Assertive Mock API VS Code Extension
The AI review rates the findings as likely false positive, but the risk score (54/100) still counts them.
Analysis record
- Analysed
- 6 months ago
- Version
- v0.0.2
- Artifact
- SHA256 754…B7E
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
6 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| HIGH | postinstall file download File download activity detected | 3 | out/api.jsout/stubTreeView.jsout/createStubWebview.js | Risky Plugins Authors FP 30% |
| HIGH | postinstall obfuscation Code obfuscation techniques detected | 1 | out/createStubWebview.js | Risky Plugins Authors FP 20% |
| HIGH | credential env files Environment configuration file path detected | 1 | out/extension.js | Risky Plugins Authors FP 10% |
| HIGH | postinstall network communication Network communication detected | 4 | LICENSE.txtreadme.mdout/unifiedTreeView.js +1 more | Risky Plugins Authors FP 30% |
| HIGH | postinstall file manipulation File system manipulation detected | 5 | out/api.jschangelog.mdout/createStubWebview.js +2 more | Risky Plugins Authors FP 20% |
| HIGH | postinstall system command System command execution detected | 4 | extension.vsixmanifestout/createStubWebview.jsout/unifiedTreeView.js +1 more | Risky Plugins Authors FP 10% |
Network Indicators
Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.
Network indicators are queued for lazy loading
Scroll this section into view to load the detailed rows.
Publisher Evidence
Limited evidenceassertive
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
10 evidence rows available.
Finding Categories
YARA Rules Matched
6 rules(18 hits)AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality weak.
The Assertive Mock API VS Code Extension (version 0.0.2) by developer "assertive" presents no security findings in the CVEQ analysis. The findings_by_category bucket is completely empty, indicating no YARA matches, no IoC detections, and no code-smell patterns were identified.
Filesystem and Process Access Justification: A mock API extension legitimately requires read access to workspace files to parse configuration and generate mock responses. The absence of findings in the postinstall_* or child_process execution categories indicates no suspicious process spawning was detected. Mock API tools typically need to read package.json, configuration files, and source files to understand API endpoints and data structures. The empty findings bucket confirms no unjustified filesystem access patterns were identified. Extensions that download and execute code during installation would trigger postinstall_* YARA rules, which are absent here.
Credential Access Findings: No credential_* findings were detected. The extension does not show evidence of accessing .env files, .git/config, SSH keys, or cloud credentials. Mock API extensions should not require credential access for their stated purpose, and the empty findings bucket confirms no such patterns were identified. Credential theft patterns would manifest as findings in credential_* categories targeting actual secrets, which are not present.
Data Exfiltration Patterns: No findings indicate workspace file reads combined with external network calls. Extensions that exfiltrate source code would show findings in data exfiltration categories, which are absent. The extension's stated purpose as a mock API tool does not require external network communication beyond potential API endpoint mocking.
Strongest Counterargument: The extension has only 4 users and is at version 0.0.2, which could indicate a recently published extension testing malicious capabilities. Low adoption combined with early version numbers sometimes correlates with supply chain attacks. However, without any actual findings of suspicious code patterns, credential access, or exfiltration behavior, this remains speculation. The absence of findings is a stronger signal than the low adoption metrics. CVEQ's scoring system has known biases where finding counts inflate risk scores, but with zero findings, this extension does not trigger those inflation mechanisms.
Conclusion: This extension appears to be a legitimate mock API tool with no detected security concerns. The empty findings bucket suggests either the extension contains no suspicious patterns or the analysis found nothing to report. The verdict of likely_false_positive reflects that CVEQ flagged this extension for analysis but identified no actual security issues.
Key Reasons
- No security findings detected in findings_by_category
- No postinstall payload execution patterns identified
- No credential access findings targeting actual secrets
- No data exfiltration patterns detected
- Low user count (4) and early version (0.0.2) are normal for new extensions
False Positive Considerations
- Empty findings bucket indicates no suspicious patterns detected
- No YARA code-smell rules triggered
- No IoC matches on suspicious domains
- No obfuscation findings in source files
Reviewed 2026-04-22; recommended action: no action; model confidence 75%.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace