Policy result for this exact artifact
Exact artifact intelligence
roo-cline
RooVeterinaryInc.roo-cline@3.54.0Security outcomeReview needed
The extension exposes sensitive capabilities or non-confirmed risk evidence that needs context.
100% analysis coverage · exact version onlyRooVeterinaryIncvs-marketplaceArtifact
caf96d596d69cb34Review decision-relevant behavior before installation.
Review the grouped evidence, affected locations, and whether each behavior matches the extension’s purpose.
80/100Review needed
Diagnostic risk index for this exact artifact — not a probability of malice.
100
Required analyzers completed
0
Diagnostic index, not probability
12 contextual groups kept separate
Power describes access, not intent
3 behavior groups need context before approval.
@modelcontextprotocol/sdk@1.12.0 has 3 OSV finding(s). Version match: exact.
caf96d596d69cb3427f00c3ca60492693135cc6b9f621aa062202903aa652735Build fedc47d31ef5 · ruleset 2026.07.19
Evidence that drives review
@modelcontextprotocol/sdk@1.12.0 has 3 OSV finding(s). Version match: exact.
11 observed locations · review evidence
Runtime dependency @roo-code/core is loaded from a mutable or non-registry source: workspace:^.
3 observed locations · review evidence
Extension webview in dist/extension.js declares a Content-Security-Policy with an unsafe directive (unsafe-inline, unsafe-eval, or a wildcard script-src).
1 observed location · review evidence