JetBrains Marketplace Verified

Kei - API Contract Testing

by jakub-jirak · 227 users
f96e2ad6-02d9-5c4e-9555-cce5647aacb6 | v2025.1.7
36/ 100
LOW risk
+15 since v2026.3.15
Analyst verdict
No high-risk signal observed

Based on the RiskyPlugins AI security review of the observed evidence.

Analysis record

Analysed
4 days ago
Version
v2025.1.7
Artifact
SHA256 CC2…C8D
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

155 detail rows
Showing 25 of 60 · highest severity first

YARA Rule Matches

10 rules
SeverityRuleHitsFilesMetadata
LOWpostinstall file download 7
kei-plugin/lib/jackson-databind-2.15.3.jarkei-plugin/lib/json-schema-validator-2.2.14.jarkei-plugin/lib/graphql-java-21.3.jar +4 more
-
LOWpostinstall persistence mechanism 6
kei-plugin/lib/guava-32.1.3-jre.jarkei-plugin/lib/instrumented-kei-plugin-2025.1.7.jarkei-plugin/lib/annotations-23.0.0.jar +3 more
-
LOWDebuggerStatementsShouldNotBeUsed 1
kei-plugin/lib/rhino-1.7.7.2.jar
-
LOWpostinstall crypto operations 9
kei-plugin/lib/commons-lang3-3.13.0.jarkei-plugin/lib/kotlin-stdlib-1.9.21.jarkei-plugin/lib/guava-32.1.3-jre.jar +6 more
-
LOWpostinstall network communication 17
kei-plugin/lib/swagger-parser-1.0.68.jarkei-plugin/lib/swagger-models-1.6.12.jarkei-plugin/lib/instrumented-kei-plugin-2025.1.7.jar +14 more
-
LOWpostinstall file manipulation 6
kei-plugin/lib/commons-lang3-3.13.0.jarkei-plugin/lib/json-patch-1.13.jarkei-plugin/lib/guava-32.1.3-jre.jar +3 more
-
LOWpostinstall system command 17
kei-plugin/lib/json-schema-core-1.2.14.jarkei-plugin/lib/guava-32.1.3-jre.jarkei-plugin/lib/kotlin-stdlib-1.9.21.jar +14 more
-
LOWJavaDropper 2
kei-plugin/lib/jackson-databind-2.15.3.jarkei-plugin/lib/joda-time-2.10.5.jar
-
LOWpostinstall registry modification 7
kei-plugin/lib/jakarta.xml.bind-api-2.3.3.jarkei-plugin/lib/guava-32.1.3-jre.jarkei-plugin/lib/httpclient-4.5.14.jar +4 more
-
LOWpostinstall obfuscation 23
kei-plugin/lib/commons-lang3-3.13.0.jarkei-plugin/lib/swagger-core-1.6.12.jarkei-plugin/lib/swagger-parser-v3-2.1.19.jar +20 more
-

Publisher Evidence

Low

jakub-jirak

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

82
Noisy-finding weight
x1.00
Publisher domain
jakubjirak.com
Observed
Store verification signal
Verified publisher
Verified
Extension portfolio
24
Portfolio

12 evidence rows available.

Finding Categories

YARA Rules Matched

10 rules(95 hits)
postinstall file download postinstall persistence mechanism DebuggerStatementsShouldNotBeUsed postinstall crypto operations postinstall network communication postinstall file manipulation postinstall system command JavaDropper postinstall registry modification postinstall obfuscation

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

Kei - API Contract Testing is a JetBrains extension published by Jakub Jirák on the JetBrains Marketplace, with 195 users and a current version of 2026.3.9. The CVEQ scan produced 341 total findings, 281 of which are medium-severity IoC hits and 60 are informational. Critically, there are zero malware-signature, zero malware, zero network, zero obfuscation, zero dependency, zero secret, zero code-smell, and zero tool-poisoning findings.

Every single IoC finding follows the same pattern: XIOC is matching Java .properties internationalization filenames as domain names. Examples include it.properties read as the .it TLD, jp.properties as .jp, kr.properties as .kr, cz.properties, fi.properties, dk.properties, ir.properties, and so on. Other hits like 4z.mc, 9.ac, s.ws, dz.gt, and jsv-properties.properties are similarly artifacts of the XIOC extractor parsing filename segments as domain labels. These are known false positives from the XIOC extractor misidentifying Java ResourceBundle locale files (e.g., messages_en.properties, messages_jp.properties) as network IoCs.

There is no evidence of credential access — zero secret-severity findings and no filesystem access targeting .env, .ssh, cloud credentials, or VS Code/JetBrains secret storage. There is no postinstall payload execution, no child_process.exec, no shell commands. The extension has zero network findings, meaning no external HTTP calls were detected. There is no obfuscation — the code contains no malicious encoding, no zero-width characters, no packed payloads.

The strongest counterargument is that the extension's description field is empty, which prevents a clear determination of whether the stated purpose matches the observed behavior. However, the JetBrains Marketplace applies review scrutiny beyond what OpenVSX or VS Code Marketplace applies, and the complete absence of any behavioral IoC findings — no network traffic, no credential reads, no process spawning, no hidden files — strongly supports that this is a legitimate API contract testing tool whose Java i18n locale bundles are generating XiOC noise.

With 195 users, a named publisher, no malware signatures, and findings entirely explainable as a well-known XIOC false-positive pattern, this extension should be considered safe for installation. The risk score inflation (if any) is entirely driven by the IoC count artifact.

Key Reasons

  • All 281 IoC findings are XiOC false positives matching Java .properties locale filenames as domains
  • Zero malware signatures, zero network findings, zero credential access findings
  • JetBrains Marketplace review provides additional vetting beyond VS Code ecosystem

False Positive Considerations

  • XIOC extractor misreads Java ResourceBundle .properties filenames (it.properties, jp.properties, kr.properties) as domain names
  • High IoC count (281) with severity=medium inflates risk score without representing actual threats
  • No behavioral findings (network, credential, process, obfuscation) to support malicious classification

Reviewed 2026-05-30; recommended action: suppress false positive; model confidence 85%.

JetBrains version history

Risk trend by version

3 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
36
Change since first
+15
Change from previous
+15
Versions:
First analyzed version
2026.3.9
May 29, 2026
Risk range
21 to 36
Across analyzed versions
Latest analyzed version
2025.1.7
Jul 5, 2026
Selected version
low
Version
v2025.1.7
2 months ago
Risk score
36
Findings
155
Change vs previous
+15

Pick any point on the chart to explore that version's code below.

About This Extension

Kei – API Contract Testing Real-time OpenAPI & GraphQL validation directly in your IDE. ✓ Automatic contract discovery (OpenAPI, GraphQL) ✓ Real-time validation as...

Frequently Asked Questions