OpenVSX Registry Verified

Python Debugger

86f1cfbf-9eeb-5b41-99bb-00f676a9d8fc | v2026.6.0
31/ 100
LOW risk
Analyst verdict
No high-risk signal observed

Based on the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
5 days ago
Version
v2026.6.0
Artifact
SHA256 F4A…A67
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

10 detail rows

Publisher Evidence

Low

ms-python

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

65
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Verified publisher
Verified
Extension portfolio
539
Portfolio

12 evidence rows available.

Finding Categories

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

The Python Debugger extension from Microsoft (ms-python) is a legitimate debugging tool with over 44 million users. This analysis examines whether the 1,203 security findings indicate actual threats or expected IDE behavior.

Filesystem and Process Access

The extension's filesystem access is justified by its debugging purpose. The package.json at /tmp/extract-cefe9f6257b5db9e4bdfc4fdbe359b1ce19a0062e4b16c1b224b085fbe9df027-189686933/extension/package.json declares dependencies like fs-extra@^11.2.0 and @vscode/debugadapter@^1.65.0, which are standard libraries for file operations and debug adapter communication. A debugger must read source files to set breakpoints and inspect variables, and it must spawn Python processes to attach to them. This is expected behavior, not a security concern.

Credential Access

No credential-access findings target actual secrets. The findings summary shows zero secret findings and zero network findings. There are no matches for .env files, SSH keys, cloud credentials, or VS Code's secret storage. The extension does not request or access credentials beyond what's needed for debugging.

Code-Smell Findings

The 857 high-severity findings are all code-smell YARA rules firing on bundled Python code. Files like extension/bundled/libs/debugpy/common/json.py, extension/bundled/libs/debugpy/_vendored/pydevd/pydevd_attach_to_process/winappdbg/win32/context_amd64.py, and extension/bundled/libs/debugpy/_vendored/pydevd/_pydevd_sys_monitoring/_pydevd_sys_monitoring.py are legitimate debugpy library code. These YARA rules match generic patterns in any non-trivial Python/JavaScript code and are classified as noise.

Threat Indicators

The threat indicators show zero matches across all categories: no IoC, no malware signatures, no malware, no network activity, no obfuscation, and no tool poisoning. This is a clean security profile.

Strongest Counterargument

Someone might argue the high finding count (1,203 total) suggests hidden issues. However, finding count is noise—finding nature is signal. All 857 "high" severity items are code-smell findings on bundled libraries, and the actual threat indicators are all zero. The extension is from Microsoft's official publisher with 44 million users, and debugpy is the standard Python debugging library.

Conclusion

This is a false positive driven by code-smell YARA rules matching legitimate bundled Python code. The extension has no actual malicious indicators and performs expected debugger functionality.

Key Reasons

  • Zero actual threat indicators (no malware, no IoC, no network, no obfuscation)
  • Official Microsoft publisher with 44 million users
  • All high-severity findings are code-smell YARA noise on bundled libraries
  • Filesystem and process access justified by debugging purpose

False Positive Considerations

  • code-smell YARA rules on bundled debugpy Python libraries
  • high finding count from legitimate npm dependencies
  • metadata hash findings from standard package distribution files
  • dependency findings for standard debugging libraries

Reviewed 2026-05-23; recommended action: suppress false positive; model confidence 95%.

About This Extension

Python Debugger extension using debugpy.

Frequently Asked Questions