JetBrains Marketplace Verified

Claude Code [Beta]

by anthropic · 4.7M users · 2.3 rating
f10c58f5-cf04-5302-b002-333db61cd613 | v0.1.14-beta
21/ 100
LOW risk
Analyst verdict
No high-risk signal observed

Based on the RiskyPlugins AI security review of the observed evidence.

No individual score drivers were recorded for this analysis.

Analysis record

Analysed
3 days ago
Version
v0.1.14-beta
Artifact
SHA256 BAC…096
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

33 detail rows
Showing 25 of 33 · highest severity first

Publisher Evidence

Low

anthropic

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

97
Noisy-finding weight
x1.00
Publisher domain
anthropic.com
Observed
Store verification signal
Verified publisher
Verified
Extension portfolio
5
Portfolio

11 evidence rows available.

Finding Categories

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

The Claude Code JetBrains plugin from Anthropic PBC presents no security concerns. All 33 findings in the analysis are metadata-level JAR file hashes from bundled dependencies, not security detections. The findings include standard Kotlin and HTTP framework libraries: claude-code-jetbrains-plugin/lib/ktor-utils-jvm-3.0.2.jar, claude-code-jetbrains-plugin/lib/ktor-events-jvm-3.0.2.jar, claude-code-jetbrains-plugin/lib/kotlinx-serialization-json-jvm-1.8.1.jar, and claude-code-jetbrains-plugin/lib/kotlin-logging-jvm-7.0.0.jar. These are legitimate dependencies required for the extension to communicate with Anthropic's Claude API and function within the JetBrains IDE.

Filesystem and process access are fully justified by the extension's stated purpose as an AI coding assistant. The bundled Ktor HTTP client libraries (ktor-client-cio-jvm-3.0.2.jar, ktor-http-cio-jvm-3.0.2.jar) enable network communication with Anthropic's servers for code generation and completion features. The Kotlin serialization and logging libraries support standard IDE integration. No findings indicate unauthorized workspace reads, credential access, or data exfiltration.

Credential-access findings are absent entirely. The findings summary shows zero detections in the secret category, and no findings reference .env files, SSH keys, cloud credentials, or VS Code/JetBrains secret storage. The metadata findings are purely file hashes of bundled JAR dependencies, not credential-related code patterns.

The strongest counterargument would be that bundled JAR dependencies could theoretically contain malicious code. However, this concern is mitigated by multiple factors: the extension is published by Anthropic PBC, a verified and well-known developer of the Claude AI model; the extension has over 3.7 million users, indicating widespread trust and adoption; and the specific libraries bundled (Ktor HTTP framework, Kotlinx serialization, Kotlin logging) are standard, widely-used JVM libraries with no indication of tampering. The zero malware signatures, zero IoC matches, and zero code-smell detections confirm these are legitimate dependencies.

This extension represents a classic false-positive scenario where the CVEQ platform's metadata extraction identifies bundled dependency hashes as "findings" when they are simply normal build artifacts. The extension performs exactly what it states: integrating Claude AI into the JetBrains development environment.

Key Reasons

  • Zero malware signatures, IoC matches, or code-smell detections in findings summary
  • All 33 findings are metadata-level JAR hashes from legitimate Kotlin/HTTP framework dependencies
  • Published by verified developer Anthropic PBC with 3.7M+ users
  • No credential access, secret exposure, or exfiltration patterns detected

False Positive Considerations

  • Bundled dependency JAR hashes flagged as metadata findings
  • Standard Kotlin/HTTP framework libraries (Ktor, Kotlinx) in lib/ directory
  • No actual security detections despite high finding count

Reviewed 2026-05-23; recommended action: suppress false positive; model confidence 95%.

About This Extension

IMPORTANT: This plugin requires Claude Code to be installed separately. For more information, see claude.com/claude-code. Integrate Claude Code with your favorite...

Frequently Asked Questions