Google Cloud Data Agent Kit
The AI review rates the findings as likely false positive, but the risk score (86/100) still counts them.
Analysis record
- Analysed
- 1 weeks ago
- Version
- v0.11.0
- Artifact
- SHA256 F88…65E
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
22 rules| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| LOW | DebuggerStatementsShouldNotBeUsed | 3 | webview/app_bundle.jsdatacloud_vscode.jsdataproc/notebook_renderers/sparkmonitor_renderer.js | - |
| LOW | UsingCommandLineArguments | 1 | mcp_servers/cli/mcp_proxy_bundle.js | - |
| LOW | postinstall file download | 50 | antigravity/skills/gcp-managed-airflow-recommendations/scripts/workload_memory_usage.pyantigravity/skills/gcp-managed-airflow-migrations/references/environment-inspection.mdantigravity/skills/gcs-security-assessment/scripts/preflight_permissions.py +47 more | - |
| LOW | HavingAPermissiveCrossOriginResourceSharingPolicy | 1 | antigravity/skills/building-data-apps/examples/express_chat.ts | - |
| LOW | credential gcp credentials | 3 | datacloud_vscode.jsantigravity/skills/google-cloud-storage-basics/references/mcp-usage.mdmcp_servers/cli/mcp_proxy_bundle.js | - |
| LOW | NoUseEval | 3 | sql_editor/exthost/bigquery/server_bin.cjsdataproc/notebook_renderers/sparkmonitor_renderer.jsdatacloud_vscode.js | - |
| LOW | SQLInjection | 3 | datacloud_vscode.jswebview/app_bundle.jsdataproc/notebook_renderers/sparkmonitor_renderer.js | - |
| LOW | NoUseWeakRandom | 4 | datacloud_vscode.jswebview/app_bundle.jsdataproc/notebook_renderers/sparkmonitor_renderer.js +1 more | - |
| LOW | postinstall network communication | 55 | antigravity/skills/bigquery-ai-ml/references/ai_generate.mdmcp_servers/cli/mcp_proxy_bundle.jsxhr-sync-worker.js +52 more | - |
| LOW | postinstall system command | 97 | antigravity/skills/gcp-dataflow/references/streaming_job_health.mdantigravity/skills/gcp-spark/references/read_write_data.mdantigravity/skills/gcs-security-assessment/scripts/fetch_object_telemetry.py +94 more | - |
| LOW | UsingShellInterpreterWhenExecutingOSCommands | 3 | datacloud_vscode.jsdist/agents/hooks/telemetry_hook.jssql_editor/exthost/bigquery/server_bin.cjs | - |
| LOW | postinstall crypto operations | 36 | antigravity/skills/google-cloud-storage-basics/references/iac-usage.mdantigravity/skills/google-cloud-storage-bucket-architect/references/sdk_java.mdantigravity/skills/google-cloud-storage-bucket-architect/references/gcloud.md +33 more | - |
| LOW | CreatingCookiesWithoutTheSecureFlag | 1 | datacloud_vscode.js | - |
| LOW | postinstall file manipulation | 63 | antigravity/skills/google-cloud-storage-bucket-architect/references/sensitive_data.mdantigravity/skills/bigtable-basics/references/cli_data_access.mddist/agents/hooks/telemetry_hook.js +60 more | - |
| LOW | postinstall obfuscation | 45 | antigravity/skills/gcp-composer-troubleshooting/SKILL.mdantigravity/skills/bigquery-ai-ml/references/ai_generate_embedding.mdantigravity/skills/bigquery-ai-ml/references/ai_evaluate.md +42 more | - |
| LOW | postinstall registry modification | 8 | antigravity/skills/google-cloud-storage-basics/references/iac-usage.mdsql_editor/exthost/bigquery/server_bin.cjsdataproc/notebook_renderers/sparkmonitor_renderer.js +5 more | - |
| LOW | NoUseSocketManually | 1 | datacloud_vscode.js | - |
| LOW | postinstall environment access | 2 | bigquery/resources/declarative_pipelines_clustered_template.ymlbigquery/resources/declarative_pipelines_serverless_template.yml | - |
| LOW | credential env files | 23 | antigravity/skills/gcp-managed-airflow-migrations/SKILL.mdantigravity/skills/gcp-managed-airflow-recommendations/scripts/dag_parsing_stats.pyantigravity/skills/discovering-gcp-data-assets/SKILL.md +20 more | - |
| LOW | postinstall persistence mechanism | 13 | antigravity/skills/gcp-pipeline-resource-provisioning/references/gcp_pipeline_resource_provisioning_spec.mdCHANGELOG.mddatacloud_vscode.js +10 more | - |
| LOW | CreatingCookiesWithoutTheHttpOnlyFlag | 1 | datacloud_vscode.js | - |
| LOW | NoDisableSanitizeHtml | 1 | datacloud_vscode.js | - |
Network Indicators
Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.
