Is "LLM Relay Monitor" on VS Code Marketplace Safe to Install?

jcyLite · vscode · v0.0.9

Status bar monitor for CC (Claude) and CX (Codex) relay providers with one-click key/config switch.

Risk Assessment

Analyzed
58.74
out of 100
MEDIUM

51351 security findings detected across all analyzers

VS Code extension analyzed via package manifest and static code analysis

Severity Breakdown

0
Critical
1685
High
49666
Medium
0
Low
0
Info

Finding Categories

1000
Malware Signatures

YARA Rules Matched

15 rules(1000 hits)
postinstall registry modification postinstall file download postinstall crypto operations postinstall system command postinstall network communication postinstall file manipulation postinstall obfuscation credential env files NoUseWeakRandom HavingAPermissiveCrossOriginResourceSharingPolicy postinstall persistence mechanism credential git credentials DebuggerStatementsShouldNotBeUsed postinstall environment access UsingShellInterpreterWhenExecutingOSCommands

About This Extension

Status bar monitor for CC (Claude) and CX (Codex) relay providers with one-click key/config switch.

Detailed Findings

1000 total

YARA Rule Matches

15 rules

Security Analysis Summary

Security Analysis Overview

LLM Relay Monitor is a Visual Studio Code Marketplace extension published by jcyLite. Version 0.0.9 has been analyzed by the Risky Plugins security platform, receiving a risk score of 58.74/100 (MEDIUM risk) based on 51351 security findings.

Risk Assessment

This extension presents moderate security risk. Several findings were detected that may warrant attention. Users should carefully review the permissions and findings before installation.

Findings Breakdown

  • High: 1685 finding(s)
  • Medium: 49666 finding(s)

What Was Analyzed

The security assessment covers multiple analysis categories:

  • Malware Detection: YARA rule matching against 2,400+ malware signatures
  • Secret Detection: Scanning for exposed API keys, tokens, and credentials
  • Static Analysis: Code-level security analysis for common vulnerability patterns
  • Network Analysis: Detection of suspicious network communications and endpoints
  • Obfuscation Detection: Identification of code obfuscation techniques

Developer Information

LLM Relay Monitor is published by jcyLite on the Visual Studio Code Marketplace marketplace. The extension has approximately 31 users.

Recommendation

Exercise caution with this extension. Review the detailed findings and ensure the requested permissions align with the extension's stated functionality before installation.

Frequently Asked Questions