VS Code Marketplace Verified

Google Cloud Data Agent Kit

by Google Cloud · 106.9K users · 5.0 rating
ec39b214-d552-54bc-a304-012b10cde78a | v0.11.0
86/ 100
CRITICAL risk
+21 since v0.6.1
Analyst verdict
Do not install

The AI review rates the findings as likely false positive, but the risk score (86/100) still counts them.

Analysis record

Analysed
1 weeks ago
Version
v0.11.0
Artifact
SHA256 F88…65E
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

448 detail rows
Showing 25 of 31 · highest severity first

YARA Rule Matches

22 rules
SeverityRuleHitsFilesMetadata
LOWDebuggerStatementsShouldNotBeUsed 3
webview/app_bundle.jsdatacloud_vscode.jsdataproc/notebook_renderers/sparkmonitor_renderer.js
-
LOWUsingCommandLineArguments 1
mcp_servers/cli/mcp_proxy_bundle.js
-
LOWpostinstall file download 50
antigravity/skills/gcp-managed-airflow-recommendations/scripts/workload_memory_usage.pyantigravity/skills/gcp-managed-airflow-migrations/references/environment-inspection.mdantigravity/skills/gcs-security-assessment/scripts/preflight_permissions.py +47 more
-
LOWHavingAPermissiveCrossOriginResourceSharingPolicy 1
antigravity/skills/building-data-apps/examples/express_chat.ts
-
LOWcredential gcp credentials 3
datacloud_vscode.jsantigravity/skills/google-cloud-storage-basics/references/mcp-usage.mdmcp_servers/cli/mcp_proxy_bundle.js
-
LOWNoUseEval 3
sql_editor/exthost/bigquery/server_bin.cjsdataproc/notebook_renderers/sparkmonitor_renderer.jsdatacloud_vscode.js
-
LOWSQLInjection 3
datacloud_vscode.jswebview/app_bundle.jsdataproc/notebook_renderers/sparkmonitor_renderer.js
-
LOWNoUseWeakRandom 4
datacloud_vscode.jswebview/app_bundle.jsdataproc/notebook_renderers/sparkmonitor_renderer.js +1 more
-
LOWpostinstall network communication 55
antigravity/skills/bigquery-ai-ml/references/ai_generate.mdmcp_servers/cli/mcp_proxy_bundle.jsxhr-sync-worker.js +52 more
-
LOWpostinstall system command 97
antigravity/skills/gcp-dataflow/references/streaming_job_health.mdantigravity/skills/gcp-spark/references/read_write_data.mdantigravity/skills/gcs-security-assessment/scripts/fetch_object_telemetry.py +94 more
-
LOWUsingShellInterpreterWhenExecutingOSCommands 3
datacloud_vscode.jsdist/agents/hooks/telemetry_hook.jssql_editor/exthost/bigquery/server_bin.cjs
-
LOWpostinstall crypto operations 36
antigravity/skills/google-cloud-storage-basics/references/iac-usage.mdantigravity/skills/google-cloud-storage-bucket-architect/references/sdk_java.mdantigravity/skills/google-cloud-storage-bucket-architect/references/gcloud.md +33 more
-
LOWCreatingCookiesWithoutTheSecureFlag 1
datacloud_vscode.js
-
LOWpostinstall file manipulation 63
antigravity/skills/google-cloud-storage-bucket-architect/references/sensitive_data.mdantigravity/skills/bigtable-basics/references/cli_data_access.mddist/agents/hooks/telemetry_hook.js +60 more
-
LOWpostinstall obfuscation 45
antigravity/skills/gcp-composer-troubleshooting/SKILL.mdantigravity/skills/bigquery-ai-ml/references/ai_generate_embedding.mdantigravity/skills/bigquery-ai-ml/references/ai_evaluate.md +42 more
-
LOWpostinstall registry modification 8
antigravity/skills/google-cloud-storage-basics/references/iac-usage.mdsql_editor/exthost/bigquery/server_bin.cjsdataproc/notebook_renderers/sparkmonitor_renderer.js +5 more
-
LOWNoUseSocketManually 1
datacloud_vscode.js
-
LOWpostinstall environment access 2
bigquery/resources/declarative_pipelines_clustered_template.ymlbigquery/resources/declarative_pipelines_serverless_template.yml
-
LOWcredential env files 23
antigravity/skills/gcp-managed-airflow-migrations/SKILL.mdantigravity/skills/gcp-managed-airflow-recommendations/scripts/dag_parsing_stats.pyantigravity/skills/discovering-gcp-data-assets/SKILL.md +20 more
-
LOWpostinstall persistence mechanism 13
antigravity/skills/gcp-pipeline-resource-provisioning/references/gcp_pipeline_resource_provisioning_spec.mdCHANGELOG.mddatacloud_vscode.js +10 more
-
LOWCreatingCookiesWithoutTheHttpOnlyFlag 1
datacloud_vscode.js
-
LOWNoDisableSanitizeHtml 1
datacloud_vscode.js
-

Network Indicators

Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.