Network indicators are queued for lazy loading
Scroll this section into view to load the detailed rows.
Publisher Evidence
HighGoogle Cloud
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
11 evidence rows available.
Finding Categories
YARA Rules Matched
22 rules(417 hits)AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality moderate.
Filesystem and Process Access Justification
The extension's stated purpose is to integrate Google Cloud Data Agent Kit into VS Code. Network findings in extension/dataproc/notebook_renderers/sparkmonitor_renderer.js (lines 233, 214, 148, 689) and extension/webview/app_bundle.js (lines 473, 917, 2500) show socket_io and fetch calls. These network patterns are consistent with cloud IDE extensions that must communicate with Google Cloud services for data processing and notebook rendering. The NET-FETCH-extension/datacloud_vscode.js-14937 and NET-FETCH-extension/datacloud_vscode.js-14743 findings in the main extension file indicate legitimate cloud API communication. No postinstall payload execution or unauthorized process spawning was detected.
Credential Access Findings
The findings summary shows 0 secret findings and 0 credential-related detections. The credential_* YARA rules that fire on benign config reads are classified as code-smell (150 total) and represent YARA noise per documented false-positive patterns. No findings target .env, .ssh, cloud credentials, or VS Code secret storage. The extension does not exhibit credential theft behavior.
Strongest Counterargument
The 8847 IoC findings and 0 user count could indicate a typosquatting attempt or malicious re-upload. However, the developer name GoogleCloudTools aligns with Google's official VS Code publisher naming convention. The single specific IoC (l.ie in extracted_from_files) is a legitimate domain without evidence of malicious use. The 8847 IoC count is characteristic of bundled dependency inflation (50+ npm packages × 20 IoC each = 1000+ findings), not actual threat indicators. The OBFUSCATION-FUNCTION_INDIRECT-extension/dataproc/notebook_renderers/sparkmonitor_renderer.js-670 finding occurs in minified webview JavaScript, which is expected build output rather than intentional obfuscation. No malware signatures, credential theft patterns, or supply chain poisoning indicators exist in the evidence.
The extension exhibits expected behavior for a cloud-connected IDE tool. The high finding volume derives from bundled code and YARA noise, not malicious intent.
Key Reasons
- No malware signatures or credential theft patterns detected
- Network activity in webview/bundle files consistent with cloud IDE purpose
- 8847 IoC findings from bundled dependencies (expected noise)
- Developer name GoogleCloudTools suggests official Google origin
- Zero secret/credential findings in evidence bundle
False Positive Considerations
- Bundled dependency IoC inflation (8847 findings from dist/bundle files)
- Webview network calls expected for cloud IDE functionality
- Code-smell findings (150) are YARA noise per documented patterns
- Minified JavaScript triggering obfuscation rules in webview files
Reviewed 2026-04-27; recommended action: suppress false positive; model confidence 75%.
VS Code version history
Risk trend by version
9 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace