VS Code Marketplace

Assertive Mock API VS Code Extension

by assertive · 9 users
d058edc5-3394-50ae-a1c0-34fc23f31660 | v0.0.2
54/ 100
MEDIUM risk
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (54/100) still counts them.

Analysis record

Analysed
6 months ago
Version
v0.0.2
Artifact
SHA256 754…B7E
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

25 detail rows

YARA Rule Matches

6 rules
SeverityRuleHitsFilesMetadata
HIGHpostinstall file download

File download activity detected

3
out/api.jsout/stubTreeView.jsout/createStubWebview.js
Risky Plugins Authors FP 30%
HIGHpostinstall obfuscation

Code obfuscation techniques detected

1
out/createStubWebview.js
Risky Plugins Authors FP 20%
HIGHcredential env files

Environment configuration file path detected

1
out/extension.js
Risky Plugins Authors FP 10%
HIGHpostinstall network communication

Network communication detected

4
LICENSE.txtreadme.mdout/unifiedTreeView.js +1 more
Risky Plugins Authors FP 30%
HIGHpostinstall file manipulation

File system manipulation detected

5
out/api.jschangelog.mdout/createStubWebview.js +2 more
Risky Plugins Authors FP 20%
HIGHpostinstall system command

System command execution detected

4
extension.vsixmanifestout/createStubWebview.jsout/unifiedTreeView.js +1 more
Risky Plugins Authors FP 10%

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

29 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Publisher Evidence

Limited evidence

assertive

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

24
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Not exposed
Not exposed
Extension portfolio
Unknown
Portfolio

10 evidence rows available.

Finding Categories

18
Malware Signatures
7
Network
29
IoC Indicators

YARA Rules Matched

6 rules(18 hits)
postinstall file download postinstall obfuscation credential env files postinstall network communication postinstall file manipulation postinstall system command

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality weak.

The Assertive Mock API VS Code Extension (version 0.0.2) by developer "assertive" presents no security findings in the CVEQ analysis. The findings_by_category bucket is completely empty, indicating no YARA matches, no IoC detections, and no code-smell patterns were identified.

Filesystem and Process Access Justification: A mock API extension legitimately requires read access to workspace files to parse configuration and generate mock responses. The absence of findings in the postinstall_* or child_process execution categories indicates no suspicious process spawning was detected. Mock API tools typically need to read package.json, configuration files, and source files to understand API endpoints and data structures. The empty findings bucket confirms no unjustified filesystem access patterns were identified. Extensions that download and execute code during installation would trigger postinstall_* YARA rules, which are absent here.

Credential Access Findings: No credential_* findings were detected. The extension does not show evidence of accessing .env files, .git/config, SSH keys, or cloud credentials. Mock API extensions should not require credential access for their stated purpose, and the empty findings bucket confirms no such patterns were identified. Credential theft patterns would manifest as findings in credential_* categories targeting actual secrets, which are not present.

Data Exfiltration Patterns: No findings indicate workspace file reads combined with external network calls. Extensions that exfiltrate source code would show findings in data exfiltration categories, which are absent. The extension's stated purpose as a mock API tool does not require external network communication beyond potential API endpoint mocking.

Strongest Counterargument: The extension has only 4 users and is at version 0.0.2, which could indicate a recently published extension testing malicious capabilities. Low adoption combined with early version numbers sometimes correlates with supply chain attacks. However, without any actual findings of suspicious code patterns, credential access, or exfiltration behavior, this remains speculation. The absence of findings is a stronger signal than the low adoption metrics. CVEQ's scoring system has known biases where finding counts inflate risk scores, but with zero findings, this extension does not trigger those inflation mechanisms.

Conclusion: This extension appears to be a legitimate mock API tool with no detected security concerns. The empty findings bucket suggests either the extension contains no suspicious patterns or the analysis found nothing to report. The verdict of likely_false_positive reflects that CVEQ flagged this extension for analysis but identified no actual security issues.

Key Reasons

  • No security findings detected in findings_by_category
  • No postinstall payload execution patterns identified
  • No credential access findings targeting actual secrets
  • No data exfiltration patterns detected
  • Low user count (4) and early version (0.0.2) are normal for new extensions

False Positive Considerations

  • Empty findings bucket indicates no suspicious patterns detected
  • No YARA code-smell rules triggered
  • No IoC matches on suspicious domains
  • No obfuscation findings in source files

Reviewed 2026-04-22; recommended action: no action; model confidence 75%.

About This Extension

A VS Code extension for the Assertive Mock API

Frequently Asked Questions