10,228 total
...

Network indicators are queued for lazy loading

Scroll this section into view to load the detailed rows.

Publisher Evidence

High

Google Cloud

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

100
Noisy-finding weight
x0.50
Publisher domain
google.com
Trusted match
Store verification signal
Verified publisher
Verified
Extension portfolio
557
Portfolio

11 evidence rows available.

Finding Categories

7
Obfuscation
15
Network
10,228
IoC Indicators

YARA Rules Matched

22 rules(417 hits)
DebuggerStatementsShouldNotBeUsed UsingCommandLineArguments postinstall file download HavingAPermissiveCrossOriginResourceSharingPolicy credential gcp credentials NoUseEval SQLInjection NoUseWeakRandom postinstall network communication postinstall system command UsingShellInterpreterWhenExecutingOSCommands postinstall crypto operations CreatingCookiesWithoutTheSecureFlag postinstall file manipulation postinstall obfuscation postinstall registry modification +6 more

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

Filesystem and Process Access Justification

The extension's stated purpose is to integrate Google Cloud Data Agent Kit into VS Code. Network findings in extension/dataproc/notebook_renderers/sparkmonitor_renderer.js (lines 233, 214, 148, 689) and extension/webview/app_bundle.js (lines 473, 917, 2500) show socket_io and fetch calls. These network patterns are consistent with cloud IDE extensions that must communicate with Google Cloud services for data processing and notebook rendering. The NET-FETCH-extension/datacloud_vscode.js-14937 and NET-FETCH-extension/datacloud_vscode.js-14743 findings in the main extension file indicate legitimate cloud API communication. No postinstall payload execution or unauthorized process spawning was detected.

Credential Access Findings

The findings summary shows 0 secret findings and 0 credential-related detections. The credential_* YARA rules that fire on benign config reads are classified as code-smell (150 total) and represent YARA noise per documented false-positive patterns. No findings target .env, .ssh, cloud credentials, or VS Code secret storage. The extension does not exhibit credential theft behavior.

Strongest Counterargument

The 8847 IoC findings and 0 user count could indicate a typosquatting attempt or malicious re-upload. However, the developer name GoogleCloudTools aligns with Google's official VS Code publisher naming convention. The single specific IoC (l.ie in extracted_from_files) is a legitimate domain without evidence of malicious use. The 8847 IoC count is characteristic of bundled dependency inflation (50+ npm packages × 20 IoC each = 1000+ findings), not actual threat indicators. The OBFUSCATION-FUNCTION_INDIRECT-extension/dataproc/notebook_renderers/sparkmonitor_renderer.js-670 finding occurs in minified webview JavaScript, which is expected build output rather than intentional obfuscation. No malware signatures, credential theft patterns, or supply chain poisoning indicators exist in the evidence.

The extension exhibits expected behavior for a cloud-connected IDE tool. The high finding volume derives from bundled code and YARA noise, not malicious intent.

Key Reasons

  • No malware signatures or credential theft patterns detected
  • Network activity in webview/bundle files consistent with cloud IDE purpose
  • 8847 IoC findings from bundled dependencies (expected noise)
  • Developer name GoogleCloudTools suggests official Google origin
  • Zero secret/credential findings in evidence bundle

False Positive Considerations

  • Bundled dependency IoC inflation (8847 findings from dist/bundle files)
  • Webview network calls expected for cloud IDE functionality
  • Code-smell findings (150) are YARA noise per documented patterns
  • Minified JavaScript triggering obfuscation rules in webview files

Reviewed 2026-04-27; recommended action: suppress false positive; model confidence 75%.

VS Code version history

Risk trend by version

9 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
86
Change since first
+21
Change from previous
+21
Versions:
First analyzed version
0.0.1
Apr 18, 2026
Risk range
65 to 86
Across analyzed versions
Latest analyzed version
0.11.0
Sep 18, 2026
Selected version
critical
Version
v0.11.0
1 weeks ago
Risk score
86
Findings
10687
Change vs previous
+21

Pick any point on the chart to explore that version's code below.

About This Extension

Bring the full power of Google Cloud Data Agent Kit (starter pack) to your intelligent IDE

Frequently Asked Questions