Policy result for this exact artifact
Exact artifact intelligence
Kubernetes
ms-kubernetes-tools.vscode-kubernetes-tools@1.4.0Security outcomeReview needed
The extension exposes sensitive capabilities or non-confirmed risk evidence that needs context.
100% analysis coverage · exact version onlyms-kubernetes-toolsvs-marketplaceArtifact
b7ae0e17eaf14e98Review decision-relevant behavior before installation.
Review the grouped evidence, affected locations, and whether each behavior matches the extension’s purpose.
54/100Review needed
Diagnostic risk index for this exact artifact — not a probability of malice.
100
Required analyzers completed
0
Diagnostic index, not probability
11 contextual groups kept separate
Power describes access, not intent
6 behavior groups need context before approval.
Call target resolved via computed member access: ThisExpression[...](...) (line 104)
b7ae0e17eaf14e98675abd413546311b4fd6fa000ff1dce2011a502bc148cd4eBuild fedc47d31ef5 · ruleset 2026.07.19
Evidence that drives review
Call target resolved via computed member access: ThisExpression[...](...) (line 104)
8 observed locations · review evidence
js-yaml@4.1.1 has 1 OSV finding(s). Version match: range-derived.
3 observed locations · review evidence
GitHub Actions workflow has dangerous supply-chain posture: .github/workflows/main.yml.
1 observed location · review evidence