Arcane Forge
Based on the RiskyPlugins AI security review of the observed evidence.
Analysis record
- Analysed
- 6 months ago
- Version
- v0.0.2
- Artifact
- SHA256 49F…DA1
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
Publisher Evidence
Limited evidenceArcane Forge AI
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
14 evidence rows available.
Finding Categories
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality strong.
Filesystem/Process Access Justification
The extension's stated purpose is to "Sync Arcane Forge knowledge base files into VS Code workspaces," which legitimately requires filesystem read/write access and network connectivity. The evidence bundle shows 1 network finding and 22 code-smell findings, but zero malware signatures, zero credential theft indicators, and zero obfuscation findings. No findings indicate postinstall payload execution, credential access, or unauthorized data exfiltration. The code-smell findings (severity=low, finding_type=code-smell) match documented YARA noise patterns that fire on standard Node.js patterns like fetch, exec, fs, and crypto operations—expected behavior for a sync extension.
Credential Access Analysis
The findings summary explicitly shows "secret":0, meaning no credential-access findings were detected. The extension does not read .env files, .git/config, SSH keys, or cloud credentials. The 70 IOC findings do not target actual secrets. Instead, they match documented false positive patterns: http://www.apache.org/licenses/LICENSE-2.0 and http://schemas.openxmlformats.org/package/2006/content-types are standard license/namespace URLs, not malicious infrastructure. The domain https://arcane-forge-service.dev.arcaneforge.ai is the extension's own service endpoint, consistent with its sync functionality.
False Positive Patterns Identified
The remaining IOC findings are property access chains misread as domains: entry.id, a.id, b.id match the documented pattern where the XIOC extractor misinterprets JavaScript property access as domain names. Similarly, syncservice.js.map, index.js.map, download.download, and this.manifeststore.save are source map filenames and method chains incorrectly flagged as domains. These patterns are explicitly documented as known false positives in the CVEQ evidence guidelines.
Strongest Counterargument
The strongest counterargument is the extension's low user count (2 users) and early version (0.0.2), which could indicate a new or suspicious publish pattern. However, this alone does not constitute malicious behavior. The extension has zero malware signatures, zero credential theft findings, and no evidence of supply chain poisoning indicators. The high finding count (93 total) stems entirely from documented false positive patterns (70 IOC garbage, 22 code-smell noise), not from actual malicious code. Without evidence of postinstall payload execution, credential theft, or exfiltration beyond the stated sync purpose, the low adoption metrics do not override the absence of malicious indicators.
Key Reasons
- Zero malware signatures in findings
- All IOC findings match documented false positive patterns
- No credential theft or secret access findings
- Network activity aligns with stated sync purpose
- No obfuscation or postinstall payload execution detected
False Positive Considerations
- XIOC property access chains misread as domains (entry.id, a.id, b.id)
- Source map filenames flagged as domains (syncservice.js.map, index.js.map)
- Standard license URLs detected as IOCs (apache.org/licenses)
- Code-smell YARA rules firing on standard Node.js patterns
Reviewed 2026-04-28; recommended action: suppress false positive; model confidence 85%.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
Nakka - AI code agent
Nakka
BOO UI编辑器
boo-best
Erilang
eritten kwame gyau
VS Code Tools for WPF
LeXtudio Inc.
Spark & Hive Tools
Microsoft
Oracle Developer Tools for VS Code (SQL and PLSQL)
Oracle Corporation