Baidu Comate (Gitee版)
The AI review rates the findings as likely false positive, but the risk score (61/100) still counts them.
Analysis record
- Analysed
- 3 days ago
- Version
- v2.1.0
- Artifact
- SHA256 88F…9D9
- Source
- Findings (non-IoC)
Is Baidu Comate (Gitee版) safe?
Baidu Comate is an AI coding assistant for JetBrains IDEs. It runs a bundled Node.js engine from comate-intellij-plugin/comate-agent/bin/comate-engine/ so it can read your project and send code context to Baidu's model service for completions and chat. The plugin declares no special permission strings and no host permissions in its manifest. The code the scan flags most often is the HTTP machinery inside that engine, with fetch and axios calls in files like plugins/git/dist/index.js and plugins/demo-feature/dist/index.js.
The scanned endpoint list is mostly junk. It contains entries such as assert.fail, array.new and agent.cc, which are pieces of minified JavaScript and property names caught by pattern matching rather than real servers. One thing that would matter is a request carrying workspace content to a remote host, since an assistant with code access could send it. Nothing in the scan ties a sensitive file read to an outbound request. There are no matches for reads of .env files, SSH keys or cloud credentials, and no malware signature matched anywhere in the package.
That pattern is what build output looks like. A minified engine pulls in dozens of small HTTP libraries and each one trips the same rules, so the finding total is mostly arithmetic. A verified publisher and roughly 15,000 installations line up with how this kind of tool ships.
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
Publisher Evidence
Lowbaidu
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
11 evidence rows available.
Finding Categories
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality moderate.
Baidu Comate is an AI coding assistant for JetBrains IDEs, published by Baidu and installed by roughly 15,000 users. Its reach into files and processes is broad by design. The plugin ships a Node.js engine under comate-intellij-plugin/comate-agent/bin/comate-engine/ that reads the open project to build context for completions and chat, and that engine is what the scanner looked at. The manifest carries no host permissions and no permission strings, so nothing in the package is asking for scopes beyond what an IDE assistant needs to see the code it is helping with. The 19 medium network findings are plain HTTP client usage inside bundled dependencies: axios calls at comate-intellij-plugin/comate-agent/bin/comate-engine/plugins/demo-feature/dist/index.js around lines 18843 to 19558, fetch calls at .../plugins/git/dist/index.js lines 5983 and 7104, more fetch calls at .../plugins/dev-tools/dist/index.js, and one at .../node_modules/@comate/plugin-host/dist/index.js. Calls to a model backend from an assistant shipped as webpack output are the expected shape of this product.
Nothing here touches real secrets. The secret category is empty, there are no credential-access rule matches, and no finding names .env, .ssh, .git/config, cloud credential files or any VS Code or JetBrains credential store. The code-smell hits that make up the low-severity bulk reference environment variables and API keys in generic patterns that fire on any non-trivial JavaScript, which is why 191 of them are spread across the same dist files that produced the network hits.
The indicator volume is where the score pressure comes from, and it does not describe behavior. The endpoint list is mostly strings like assert.fail, array.new, ancestor.read, ajv.opts.code.es and agent.cc, which are property accesses and identifier fragments sliced out of minified JavaScript rather than servers. Several entries contain non-Latin characters mixed into hostname-shaped text, another sign of substring extraction. Against that noise, malware signatures return zero, obfuscation returns zero, tool-poisoning returns zero and dependency findings return zero.
The strongest counterargument is that 19 medium network findings sit inside an engine that can read the whole workspace, and an AI assistant has exactly the access needed to ship source code off a developer machine. What would confirm that is a file read of a sensitive path paired with an outbound request, and no such pairing exists in this scan. The flagged calls resolve to code identifiers, and no secret-reading finding was recorded to pair them with. A verified publisher with 15,000 installs bundling a minified inference engine explains every category of finding without assuming intent to harm.
Key Reasons
- All 19 network findings are HTTP client calls (axios, fetch, XMLHttpRequest) inside bundled dist/ files of the comate-engine runtime, which an AI assistant needs to reach its model backend
- Zero secret, credential-access, malware-signature, obfuscation and tool-poisoning findings across 1,778 results
- The endpoint list resolves to minified JavaScript property chains such as assert.fail, array.new and ajv.opts.code.es rather than real hosts
- Publisher is Baidu with ~15,000 installs on JetBrains Marketplace, and the manifest declares no host permissions or permission strings
False Positive Considerations
- IoC extraction from minified JS property chains and identifier fragments
- Multiplicative hits from bundled node_modules and multiple dist/index.js plugin bundles
- Generic code-smell rules firing on any non-trivial JavaScript
- Absence of any matching evidence in the categories that would confirm intent (secret, malware, obfuscation, tool-poisoning)
Reviewed 2026-09-30; recommended action: suppress false positive; model confidence 85%.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace