Policy result for this exact artifact
Exact artifact intelligence
GitHub Copilot
GitHub.copilot@1.388.0Security outcomeReview needed
The extension exposes sensitive capabilities or non-confirmed risk evidence that needs context.
100% analysis coverage · exact version onlyGitHubvs-marketplaceArtifact
ed18caf3e3cd23eaReview decision-relevant behavior before installation.
Review the grouped evidence, affected locations, and whether each behavior matches the extension’s purpose.
61/100Review needed
Diagnostic risk index for this exact artifact — not a probability of malice.
100
Required analyzers completed
0
Diagnostic index, not probability
12 contextual groups kept separate
Power describes access, not intent
9 behavior groups need context before approval.
Native binary dist/crypt32.node has no companion checksum or signature file and no documented provenance.
ed18caf3e3cd23eac8b9141f0b0a6fb30022cfdf7575a7113b6a9885cbf5be19Build fedc47d31ef5 · ruleset 2026.07.19
Evidence that drives review
Native binary dist/crypt32.node has no companion checksum or signature file and no documented provenance.
17 observed locations · review evidence
@modelcontextprotocol/sdk@1.17.0 has 3 OSV finding(s). Version match: range-derived.
7 observed locations · review evidence
Call target resolved via computed member access: n[...](...) (line 1)
6 observed locations · review evidence