OpenVSX Registry Verified

Granite.Code

by redhat
cbb45e6a-e78b-5c8e-a74a-7ad074b84fe6 | v0.6.0
65/ 100
MEDIUM risk
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (65/100) still counts them.

Analysis record

Analysed
4 days ago
Version
v0.6.0
Artifact
SHA256 A6C…D37
Source
Findings (non-IoC)

Is Granite.Code safe?

Granitecode is described as a local AI coding assistant, and the package contains ONNX Runtime files such as extension/bin/napi-v3/win32/x64/onnxruntime.dll plus Tree-sitter parsers such as extension/out/tree-sitter-wasms/tree-sitter-typescript.wasm. Those components give it the code-processing and native inference capability expected from local coding help. The manifest declares no special permissions or host permissions. Network code includes extension/out/xhr-sync-worker.js and the endpoint 001.test.code-builder-stg.platform.salesforce.com, so the extension can make requests even though the supplied manifest lists no declared host permissions.

The finding OBFUSCATION-NATIVE_BINARY_ADDON-extension/bin/napi-v3/win32/x64/onnxruntime_binding.node-0 identifies a native add-on, while OBFUSCATION-LARGE_WASM_FILE-extension/out/tree-sitter-wasms/tree-sitter-bash.wasm-0 identifies a parser module. If those findings represented harmful code, they would deserve close attention, yet their file names match the local model and language parsing functions. No supplied finding names .env, .ssh, cloud credentials, secret storage, malware, or tool poisoning.

The scanner also extracted many unrelated-looking domains, including 0-i.top and 123website.be, but no listed endpoint has a paired finding showing source or credential upload. The code-shape findings in extension/gui/assets/index.js and extension/out/index.js are consistent with bundled application code. The available findings therefore describe a powerful coding tool and scanner noise around its packaged native and web assets, rather than a demonstrated attack.

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

410 detail rows
Showing 25 of 33 · highest severity first

YARA Rule Matches

39 rules
SeverityRuleHitsFilesMetadata
LOWNoUseEval 2
out/index.js.mapout/index.js
-
LOWpostinstall file download 21
textmate-syntaxes/TypeScript.tmLanguage.jsongui/assets/indexSetupGranite.jsgui/assets/chunk-6OLS64BW.js +18 more
-
LOWNoUseWeakRandom 9
gui/assets/architectureDiagram-NQ2NVSRB.jsgui/assets/handlebars.jsgui/assets/mindmap-definition-CZNETY7S.js +6 more
-
LOWcredential git credentials 3
out/index.js.mapgui/assets/index.jsout/index.js
-
LOWHavingAPermissiveCrossOriginResourceSharingPolicy 1
out/index.js
-
LOWUntrustedContentShouldNotBeIncluded 1
out/index.js
-
LOWcredential gcp credentials 2
out/index.js.mapout/index.js
-
LOWSQLInjection 3
out/index.js.mapgui/assets/index.jsout/index.js
-
LOWcredential generic tokens 2
out/index.jsout/index.js.map
-
LOWServerHostnameNotVerified 2
out/index.jsout/index.js.map
-
LOWLocalStorageShouldNotBeUsed 3
gui/assets/index.jsout/index.js.mapout/index.js
-
LOWDebuggerStatementsShouldNotBeUsed 11
out/index.jstextmate-syntaxes/coffeescript.jsontextmate-syntaxes/TypeScriptReact.tmLanguage.json +8 more
-
LOWcredential aws profile 2
out/index.jsout/index.js.map
-
LOWUsingCommandLineArguments 2
out/index.jsout/index.js.map
-
LOWPostgresqlHardCodedCredentialsSecuritySensitive 1
out/index.js.map
-
LOWpostinstall obfuscation 31
textmate-syntaxes/JavaScript.tmLanguage.jsongui/assets/journeyDiagram-EWQZEKCU.jsgui/assets/c4Diagram-6F6E4RAY.js +28 more
-
LOWpostinstall system command 66
gui/assets/index.csstextmate-syntaxes/JavaScript.tmLanguage.jsonout/tree-sitter-wasms/tree-sitter-c.wasm +63 more
-
LOWcredential postgres credentials 2
out/index.jsout/index.js.map
-
LOWCreatingCookiesWithoutTheSecureFlag 2
out/index.js.mapout/index.js
-
LOWUsingShellInterpreterWhenExecutingOSCommands 2
out/index.js.mapout/index.js
-
LOWOriginsNotVerified 3
out/index.js.mapgui/assets/indexConsole.jsout/index.js
-
LOWpostinstall crypto operations 46
gui/assets/xychartDiagram-H2YORKM3.jsgui/assets/gitGraphDiagram-GW3U2K7C.jstextmate-syntaxes/Shell-Unix-Bash.tmLanguage.json +43 more
-
LOWcredential steam data 2
out/index.js.mapout/index.js
-
LOWcredential aws credentials 2
out/index.js.mapout/index.js
-
LOWpostinstall network communication 30
textmate-syntaxes/MagicPython.tmLanguage.jsonout/xhr-sync-worker.jsgui/assets/dagre-FFZHY6LT.js +27 more
-
LOWpostinstall file manipulation 56
gui/assets/timeline-definition-RI47OAVP.jsgui/assets/treemap-FKARHQ26.jsout/tree-sitter-wasms/tree-sitter-yaml.wasm +53 more
-
LOWpostinstall registry modification 5
out/index.js.mapgui/assets/index.jstextmate-syntaxes/lua.json +2 more
-
LOWDisablingStrictHTTPNoReferrerPolicy 1
out/index.js.map
-
LOWNoUseSocketManually 2
out/index.js.mapout/index.js
-
LOWpostinstall environment access 33
gui/assets/diagram-ZTM2IBQH.jsgui/assets/journeyDiagram-EWQZEKCU.jsgui/assets/c4Diagram-6F6E4RAY.js +30 more
-
LOWcredential macos keychain 2
out/index.js.mapout/index.js
-
LOWpostinstall persistence mechanism 10
textmate-syntaxes/Handlebars.jsonout/index.js.maptextmate-syntaxes/ASPVBnet.plist +7 more
-
LOWcredential env files 5
textmate-syntaxes/Ruby.plistgui/assets/index.jsout/index.js.map +2 more
-
LOWCreatingCookiesWithoutTheHttpOnlyFlag 2
out/index.js.mapout/index.js
-
LOWNoDisableSanitizeHtml 2
out/index.jsout/index.js.map
-
LOWAPT1 WEBC2 Y21K 2
out/index.js.mapout/index.js
-
LOWRedirectToUnknownPath 2
out/index.js.mapout/index.js
-
LOWWeakSSLTLSProtocolsShouldNotBeUsed 2
out/index.js.mapout/index.js
-
LOWServerCertificatesNotVerified 2
out/index.js.mapout/index.js
-

Publisher Evidence

Low

redhat

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

65
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Verified publisher
Verified
Extension portfolio
44
Portfolio

12 evidence rows available.

Finding Categories

22
Obfuscation
11
Network

YARA Rules Matched

39 rules(377 hits)
NoUseEval postinstall file download NoUseWeakRandom credential git credentials HavingAPermissiveCrossOriginResourceSharingPolicy UntrustedContentShouldNotBeIncluded credential gcp credentials SQLInjection credential generic tokens ServerHostnameNotVerified LocalStorageShouldNotBeUsed DebuggerStatementsShouldNotBeUsed credential aws profile UsingCommandLineArguments PostgresqlHardCodedCredentialsSecuritySensitive postinstall obfuscation +23 more

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

The filesystem and process access implied by this package is consistent with a local coding assistant. The native files extension/bin/napi-v3/win32/x64/onnxruntime.dll, extension/bin/napi-v3/win32/x64/onnxruntime_binding.node, and extension/bin/napi-v3/win32/x64/onnxruntime_providers_shared.dll are ONNX Runtime components, which fit local model inference. The parser files extension/out/tree-sitter-wasms/tree-sitter-typescript.wasm, extension/out/tree-sitter-wasms/tree-sitter-bash.wasm, and extension/out/tree-sitter-wasms/tree-sitter-python.wasm would support source parsing across languages. Those files explain why the extension needs access to workspace code and may start native or WebAssembly components. The supplied manifest data lists no permissions or host permissions, and no finding names a postinstall action, command execution, or destructive file write.

The network findings also fit the packaged user interface and local service plumbing. NET-XMLHTTPREQUEST-extension/out/xhr-sync-worker.js-9 identifies XMLHttpRequest use in an XHR worker, while NET-SOCKET_IO-extension/gui/assets/cytoscape.esm.js-8 identifies Socket.IO-related code inside a graph UI dependency. The listed endpoint 001.test.code-builder-stg.platform.salesforce.com is a staging-style development hostname. The other listed domains, including 0-i.top, 001www.com, and 123website.be, are endpoint-extractor results without a matching data-flow finding or a file path showing secret or source-code upload. Domain extraction alone does not establish exfiltration.

Credential access is absent from the supplied findings. No finding names .env, .ssh, cloud credential files, VS Code secret storage, or a credential provider. The native ONNX files named by OBFUSCATION-NATIVE_BINARY_ADDON-extension/bin/napi-v3/win32/x64/onnxruntime.dll-0 and OBFUSCATION-NATIVE_BINARY_ADDON-extension/bin/napi-v3/win32/x64/onnxruntime_binding.node-0 describe binary format characteristics, not secret collection. The JavaScript findings OBFUSCATION-UNICODE_HEAVY-extension/gui/assets/index.js-420 and OBFUSCATION-HEX_STRING_HEAVY-extension/out/index.js-247977 concern bundled output, where generated or minified code commonly triggers scanner rules. The large WASM findings for extension/out/tree-sitter-wasms/tree-sitter-ruby.wasm and extension/out/tree-sitter-wasms/tree-sitter-swift.wasm likewise fit parser assets.

The strongest counterargument is that native binaries and network code give an extension meaningful power. extension/bin/napi-v3/win32/x64/onnxruntime_binding.node can run native inference, and extension/out/xhr-sync-worker.js can make network requests. That concern does not change the conclusion because the supplied results contain zero malware-signature findings, zero secret findings, and zero tool-poisoning findings, while the named binaries and parser assets match the stated local-AI coding function. Runtime inspection would still be needed to verify what data the XHR worker sends, since the endpoint list alone does not show request contents.

Key Reasons

  • extension/bin/napi-v3/win32/x64/onnxruntime.dll and extension/bin/napi-v3/win32/x64/onnxruntime_binding.node match local AI inference components.
  • extension/out/tree-sitter-wasms/tree-sitter-typescript.wasm and related parser files match source-code analysis.
  • NET-XMLHTTPREQUEST-extension/out/xhr-sync-worker.js-9 shows network capability without a paired exfiltration or credential finding.
  • No supplied finding names secrets, malware signatures, tool poisoning, or postinstall execution.

False Positive Considerations

  • Native binary detection on extension/bin/napi-v3/win32/x64/onnxruntime.dll and related ONNX files.
  • Large WASM detection on extension/out/tree-sitter-wasms/*.wasm parser assets.
  • Unicode and hex-pattern detections in bundled files such as extension/gui/assets/index.js and extension/out/index.js.
  • IoC extraction from generic or unrelated domains such as 0-i.top and 123website.be.

Reviewed 2026-09-29; recommended action: suppress false positive; model confidence 88%.

About This Extension

Open-source coding assistant with local AI

Frequently Asked Questions