Exact artifact intelligence

roo-cline

RooVeterinaryInc.roo-cline@3.54.0
Security outcomeReview needed

The extension exposes sensitive capabilities or non-confirmed risk evidence that needs context.

100% analysis coverage · exact version only
RooVeterinaryIncvs-marketplaceArtifact caf96d596d69cb34
Security brief

Review decision-relevant behavior before installation.

Review the grouped evidence, affected locations, and whether each behavior matches the extension’s purpose.

80/100Review needed

Diagnostic risk index for this exact artifact — not a probability of malice.

OutcomeReview needed

Policy result for this exact artifact

Coverage
100

Required analyzers completed

Malware signal
0

Diagnostic index, not probability

Evidence groups3

12 contextual groups kept separate

Capabilities7

Power describes access, not intent

Why this outcome

3 behavior groups need context before approval.

@modelcontextprotocol/sdk@1.12.0 has 3 OSV finding(s). Version match: exact.

Exact artifactcaf96d596d69cb3427f00c3ca60492693135cc6b9f621aa062202903aa652735

Build fedc47d31ef5 · ruleset 2026.07.19

Evidence that drives review
HIGH
@modelcontextprotocol/sdk@1.12.0 has 3 OSV finding(s). Version match: exact.

11 observed locations · review evidence

MEDIUM
Runtime dependency @roo-code/core is loaded from a mutable or non-registry source: workspace:^.

3 observed locations · review evidence

MEDIUM
Extension webview in dist/extension.js declares a Content-Security-Policy with an unsafe directive (unsafe-inline, unsafe-eval, or a wildcard script-src).

1 observed location · review evidence