Go
The AI review rates the findings as likely false positive, but the risk score (44/100) still counts them.
Analysis record
- Analysed
- 1 months ago
- Version
- v0.57.2
- Artifact
- SHA256 F72…5D4
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
Publisher Evidence
LowGo Team at Google
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
12 evidence rows available.
Finding Categories
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality strong.
This is the official Go language extension for Visual Studio Code, published by the "golang" developer account with over 18 million users. The extension's stated purpose is providing "Rich Go language support" including language server features, debugging, and code intelligence—capabilities that legitimately require filesystem access and process execution.
The filesystem and process access patterns are fully justified by the extension's purpose. The dependency findings in /tmp/extract-b206452378968a879cbe1d396d3bd3fe0254d3311fefd3f5c6ceafcc69014d65-3809919923/extension/package.json list standard VS Code extension packages: [email protected], [email protected], [email protected], and [email protected]. These are official Microsoft packages required for language server protocol implementation and debugger integration. Additional dependencies like [email protected], [email protected], and [email protected] are common utility packages used for file pattern matching, version comparison, and HTTP requests—standard operations for any language tooling extension.
The single network finding, NET-WEBSOCKET-extension/dist/debugAdapter.js-13576, represents a websocket connection in the debug adapter. This is expected behavior for a debugger extension. The Go debugger must communicate with the debug adapter protocol server to provide breakpoints, variable inspection, and step-through debugging. The websocket call originates from extension/dist/debugAdapter.js, which is the compiled debug adapter binary—a normal component of any VS Code debugger extension.
No credential-access findings target actual secrets. The findings summary shows zero secret-related detections, zero credential-access patterns, and zero findings related to .env files, SSH keys, cloud credentials, or VS Code secret storage. The extension does not request or access any sensitive configuration files beyond what is necessary for Go tooling.
The strongest counterargument to this verdict would be the presence of any network communication or bundled code in the dist/ directory. However, the websocket finding in debugAdapter.js is documented debugger behavior, not exfiltration. Bundled JavaScript in dist/ directories is standard build output from webpack or similar tools, not intentional obfuscation. With zero malware signatures, zero IoC matches, zero obfuscation findings, and zero code-smell detections, there is no evidence of malicious intent.
This extension represents the baseline for legitimate IDE tooling: a language server that reads source files to provide IntelliSense, spawns Go compiler processes for compilation, and communicates with debug adapters for debugging. All findings align with expected behavior for this class of extension.
Key Reasons
- Official extension from verified golang publisher with 18M+ users
- Zero malware signatures or IoC findings
- All dependencies are standard VS Code language server packages
- Network finding is expected debugger websocket communication
- No credential access or secret-related findings
False Positive Considerations
- Dependency scanning on standard VS Code packages
- Network finding from legitimate debugger websocket communication
- Bundled dist/ files containing standard build output
Reviewed 2026-05-23; recommended action: no action; model confidence 92%.
VS Code version history
Risk trend by version
4 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace