Policy result for this exact artifact
Exact artifact intelligence
GitHub Pull Requests
GitHub.vscode-pull-request-github@0.159.2026071604Security outcomeReview needed
The extension exposes sensitive capabilities or non-confirmed risk evidence that needs context.
100% analysis coverage · exact version onlyGitHubvs-marketplaceArtifact
5e40bb78c3af7ad2Review decision-relevant behavior before installation.
Review the grouped evidence, affected locations, and whether each behavior matches the extension’s purpose.
58/100Review needed
Diagnostic risk index for this exact artifact — not a probability of malice.
100
Required analyzers completed
0
Diagnostic index, not probability
8 contextual groups kept separate
Power describes access, not intent
7 behavior groups need context before approval.
Call target resolved via computed member access: ThisExpression[...](...) (line 2616)
5e40bb78c3af7ad2df6c30d6c58a5f3b1c483e4151db3e07640007859e9e2907Build fedc47d31ef5 · ruleset 2026.07.19
Evidence that drives review
Call target resolved via computed member access: ThisExpression[...](...) (line 2616)
9 observed locations · review evidence
Extension webview in dist/extension.js declares a Content-Security-Policy with an unsafe directive (unsafe-inline, unsafe-eval, or a wildcard script-src).
2 observed locations · review evidence
Package defines a lifecycle script: postinstall.
1 observed location · review evidence