Policy result for this exact artifact
Exact artifact intelligence
SonarQube for IDE
SonarSource.sonarlint-vscode@5.5.0Security outcomeReview needed
The extension exposes sensitive capabilities or non-confirmed risk evidence that needs context.
100% analysis coverage · exact version onlySonarSourcevs-marketplaceArtifact
d755728fcd9d87b1Review decision-relevant behavior before installation.
Review the grouped evidence, affected locations, and whether each behavior matches the extension’s purpose.
58/100Review needed
Diagnostic risk index for this exact artifact — not a probability of malice.
100
Required analyzers completed
0
Diagnostic index, not probability
11 contextual groups kept separate
Power describes access, not intent
6 behavior groups need context before approval.
@xmldom/xmldom@0.8.11 has 5 OSV finding(s). Version match: range-derived.
d755728fcd9d87b122717b34868fc5a88908b571432e387f9f601f229307fdcfBuild 8c83a1c11c79 · ruleset 2026.07.19
Evidence that drives review
@xmldom/xmldom@0.8.11 has 5 OSV finding(s). Version match: range-derived.
4 observed locations · review evidence
Extension contributes agent-facing capability: languageModelTools.
1 observed location · review evidence
Agent-facing tool surface can run shell or process commands.
1 observed location · review evidence