OpenVSX Registry Verified

Black Formatter

87d0cc8c-c24a-5571-b7cf-536db97180a4 | v2025.2.0
52/ 100
MEDIUM risk
Risk verdict
Review before use

Score-based assessment (medium risk, 52/100). No analyst review available.

Analysis record

Analysed
2 weeks ago
Version
v2025.2.0
Artifact
SHA256 52A…51E
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

358 detail rows

YARA Rule Matches

14 rules
SeverityRuleHitsFilesMetadata
LOWDebuggerStatementsShouldNotBeUsed 2
bundled/libs/attrs-25.1.0.dist-info/METADATAbundled/libs/attr/_make.py
-
LOWNoUseEval 9
bundled/libs/cattrs/gen/typeddicts.pybundled/libs/blib2to3/pgen2/literals.pybundled/libs/blib2to3/Grammar.txt +6 more
-
LOWNoUseWeakRandom 1
dist/extension.js
-
LOWpostinstall file download 24
bundled/libs/platformdirs/unix.pybundled/libs/packaging/licenses/_spdx.pybundled/libs/black/lines.py +21 more
-
LOWpostinstall crypto operations 26
bundled/libs/attr/__init__.pyibundled/libs/attr/_next_gen.pybundled/libs/packaging/requirements.py +23 more
-
LOWpostinstall system command 74
bundled/libs/click-8.1.8.dist-info/RECORDbundled/libs/click/utils.pybundled/libs/black-25.1.0.dist-info/METADATA +71 more
-
LOWUsingShellInterpreterWhenExecutingOSCommands 1
dist/extension.js
-
LOWpostinstall network communication 39
bundled/libs/black/__init__.pybundled/tool/lsp_io.pySECURITY.md +36 more
-
LOWpostinstall obfuscation 58
bundled/libs/blib2to3/pgen2/pgen.pybundled/libs/black/trans.pybundled/libs/cattrs/cols.py +55 more
-
LOWpostinstall registry modification 4
bundled/libs/cattrs/converters.pybundled/libs/typing_extensions.pybundled/libs/cattrs/dispatch.py +1 more
-
LOWpostinstall environment access 27
build/azure-pipeline.stable.ymlbundled/libs/cattrs-24.1.2.dist-info/METADATAbundled/libs/exceptiongroup/__init__.py +24 more
-
LOWpostinstall file manipulation 66
bundled/libs/cattrs/cols.pybundled/libs/black-25.1.0.dist-info/METADATAbundled/libs/black/cache.py +63 more
-
LOWcredential env files 21
bundled/libs/platformdirs/unix.pypackage.jsonbundled/libs/platformdirs/android.py +18 more
-
LOWpostinstall persistence mechanism 3
bundled/libs/packaging/licenses/_spdx.pybundled/libs/black-25.1.0.dist-info/METADATAbuild/azure-pipeline.pre-release.yml
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

593 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Publisher Evidence

Low

ms-python

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

65
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Verified publisher
Verified
Extension portfolio
539
Portfolio

12 evidence rows available.

Finding Categories

593
IoC Indicators

YARA Rules Matched

14 rules(355 hits)
DebuggerStatementsShouldNotBeUsed NoUseEval NoUseWeakRandom postinstall file download postinstall crypto operations postinstall system command UsingShellInterpreterWhenExecutingOSCommands postinstall network communication postinstall obfuscation postinstall registry modification postinstall environment access postinstall file manipulation credential env files postinstall persistence mechanism

Security Analysis Summary

Security Analysis Overview

Black Formatter is a OpenVSX Registry extension published by ms-python. Version 2025.2.0 has been analyzed by the Risky Plugins security platform, receiving a risk score of 51.97/100 (MEDIUM risk) based on 951 security findings.

Risk Assessment

This extension presents moderate security risk. Several findings were detected that may warrant attention. Users should carefully review the permissions and findings before installation.

Findings Breakdown

  • Medium: 593 finding(s)
  • Low: 358 finding(s)

What Was Analyzed

The security assessment covers multiple analysis categories:

  • Malware Detection: YARA rule matching against 2,400+ malware signatures
  • Secret Detection: Scanning for exposed API keys, tokens, and credentials
  • Static Analysis: Code-level security analysis for common vulnerability patterns
  • Network Analysis: Detection of suspicious network communications and endpoints
  • Obfuscation Detection: Identification of code obfuscation techniques

Developer Information

Black Formatter is published by ms-python on the OpenVSX Registry marketplace.

Recommendation

Exercise caution with this extension. Review the detailed findings and ensure the requested permissions align with the extension's stated functionality before installation.

About This Extension

Formatting support for Python files using the Black formatter.

Frequently Asked Questions