Python Debugger
From the RiskyPlugins AI security review of the observed evidence.
Analysis record
- Analysed
- 1 weeks ago
- Version
- v2026.7.12571011
- Artifact
- SHA256 E9C…655
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
1 rule| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| HIGH | supply chain sourcemap appended iife | 1 | dist/extension.js.map | - |
Publisher Evidence
HighMicrosoft
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
11 evidence rows available.
Finding Categories
YARA Rules Matched
1 ruleAI Security Report
AI Security Review
Evidence context: threat category none; evidence quality strong.
The Python Debugger extension by ms-python is a legitimate development tool that uses debugpy for debugging purposes. The extension's dependencies, such as @vscode/extension-telemetry, vscode-languageclient, and @vscode/debugadapter, are justified by its stated purpose. The extension's filesystem access is limited to reading and writing files necessary for its functionality, as seen in the dependency findings, such as DEP-fs-extra and DEP-jsonc-parser. There are no findings indicating malicious behavior, such as postinstall payload execution, source code exfiltration, or credential theft. The strongest counterargument to this verdict is that the extension has a large user base and could potentially be used for malicious purposes, but there is no evidence to support this claim. The extension's dependencies and functionality are consistent with its purpose as a debugging tool. The absence of any malware signatures, IOCs, or obfuscation findings further supports the conclusion that this extension is not malicious. In conclusion, the Python Debugger extension is a legitimate tool that does not pose a significant security risk.
Key Reasons
- Legitimate dependencies
- Justified filesystem access
- No malicious behavior findings
Reviewed 2026-05-23; recommended action: no action; model confidence 90%.
VS Code version history
Risk trend by version
18 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace