Exact artifact intelligence

Continue - open-source AI code agent

Continue.continue@2.1.0
Security outcomeReview needed

The extension exposes sensitive capabilities or non-confirmed risk evidence that needs context.

100% analysis coverage · exact version only
Continuevs-marketplaceArtifact 28e1c4691f090080
Security brief

Review decision-relevant behavior before installation.

Review the grouped evidence, affected locations, and whether each behavior matches the extension’s purpose.

61/100Review needed

Diagnostic risk index for this exact artifact — not a probability of malice.

OutcomeReview needed

Policy result for this exact artifact

Coverage
100

Required analyzers completed

Malware signal
0

Diagnostic index, not probability

Evidence groups9

12 contextual groups kept separate

Capabilities8

Power describes access, not intent

Why this outcome

9 behavior groups need context before approval.

Call target resolved via computed member access: i.attributes[...](...) (line 4)

Exact artifact28e1c4691f090080f9872ddbbd450e32a822759fefea6e6c12f96a45929351b9

Build 8c83a1c11c79 · ruleset 2026.07.19

Evidence that drives review
MEDIUM
Call target resolved via computed member access: i.attributes[...](...) (line 4)

40 observed locations · review evidence

MEDIUM
Native binary bin/napi-v3/linux/x64/onnxruntime_binding.node has no companion checksum or signature file and no documented provenance.

14 observed locations · review evidence

MEDIUM
axios@1.13.1 has 24 OSV finding(s). Version match: range-derived.

10 observed locations · review evidence