Exact artifact intelligence

go

golang.go@0.56.0
Security outcomeReview needed

The extension exposes sensitive capabilities or non-confirmed risk evidence that needs context.

100% analysis coverage · exact version only
golangvs-marketplaceArtifact 9f5959fb17ba0a8d
Security brief

Review decision-relevant behavior before installation.

Review the grouped evidence, affected locations, and whether each behavior matches the extension’s purpose.

61/100Review needed

Diagnostic risk index for this exact artifact — not a probability of malice.

OutcomeReview needed

Policy result for this exact artifact

Coverage
100

Required analyzers completed

Malware signal
0

Diagnostic index, not probability

Evidence groups4

9 contextual groups kept separate

Capabilities7

Power describes access, not intent

Why this outcome

4 behavior groups need context before approval.

Call target resolved via computed member access: obj[...](...) (line 8392)

Exact artifact9f5959fb17ba0a8dbd804387ddda50975fcaa9dd5267aa33eaaa89912072aacb

Build fedc47d31ef5 · ruleset 2026.07.19

Evidence that drives review
MEDIUM
Call target resolved via computed member access: obj[...](...) (line 8392)

43 observed locations · review evidence

MEDIUM
Runtime dependency tree-kill is loaded from a mutable or non-registry source: file:third_party/tree-kill.

1 observed location · review evidence

LOW
Extension activates on sensitive IDE event: onDebugInitialConfigurations.

3 observed locations · review evidence