The AI review rates the findings as likely false positive, but the risk score (42/100) still counts them.
Analysis record
- Analysed
- 2 weeks ago
- Version
- v2.5.1
- Artifact
- SHA256 624…1AB
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
9 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| LOW | credential env files | 1 | out/extension.js | - |
| LOW | credential vscode credentials | 1 | readme.md | - |
| LOW | postinstall crypto operations | 1 | out/extension.js | - |
| LOW | postinstall file manipulation | 2 | readme.mdout/extension.js | - |
| LOW | postinstall obfuscation | 1 | out/extension.js | - |
| LOW | postinstall network communication | 3 | out/extension.jsreadme/demo.gifLICENSE.txt | - |
| LOW | postinstall system command | 5 | extension.vsixmanifest[Content_Types].xmlreadme.md +2 more | - |
| LOW | UsingShellInterpreterWhenExecutingOSCommands | 1 | out/extension.js | - |
| LOW | NoUseWeakRandom | 1 | out/extension.js | - |
Publisher Evidence
Lowmeta
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
12 evidence rows available.
Finding Categories
YARA Rules Matched
9 rules(16 hits)AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality moderate.
Security Analysis: Relay GraphQL Extension
Filesystem and Process Access Justification
The evidence bundle contains zero findings related to filesystem access, process execution, or manifest analysis. The findings_summary shows "manifest-analysis":"0" and "network":"0", indicating no suspicious file system or process patterns were detected. Relay GraphQL is a legitimate GraphQL framework from Meta (Facebook), and IDE extensions for GraphQL tools legitimately need to read source files for code completion and schema validation. The absence of manifest-analysis findings means the extension's declared permissions align with its stated purpose.
Credential Access Assessment
The findings_summary explicitly shows "secret":"0" - zero credential-related findings. There are no detections of .env file access, SSH key reads, cloud credential access, or VS Code secret storage interactions. This is consistent with a GraphQL client extension that does not need to access developer credentials. The extension's purpose (GraphQL query support) does not require credential access, and the analysis confirms no such patterns exist.
Strongest Counterargument
The strongest argument against this verdict is the 690 medium-severity IoC findings in the findings_summary. However, examining the actual IoC entries reveals they are all XIOC false positives - property access chains from minified JavaScript misidentified as domains:
tm.textdocumentfilter.isandtm.notebookcelltextdocumentfilter.isare VS Code API property access patterns, not domainsy.documenthighlightkind.readandw.symbolkind.propertyare TypeScript enum property chainsd.data,f.target,c.dataare minified variable property accessesem.diagnosticcode.isandy.codedescription.isare property access patterns
These findings all have file_path: "extracted_from_files" rather than specific source files, indicating they were extracted from bundled/minified code. The XIOC extractor is documented to produce massive false-positive volumes on property access chains. Combined with zero malware-signature findings, zero network findings, and zero obfuscation findings, the 690 IoC detections represent extraction noise, not actual malicious indicators.
Conclusion
Relay GraphQL from Meta is a legitimate GraphQL framework extension. All 690 IoC findings are well-documented XIOC false positives from minified JavaScript property access patterns. No actual malicious behavior, credential theft, or suspicious network activity was detected.
Key Reasons
- All 690 IoC findings are XIOC false positives from property access chains
- Zero malware-signature, network, or secret findings
- From legitimate publisher Meta (Relay GraphQL framework)
- No credential theft or exfiltration patterns detected
False Positive Considerations
- XIOC property access chains misread as domains (tm.textdocumentfilter.is, y.documenthighlightkind.read)
- Minified JavaScript property access patterns (d.data, f.target, c.data)
- VS Code API patterns misidentified as IoCs
- High IoC count from bundled code extraction noise
Reviewed 2026-05-07; recommended action: suppress false positive; model confidence 85%.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace