VS Code Marketplace Verified

Amicode

by Harmoniqs · 93 users · 5.0 rating
88b287a0-b527-59a4-a9ea-2f089cb75467 | v0.3.7
82/ 100
HIGH risk
No change since v0.3.5
Risk verdict
Review before use

Score-based assessment (high risk, 82/100). No analyst review available.

Analysis record

Analysed
1 weeks ago
Version
v0.3.7
Artifact
SHA256 EC5…787
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

1000 detail rows
Showing 25 of 61 · highest severity first

YARA Rule Matches

15 rules
SeverityRuleHitsFilesMetadata
LOWpostinstall persistence mechanism 152
dist/app/assets/templ-W185oS4p.jsdist/app/assets/sl-BHOwvC_4.jstemplates/mocksoc-rehearsal/Project.toml +149 more
-
LOWcredential env files 132
skills/tdd/mocking.mddist/app/assets/apache-PcO-DBxQ.jsdist/app/assets/vhdl-DJCsFYgn.js +129 more
-
LOWcredential vscode credentials 1
tools/fleet/amico-opencode-fleet-guard
-
LOWpostinstall file download 369
dist/app/assets/wit-DDW3hD69.jsdist/app/assets/fr-m8UysddV.jsdist/app/assets/solidity-B3CjIuAd.js +366 more
-
LOWNoUseWeakRandom 8
bin/dist/amicode-service-runner.mjsbin/dist/mcp-amico.mjsbin/dist/mcp-amico.mjs.map +5 more
-
LOWBolonyokte 3
bin/dist/amicode-service-runner.mjsdist/app/assets/index-Didq6CIc.jsdist/extension.js
-
LOWSQLInjection 2
dist/app/assets/index-DKdKVJA2.jsdist/app/assets/index-Didq6CIc.js
-
LOWcredential git credentials 2
dist/app/assets/mdx-C2fqO2XY.jsdist/app/assets/mdx-Cmh6b_Ma.js
-
LOWDebuggerStatementsShouldNotBeUsed 33
dist/app/assets/emacs-lisp-CXvaQtF9.jsdist/app/assets/night-owl-light-CMTm3GFP.jsdist/app/assets/everforest-light-C8M2exoo.js +30 more
-
LOWUsingCommandLineArguments 10
bin/dist/amico-git-credential.jsbin/dist/amico-run.jsbin/dist/amico.js +7 more
-
LOWLocalStorageShouldNotBeUsed 4
dist/app/assets/index-Didq6CIc.jsdist/app/assets/index-BOLpGlpP.jsdist/app/oc-theme-preload.js +1 more
-
LOWpostinstall file manipulation 1
dist/app/assets/common-lisp-DXc9XcIM.js
-
LOWpostinstall registry modification 17
opencode-plugin/model_routing.tsbin/dist/amico.jsdist/app/assets/objective-c-BoaBTdtz.js +14 more
-
LOWpostinstall environment access 204
dist/app/assets/haskell-Cw1EW3IL.jsdist/app/assets/imba-DGztddWO.jsdist/app/assets/wikitext-BhOHFoWU.js +201 more
-
LOWpostinstall crypto operations 1
dist/app/assets/apache-PcO-DBxQ.js
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

2,936 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Publisher Evidence

Limited evidence

Harmoniqs

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

32
Noisy-finding weight
x1.00
Publisher domain
harmoniqs.ai
Observed
Store verification signal
Not exposed
Not exposed
Extension portfolio
1
Portfolio

13 evidence rows available.

Finding Categories

54
Network
2,936
IoC Indicators

YARA Rules Matched

15 rules(939 hits)
postinstall persistence mechanism credential env files credential vscode credentials postinstall file download NoUseWeakRandom Bolonyokte SQLInjection credential git credentials DebuggerStatementsShouldNotBeUsed UsingCommandLineArguments LocalStorageShouldNotBeUsed postinstall file manipulation postinstall registry modification postinstall environment access postinstall crypto operations

Security Analysis Summary

Security Analysis Overview

Amicode is a Visual Studio Code Marketplace extension published by Harmoniqs. Version 0.3.7 has been analyzed by the Risky Plugins security platform, receiving a risk score of 81.7/100 (HIGH risk) based on 5936 security findings.

Risk Assessment

This extension presents high security risk. Significant concerns were identified during analysis. It is not recommended for use in sensitive or production environments without thorough review.

Findings Breakdown

  • Critical: 1 finding(s)
  • Medium: 2996 finding(s)
  • Low: 2939 finding(s)

What Was Analyzed

The security assessment covers multiple analysis categories:

  • Malware Detection: YARA rule matching against 2,400+ malware signatures
  • Secret Detection: Scanning for exposed API keys, tokens, and credentials
  • Static Analysis: Code-level security analysis for common vulnerability patterns
  • Network Analysis: Detection of suspicious network communications and endpoints
  • Obfuscation Detection: Identification of code obfuscation techniques

Developer Information

Amicode is published by Harmoniqs on the Visual Studio Code Marketplace marketplace. The extension has approximately 93 users.

Recommendation

This extension is not recommended for installation without thorough manual review. Consider alternatives with lower risk scores, or contact the developer to address the identified security concerns.

VS Code version history

Risk trend by version

3 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
82
Change since first
No change
Change from previous
No change
Versions:
First analyzed version
0.3.4
Sep 10, 2026
Risk range
82 to 82
Across analyzed versions
Latest analyzed version
0.3.7
Sep 24, 2026
Selected version
high
Version
v0.3.7
1 weeks ago
Risk score
82
Findings
5936
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

Open autonomous research in VS Code — vaults, fleet, and live solves for quantum control and physical intelligence.

Frequently Asked Questions