ZenStack V3 Language Tools
The AI review rates the findings as likely false positive, but the risk score (49/100) still counts them.
Analysis record
- Analysed
- 1 months ago
- Version
- v3.9.2
- Artifact
- SHA256 434…7DA
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
15 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| LOW | DebuggerStatementsShouldNotBeUsed | 1 | dist/extension.cjs | - |
| LOW | UsingCommandLineArguments | 1 | dist/extension.cjs | - |
| LOW | postinstall crypto operations | 4 | dist/esm-DsUIqUfc.cjsdist/extension.cjsres/stdlib.zmodel +1 more | - |
| LOW | postinstall file manipulation | 5 | language-configuration.jsondist/esm-DsUIqUfc.cjsdist/language-server.cjs +2 more | - |
| LOW | postinstall system command | 6 | dist/extension.cjsdist/esm-DsUIqUfc.cjsres/zmodel-v3-preview-release-notes.html +3 more | - |
| LOW | postinstall environment access | 2 | dist/language-server.cjsdist/extension.cjs | - |
| LOW | postinstall registry modification | 2 | dist/language-server.cjsdist/extension.cjs | - |
| LOW | postinstall obfuscation | 3 | dist/esm-DsUIqUfc.cjsdist/language-server.cjsdist/extension.cjs | - |
| LOW | postinstall network communication | 3 | dist/esm-DsUIqUfc.cjsdist/language-server.cjsdist/extension.cjs | - |
| LOW | UsingShellInterpreterWhenExecutingOSCommands | 2 | dist/language-server.cjsdist/extension.cjs | - |
| LOW | postinstall file download | 3 | dist/esm-DsUIqUfc.cjsdist/language-server.cjsdist/extension.cjs | - |
| LOW | NoUseWeakRandom | 2 | dist/language-server.cjsdist/extension.cjs | - |
| LOW | credential env files | 3 | dist/esm-DsUIqUfc.cjsdist/language-server.cjsdist/extension.cjs | - |
| LOW | credential vscode credentials | 1 | readme.md | - |
| LOW | postinstall persistence mechanism | 1 | dist/language-server.cjs | - |
Network Indicators
Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.
Network indicators are queued for lazy loading
Scroll this section into view to load the detailed rows.
Publisher Evidence
Lowzenstack
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
12 evidence rows available.
Finding Categories
YARA Rules Matched
15 rules(39 hits)AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality weak.
ZenStack V3 Language Tools Security Analysis
Extension Profile
ZenStack V3 Language Tools (v3.5.2) is a VS Code extension published by "zenstack" on OpenVSX with 1,714 users. The extension provides language support for ZenStack's ZModel domain-specific language, a legitimate development framework for database schema modeling.
Filesystem and Process Access Assessment
The CVEQ analysis returned an empty findings bundle with no detections across any security category. Language server extensions like this one legitimately require workspace file read access to parse and validate ZModel schema files, and may spawn language server processes for syntax highlighting and IntelliSense. However, the analysis shows no evidence of suspicious filesystem access patterns, credential theft attempts, or unauthorized process execution. The absence of findings in the findings_by_category object indicates no code-smell detections (postinstall execution, credential access patterns, or exfiltration logic) were identified.
Credential Access Evaluation
No credential-access findings were detected. Language tool extensions typically do not require access to .env files, SSH keys, or cloud credentials. The empty findings bundle confirms no YARA rules matched credential-related patterns (credential_env, credential_git, credential_cloud, etc.) and no IoC extraction identified suspicious network destinations or secret storage access. This aligns with expected behavior for a language server extension.
Strongest Counterargument
The strongest counterargument to this verdict is that the completely empty findings bundle could indicate incomplete analysis rather than a clean result. An analysis that properly scanned the extension would typically produce some code-smell findings from bundled dependencies (minified JavaScript in dist/ folders, npm packages with standard patterns). The absence of any findings raises questions about whether the analysis ran completely.
However, this does not change the conclusion because:
- The extension publisher name ("zenstack") matches the known ZenStack framework publisher
- The extension has 1,714 users indicating community adoption
- The extension purpose (language tools for ZModel) is legitimate and well-documented
- No specific findings exist to justify a risk verdict
Without evidence of malicious behavior—no postinstall payload execution, no credential theft patterns, no suspicious network destinations—the extension should be treated as benign. The empty findings may reflect either a clean analysis or data collection issues, but neither scenario warrants a risk classification.
Recommendation
No action required. The extension exhibits no security concerns based on available evidence.
Key Reasons
- Empty findings bundle with no security detections
- Publisher name matches legitimate ZenStack framework
- Moderate user adoption (1,714 users) indicates community trust
- No evidence of credential theft or exfiltration patterns
- Language server extensions legitimately require file access
False Positive Considerations
- No findings detected (empty analysis bundle)
- Language server extensions require legitimate file/process access
- Bundled dependencies not analyzed or produced no detections
Reviewed 2026-04-21; recommended action: no action; model confidence 75%.
Open VSX version history
Risk trend by version
4 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
ZenStack Language Tools
ZenStack
zenstack
zenstack
ZenStack V3 Language Tools
ZenStack Modeling Tools
ZenStack V2 Language Tools
ZenStack Modeling Tools
quark-lang
quarkproject
jcl-check-support
BroadcomMFD