GitHub Pull Requests
The AI review rates the findings as likely false positive, but the risk score (42/100) still counts them.
Analysis record
- Analysed
- 1 weeks ago
- Version
- v0.166.1
- Artifact
- SHA256 898…249
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
13 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| LOW | DebuggerStatementsShouldNotBeUsed | 1 | eslint.config.mjs | - |
| LOW | NoUseWeakRandom | 5 | dist/webview-pr-description.jsdist/browser/extension.jsdist/extension.js +2 more | - |
| LOW | postinstall file download | 13 | eslint.config.mjspackage.jsonpackage.nls.json +10 more | - |
| LOW | credential git credentials | 1 | changelog.md | - |
| LOW | SQLInjection | 2 | dist/webview-open-pr-view.jsdist/webview-pr-description.js | - |
| LOW | postinstall crypto operations | 10 | dist/webview-create-pr-view-new.jsresources/emojis.jsondist/webview-open-pr-view.js +7 more | - |
| LOW | postinstall file manipulation | 10 | dist/webview-create-pr-view-new.jspackage.nls.jsondist/webview-pr-description.js +7 more | - |
| LOW | postinstall system command | 12 | dist/webview-pr-description.jsdist/webview-create-pr-view-new.jspackage.nls.json +9 more | - |
| LOW | postinstall registry modification | 2 | dist/browser/extension.jsdist/extension.js | - |
| LOW | postinstall obfuscation | 9 | dist/webview-create-pr-view-new.jsdist/webview-pr-description.jsdist/webview-open-pr-view.js +6 more | - |
| LOW | postinstall network communication | 8 | LICENSE.txtchangelog.mdpackage.json +5 more | - |
| LOW | credential env files | 2 | dist/browser/extension.jsdist/extension.js | - |
| LOW | postinstall persistence mechanism | 5 | dist/browser/extension.jsdist/extension.jschangelog.md +2 more | - |
Publisher Evidence
LowGitHub
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
12 evidence rows available.
Finding Categories
YARA Rules Matched
13 rules(80 hits)AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality strong.
The GitHub Pull Requests extension (version 0.144.0) is published by GitHub itself and has over 5.7 million users, indicating it is a legitimate, widely-trusted development tool. The extension's stated purpose is to provide Pull Request and Issue integration for GitHub repositories within the IDE environment.
Filesystem and Process Access Justification
The evidence bundle contains no findings related to filesystem access, process execution, or network behavior. All 29 findings in this bundle are dependency declarations extracted from the package.json file located at /tmp/extract-c9358907d2d3a3a70989e264b362a66b8b4f31f718115902dec2a513ec64c372-3331917101/extension/package.json. These dependencies include legitimate libraries such as @octokit/[email protected] (GitHub's official REST API client), @vscode/codicons@^0.0.36 (VS Code icon library), and marked@^4.0.10 (Markdown parser). These are standard dependencies for a GitHub integration extension and do not indicate any suspicious behavior. A pull request extension legitimately needs to read workspace files to display code changes, diff information, and related files from the repository.
Credential Access Findings
The findings summary explicitly shows zero findings in the secret category ("secret":"0"). There are no credential-access findings in this bundle. The extension does not have any findings that target .env files, .ssh directories, cloud credentials, or VS Code's secret storage. The dependency @octokit/rest is used for authenticating with GitHub's API through GitHub's official authentication mechanisms, which is expected behavior for this extension.
Strongest Counterargument
The strongest counterargument to this verdict is the presence of 29 findings in the bundle. However, all 29 findings are classified as dependency type with severity: low, and the findings summary confirms there are zero findings in categories that matter for security: "ioc":"0","malware-signature":"0","malware":"0","obfuscation":"0","code-smell":"0","tool-poisoning":"0". Dependency declarations in package.json are normal for any Node.js-based extension and do not constitute security concerns. The extension is published by GitHub (verified publisher), has millions of users, and contains no actual security findings beyond standard npm dependency listings.
This extension represents expected IDE behavior with no malicious indicators.
Key Reasons
- All 29 findings are low-severity dependency declarations, not security issues
- Zero findings in malware, IoC, obfuscation, secret, or code-smell categories
- Extension published by verified GitHub publisher with 5.7M+ users
- Dependencies like @octokit/rest are legitimate for GitHub PR integration
False Positive Considerations
- Dependency findings from package.json are normal for Node.js extensions
- No actual security findings beyond standard npm declarations
- High finding count is noise from bundled dependencies
Reviewed 2026-05-23; recommended action: no action; model confidence 95%.
Open VSX version history
Risk trend by version
16 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace