JTools
The AI review rates the findings as likely false positive, but the risk score (48/100) still counts them.
Analysis record
- Analysed
- 2 days ago
- Version
- v1.1.5.7
- Artifact
- SHA256 8F1…F6E
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
Publisher Evidence
Limited evidence8349aa96-e390-43d3-9aaf-5572ea8a8593
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
12 evidence rows available.
Finding Categories
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality weak.
The JTools extension for JetBrains declares no explicit permissions in the provided metadata. The permissions and host_permissions arrays are completely empty. For a general utility plugin, this aligns with standard behavior where the IDE grants baseline access without requiring elevated filesystem or process execution rights. We see no evidence of the extension spawning unauthorized child processes or reading files outside its expected scope. The lack of declared permissions means the plugin relies entirely on the default sandbox provided by the JetBrains platform, limiting its ability to access arbitrary system resources.
When evaluating credential access, the evidence is entirely clean. The scan results show zero secret detections across the entire codebase. There are no alerts for reading .env files, accessing .ssh directories, or harvesting cloud credentials. The extension does not attempt to interact with the IDE secret storage or credential providers. This complete absence of secret-access findings confirms the plugin is not attempting to steal developer credentials or exfiltrate sensitive configuration data.
The strongest counterargument to a clean verdict relies on the sheer volume of automated alerts. The scan results contain 452 medium-severity IoC findings and 155 low-severity code-smell findings. A reviewer might look at alerts like XIOC-DOMAIN-r.gt, XIOC-DOMAIN-g.pw, and XIOC-DOMAIN-ʞ.co and conclude the extension is beaconing to a vast network of suspicious domains. They might also point to the 155 code-smell alerts as evidence of hidden payloads or malicious logic buried deep within the compiled output.
Those conclusions ignore the actual content of the extracted indicators. The domains are structurally absurd. They include two-letter country codes, domains containing unicode characters like rī.au and 2ڊc.nz, and even a Java configuration file named sqlite-jdbc.properties misidentified as a web address. These are well-documented artifacts of a broken IoC extractor misinterpreting minified JavaScript, binary data, or bundled dependencies as network traffic, rather than actual outbound connections. The code-smell findings are standard noise that trigger on any non-trivial codebase containing basic file or network operations.
The network endpoints list further confirms this pattern. The scanner extracted addresses like 02m.ca, 0zx.fo, and 7蔧u.fi. These three-character domains and unicode-laden strings are not real infrastructure. They are hex substrings and binary fragments parsed incorrectly by the extraction tool. With zero malware signatures, zero secret detections, and no legitimate network endpoints, the extension poses no threat.
Key Reasons
- Zero malware signatures and zero secret access findings
- 452 IoC findings are structurally invalid garbage including unicode domains and properties files
- No explicit permissions or host permissions declared in the package metadata
- 155 code-smell findings are standard noise for non-trivial codebases
False Positive Considerations
- Broken IoC extractor parsing minified JS and binary data as domains
- Code-smell YARA rules firing on standard bundled dependencies
- XIOC extractor misidentifying configuration filenames as network endpoints
Reviewed 2026-10-01; recommended action: suppress false positive; model confidence 95%.
JetBrains version history
Risk trend by version
21 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
JTools HTTP Client
8349aa96-e390-43d3-9aaf-5572ea8a8593
JTools SSH Publisher
8349aa96-e390-43d3-9aaf-5572ea8a8593
JTools-Background
8349aa96-e390-43d3-9aaf-5572ea8a8593
Jtools-Mybatis-Log
8349aa96-e390-43d3-9aaf-5572ea8a8593
DotVVM
keeper7
CodeScan
CodeScan