Exact artifact intelligence

aws-toolkit-vscode

amazonwebservices.aws-toolkit-vscode@4.10.0
Security outcomeReview needed

The extension exposes sensitive capabilities or non-confirmed risk evidence that needs context.

100% analysis coverage · exact version only
amazonwebservicesvs-marketplaceArtifact 9197f84348510b68
Security brief

Review decision-relevant behavior before installation.

Review the grouped evidence, affected locations, and whether each behavior matches the extension’s purpose.

61/100Review needed

Diagnostic risk index for this exact artifact — not a probability of malice.

OutcomeReview needed

Policy result for this exact artifact

Coverage
100

Required analyzers completed

Malware signal
0

Diagnostic index, not probability

Evidence groups7

15 contextual groups kept separate

Capabilities10

Power describes access, not intent

Why this outcome

7 behavior groups need context before approval.

Call target resolved via computed member access: F[...](...) (line 9997)

Exact artifact9197f84348510b68ed96e7f621f55b9fae434cfd651b5ff458e32c6ca21f3e03

Build 8c83a1c11c79 · ruleset 2026.07.19

Evidence that drives review
MEDIUM
Call target resolved via computed member access: F[...](...) (line 9997)

82 observed locations · review evidence

MEDIUM
Extension webview in dist/src/extensionNode.js declares a Content-Security-Policy with an unsafe directive (unsafe-inline, unsafe-eval, or a wildcard script-src).

2 observed locations · review evidence

MEDIUM
Extension contains a packed artifact: resources/amazonQCT/QCT-Maven-1-0-156-0.jar.

1 observed location · review evidence