Meta VR
Score-based assessment (low risk, 38/100). Last analyst review covers version 1.0.2.
Analysis record
- Analysed
- 3 months ago
- Version
- v1.3.2
- Artifact
- SHA256 E1B…F16
- Source
- Findings (non-IoC)
Network indicator detail is shown below
1,608 aggregate findings were counted. 1,608 network indicators contributed to the aggregate finding count.
Network Indicators
Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.
Network indicators are queued for lazy loading
Scroll this section into view to load the detailed rows.
Publisher Evidence
LowMeta
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
12 evidence rows available.
Finding Categories
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality strong.
This extension is developed and published by Meta to support Horizon OS and Quest development. Based on the description, it functions as a bridge between the local IDE and Meta's development infrastructure, bundling tools like hzdb and an MCP (Model Context Protocol) server.
The capabilities required by this extension—reading workspace files, executing child processes, and external network communication—are standard for this category of development tool. An SDK extension must spawn language servers or build tools (process execution), read source code to provide features (file access), and communicate with vendor APIs (network calls). There are no findings in the evidence bundle suggesting credential theft, unauthorized exfiltration, or supply chain typosquatting. The extension is from a verified publisher (meta) and serves a clear, legitimate purpose for VR/AR developers. While powerful, this tool is benign in the context of professional software development.
Key Reasons
- Verified official publisher (Meta)
- Clear, functional purpose (SDK/DevTools)
- Expected capabilities for an IDE SDK extension
False Positive Considerations
- Benign use of child_process for language servers/build tools
- Benign network calls to official vendor update/API endpoints
- Workspace file access is a core feature, not suspicious behavior
Reviewed 2026-04-17; recommended action: no action; model confidence 95%.
VS Code version history
Risk trend by version
5 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace