The AI review rates the findings as likely false positive, but the risk score (65/100) still counts them.
Analysis record
- Analysed
- 4 days ago
- Version
- v0.6.0
- Artifact
- SHA256 A6C…D37
- Source
- Findings (non-IoC)
Is Granite.Code safe?
Granitecode is described as a local AI coding assistant, and the package contains ONNX Runtime files such as extension/bin/napi-v3/win32/x64/onnxruntime.dll plus Tree-sitter parsers such as extension/out/tree-sitter-wasms/tree-sitter-typescript.wasm. Those components give it the code-processing and native inference capability expected from local coding help. The manifest declares no special permissions or host permissions. Network code includes extension/out/xhr-sync-worker.js and the endpoint 001.test.code-builder-stg.platform.salesforce.com, so the extension can make requests even though the supplied manifest lists no declared host permissions.
The finding OBFUSCATION-NATIVE_BINARY_ADDON-extension/bin/napi-v3/win32/x64/onnxruntime_binding.node-0 identifies a native add-on, while OBFUSCATION-LARGE_WASM_FILE-extension/out/tree-sitter-wasms/tree-sitter-bash.wasm-0 identifies a parser module. If those findings represented harmful code, they would deserve close attention, yet their file names match the local model and language parsing functions. No supplied finding names .env, .ssh, cloud credentials, secret storage, malware, or tool poisoning.
The scanner also extracted many unrelated-looking domains, including 0-i.top and 123website.be, but no listed endpoint has a paired finding showing source or credential upload. The code-shape findings in extension/gui/assets/index.js and extension/out/index.js are consistent with bundled application code. The available findings therefore describe a powerful coding tool and scanner noise around its packaged native and web assets, rather than a demonstrated attack.
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
39 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| LOW | NoUseEval | 2 | out/index.js.mapout/index.js | - |
| LOW | postinstall file download | 21 | textmate-syntaxes/TypeScript.tmLanguage.jsongui/assets/indexSetupGranite.jsgui/assets/chunk-6OLS64BW.js +18 more | - |
| LOW | NoUseWeakRandom | 9 | gui/assets/architectureDiagram-NQ2NVSRB.jsgui/assets/handlebars.jsgui/assets/mindmap-definition-CZNETY7S.js +6 more | - |
| LOW | credential git credentials | 3 | out/index.js.mapgui/assets/index.jsout/index.js | - |
| LOW | HavingAPermissiveCrossOriginResourceSharingPolicy | 1 | out/index.js | - |
| LOW | UntrustedContentShouldNotBeIncluded | 1 | out/index.js | - |
| LOW | credential gcp credentials | 2 | out/index.js.mapout/index.js | - |
| LOW | SQLInjection | 3 | out/index.js.mapgui/assets/index.jsout/index.js | - |
| LOW | credential generic tokens | 2 | out/index.jsout/index.js.map | - |
| LOW | ServerHostnameNotVerified | 2 | out/index.jsout/index.js.map | - |
| LOW | LocalStorageShouldNotBeUsed | 3 | gui/assets/index.jsout/index.js.mapout/index.js | - |
| LOW | DebuggerStatementsShouldNotBeUsed | 11 | out/index.jstextmate-syntaxes/coffeescript.jsontextmate-syntaxes/TypeScriptReact.tmLanguage.json +8 more | - |
| LOW | credential aws profile | 2 | out/index.jsout/index.js.map | - |
| LOW | UsingCommandLineArguments | 2 | out/index.jsout/index.js.map | - |
| LOW | PostgresqlHardCodedCredentialsSecuritySensitive | 1 | out/index.js.map | - |
| LOW | postinstall obfuscation | 31 | textmate-syntaxes/JavaScript.tmLanguage.jsongui/assets/journeyDiagram-EWQZEKCU.jsgui/assets/c4Diagram-6F6E4RAY.js +28 more | - |
| LOW | postinstall system command | 66 | gui/assets/index.csstextmate-syntaxes/JavaScript.tmLanguage.jsonout/tree-sitter-wasms/tree-sitter-c.wasm +63 more | - |
| LOW | credential postgres credentials | 2 | out/index.jsout/index.js.map | - |
| LOW | CreatingCookiesWithoutTheSecureFlag | 2 | out/index.js.mapout/index.js | - |
| LOW | UsingShellInterpreterWhenExecutingOSCommands | 2 | out/index.js.mapout/index.js | - |
| LOW | OriginsNotVerified | 3 | out/index.js.mapgui/assets/indexConsole.jsout/index.js | - |
| LOW | postinstall crypto operations | 46 | gui/assets/xychartDiagram-H2YORKM3.jsgui/assets/gitGraphDiagram-GW3U2K7C.jstextmate-syntaxes/Shell-Unix-Bash.tmLanguage.json +43 more | - |
| LOW | credential steam data | 2 | out/index.js.mapout/index.js | - |
| LOW | credential aws credentials | 2 | out/index.js.mapout/index.js | - |
| LOW | postinstall network communication | 30 | textmate-syntaxes/MagicPython.tmLanguage.jsonout/xhr-sync-worker.jsgui/assets/dagre-FFZHY6LT.js +27 more | - |
| LOW | postinstall file manipulation | 56 | gui/assets/timeline-definition-RI47OAVP.jsgui/assets/treemap-FKARHQ26.jsout/tree-sitter-wasms/tree-sitter-yaml.wasm +53 more | - |
| LOW | postinstall registry modification | 5 | out/index.js.mapgui/assets/index.jstextmate-syntaxes/lua.json +2 more | - |
| LOW | DisablingStrictHTTPNoReferrerPolicy | 1 | out/index.js.map | - |
| LOW | NoUseSocketManually | 2 | out/index.js.mapout/index.js | - |
| LOW | postinstall environment access | 33 | gui/assets/diagram-ZTM2IBQH.jsgui/assets/journeyDiagram-EWQZEKCU.jsgui/assets/c4Diagram-6F6E4RAY.js +30 more | - |
| LOW | credential macos keychain | 2 | out/index.js.mapout/index.js | - |
| LOW | postinstall persistence mechanism | 10 | textmate-syntaxes/Handlebars.jsonout/index.js.maptextmate-syntaxes/ASPVBnet.plist +7 more | - |
| LOW | credential env files | 5 | textmate-syntaxes/Ruby.plistgui/assets/index.jsout/index.js.map +2 more | - |
| LOW | CreatingCookiesWithoutTheHttpOnlyFlag | 2 | out/index.js.mapout/index.js | - |
| LOW | NoDisableSanitizeHtml | 2 | out/index.jsout/index.js.map | - |
| LOW | APT1 WEBC2 Y21K | 2 | out/index.js.mapout/index.js | - |
| LOW | RedirectToUnknownPath | 2 | out/index.js.mapout/index.js | - |
| LOW | WeakSSLTLSProtocolsShouldNotBeUsed | 2 | out/index.js.mapout/index.js | - |
| LOW | ServerCertificatesNotVerified | 2 | out/index.js.mapout/index.js | - |
Publisher Evidence
Lowredhat
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
12 evidence rows available.
Finding Categories
YARA Rules Matched
39 rules(377 hits)AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality strong.
The filesystem and process access implied by this package is consistent with a local coding assistant. The native files extension/bin/napi-v3/win32/x64/onnxruntime.dll, extension/bin/napi-v3/win32/x64/onnxruntime_binding.node, and extension/bin/napi-v3/win32/x64/onnxruntime_providers_shared.dll are ONNX Runtime components, which fit local model inference. The parser files extension/out/tree-sitter-wasms/tree-sitter-typescript.wasm, extension/out/tree-sitter-wasms/tree-sitter-bash.wasm, and extension/out/tree-sitter-wasms/tree-sitter-python.wasm would support source parsing across languages. Those files explain why the extension needs access to workspace code and may start native or WebAssembly components. The supplied manifest data lists no permissions or host permissions, and no finding names a postinstall action, command execution, or destructive file write.
The network findings also fit the packaged user interface and local service plumbing. NET-XMLHTTPREQUEST-extension/out/xhr-sync-worker.js-9 identifies XMLHttpRequest use in an XHR worker, while NET-SOCKET_IO-extension/gui/assets/cytoscape.esm.js-8 identifies Socket.IO-related code inside a graph UI dependency. The listed endpoint 001.test.code-builder-stg.platform.salesforce.com is a staging-style development hostname. The other listed domains, including 0-i.top, 001www.com, and 123website.be, are endpoint-extractor results without a matching data-flow finding or a file path showing secret or source-code upload. Domain extraction alone does not establish exfiltration.
Credential access is absent from the supplied findings. No finding names .env, .ssh, cloud credential files, VS Code secret storage, or a credential provider. The native ONNX files named by OBFUSCATION-NATIVE_BINARY_ADDON-extension/bin/napi-v3/win32/x64/onnxruntime.dll-0 and OBFUSCATION-NATIVE_BINARY_ADDON-extension/bin/napi-v3/win32/x64/onnxruntime_binding.node-0 describe binary format characteristics, not secret collection. The JavaScript findings OBFUSCATION-UNICODE_HEAVY-extension/gui/assets/index.js-420 and OBFUSCATION-HEX_STRING_HEAVY-extension/out/index.js-247977 concern bundled output, where generated or minified code commonly triggers scanner rules. The large WASM findings for extension/out/tree-sitter-wasms/tree-sitter-ruby.wasm and extension/out/tree-sitter-wasms/tree-sitter-swift.wasm likewise fit parser assets.
The strongest counterargument is that native binaries and network code give an extension meaningful power. extension/bin/napi-v3/win32/x64/onnxruntime_binding.node can run native inference, and extension/out/xhr-sync-worker.js can make network requests. That concern does not change the conclusion because the supplied results contain zero malware-signature findings, zero secret findings, and zero tool-poisoning findings, while the named binaries and parser assets match the stated local-AI coding function. Runtime inspection would still be needed to verify what data the XHR worker sends, since the endpoint list alone does not show request contents.
Key Reasons
extension/bin/napi-v3/win32/x64/onnxruntime.dllandextension/bin/napi-v3/win32/x64/onnxruntime_binding.nodematch local AI inference components.extension/out/tree-sitter-wasms/tree-sitter-typescript.wasmand related parser files match source-code analysis.NET-XMLHTTPREQUEST-extension/out/xhr-sync-worker.js-9shows network capability without a paired exfiltration or credential finding.- No supplied finding names secrets, malware signatures, tool poisoning, or postinstall execution.
False Positive Considerations
- Native binary detection on
extension/bin/napi-v3/win32/x64/onnxruntime.dlland related ONNX files. - Large WASM detection on
extension/out/tree-sitter-wasms/*.wasmparser assets. - Unicode and hex-pattern detections in bundled files such as
extension/gui/assets/index.jsandextension/out/index.js. - IoC extraction from generic or unrelated domains such as
0-i.topand123website.be.
Reviewed 2026-09-29; recommended action: suppress false positive; model confidence 88%.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace