Exact extension version, artifact hash, affected file or dependency, normalized rule identifier, confidence, and scanner ruleset.
Semgrep · execution
Workspace input reaches process execution
untrusted-workspace-input-to-processWorkspace or user configuration reaches a process execution API; common developer-tool behavior that requires shell and trust context.
Default severityMEDIUMEvidence classcapability
What it means
Read the evidence before the label.
This alert records capability evidence produced by the Semgrep analyzer. Its default severity describes potential impact, not certainty that an extension is malicious.
A final decision also considers evidence correlation, artifact identity, analysis coverage, and the active policy.
Confirm whether the behavior matches the extension’s declared purpose and whether execution requires explicit user intent.