OpenVSX Registry Verified

Python

efd86bcb-7b1a-58e9-8416-4b83eb0cf514 | v2026.4.0
31/ 100
LOW risk
Analyst verdict
No high-risk signal observed

Based on the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
6 months ago
Version
v2026.4.0
Artifact
SHA256 232…4A6
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

29 detail rows
Showing 25 of 29 · highest severity first

Publisher Evidence

Low

ms-python

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

65
Noisy-finding weight
x1.00
Publisher domain
No domain
Missing
Store verification signal
Verified publisher
Verified
Extension portfolio
539
Portfolio

12 evidence rows available.

Finding Categories

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

Security Analysis

The extension named "Python" available on OpenVSX provides Python language support, including IntelliSense via Pylance, debugging, linting, formatting, refactoring, and unit‑test integration. Its public description states that it enables developers to write, analyze, and test Python code within the IDE.

All 29 findings reported in the evidence are categorized as "dependency" with low severity. Each finding is a declaration of a third‑party package in the file "/tmp/extract-232aeafb01f069824fdd92d3e628c1c442bbcfa1d3cc945ff97076340bb2b4a6-3509332181/extension/out/client/package.json". Examples include "DEP-vscode-languageserver-protocol-^3.17.6-next.10", "DEP-sudo-prompt-^9.2.1", and "DEP-winreg-^1.2.4". No findings belong to categories such as malware-signature, ioc, obfuscation, or secret, and the total count of high‑severity or critical items is zero.

Because the extension’s advertised functionality requires a rich set of language‑server protocols, build tools, and platform adapters, the presence of these dependencies is expected. The dependency on "vscode-languageclient" and "vscode-jsonrpc" entails spawning child processes to communicate with the Pylance language server, and reading workspace files is necessary for linting, formatting, and debugging operations. None of the dependency entries reference suspicious network endpoints or indicate postinstall code execution; the only network‑related behavior documented in the extension’s purpose is interaction with official VS Code update servers, which is typical for language extensions.

Credential‑related findings are absent; the summary shows a "secret" count of zero, meaning no attempts to read .env files, .ssh configuration, or cloud credentials were observed. Consequently, there is no evidence of credential theft or exfiltration.

A potential counterargument is that the listed dependency "winreg" could be used to query the Windows Registry for stored credentials. While winreg is a legitimate Node.js module for interacting with the registry, its inclusion merely supports Windows‑specific integration points that the extension may expose to users. No actual registry reads or credential extraction APIs are manifested in the evidence, and the extension’s documentation does not claim to harvest or transmit registry data. Therefore, this does not constitute malicious credential‑theft behavior.

In summary, the observed artifacts are fully consistent with the normal operational requirements of a Python language extension. The absence of malicious indicators, combined with the clear alignment of found dependencies with the extension’s stated capabilities, leads to the conclusion that the findings represent benign functional code rather than a threat.

The extension therefore poses no immediate security risk to users beyond the inherent privileges required for any language‑server extension.

Key Reasons

  • All findings are dependency declarations
  • No malware signatures or IoC evidence
  • No secret or credential access findings
  • Extension purpose matches observed behavior
  • No postinstall or process execution evidence

False Positive Considerations

  • dependency false positives
  • code-smell noise
  • IoC extractor garbage
  • bundled package analysis

Reviewed 2026-05-23; recommended action: no action; model confidence 96%.

About This Extension

Python language support with extension access points for IntelliSense (Pylance), Debugging (Python Debugger), linting, formatting, refactoring, unit tests, and more.

Frequently Asked Questions