js:10236, extension/out/extension.js:9327, extension/out/extension.js:9521, extension/out/3.extension.js:23159, extension/out/1.extension.js:16830, extension/out/1.extension.js:1590, extension/out/4.extension.js:317, extension/out/4.extension.js:10307, extension/out/1.extension.js:12345, extension/out/3.extension.js:22769 and socket_io calls in extension/webviews/codex-webviews/dist/EditableReactTable/index.js:58 and extension/webviews/codex-webviews/dist/EditableReactTable/index.js:209. These are expected patterns for a translation editor that must communicate with translation APIs and render interactive webview components.
No credential-access findings were detected. The findings_summary shows secret:0 with no matches for .env files, .git/config, SSH keys, or cloud credentials. This is consistent with the extension's stated purpose, which does not require access to secrets.
The strongest counterargument is the volume of network calls (48 findings), which could theoretically indicate data exfiltration. However, the threat_indicators show ioc:0 and malware-signature:0, meaning none of these network calls target suspicious domains. The calls occur in bundled output files (extension/out/) and webview dist folders (extension/webviews/codex-webviews/dist/), which are standard locations for compiled extension code and third-party UI libraries. The 48 low-severity dependency findings are consistent with bundled npm packages, not malicious code.
With 62,522 users, no malware signatures, no obfuscation findings, and network behavior justified by translation functionality, this extension exhibits normal IDE extension patterns. The findings are false positives from expected network activity in a translation tool.
Key Reasons
- Zero malware-signature and zero ioc findings
- Network activity justified by translation editor purpose
- No credential-access or secret findings
- Webview socket_io calls are standard UI pattern
False Positive Considerations
- Network calls in translation editor are expected behavior for API communication
- socket_io in webview dist folder is standard UI component pattern
- No IoC matches despite 48 network findings
- Zero malware signatures and zero obfuscation findings
Reviewed 2026-05-23; recommended action: no action; model confidence 85%.
Open VSX version history
Risk trend by version
9 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
codex-copilot
project-accelerate
shared-state-store
project-accelerate
pythoninstaller
project-accelerate
scripture-language-support
project-accelerate
translators-copilot
project-accelerate
vscode-edit-table
project-accelerate