Exact artifact intelligence

Kubernetes

ms-kubernetes-tools.vscode-kubernetes-tools@1.4.0
Security outcomeReview needed

The extension exposes sensitive capabilities or non-confirmed risk evidence that needs context.

100% analysis coverage · exact version only
ms-kubernetes-toolsvs-marketplaceArtifact b7ae0e17eaf14e98
Security brief

Review decision-relevant behavior before installation.

Review the grouped evidence, affected locations, and whether each behavior matches the extension’s purpose.

54/100Review needed

Diagnostic risk index for this exact artifact — not a probability of malice.

OutcomeReview needed

Policy result for this exact artifact

Coverage
100

Required analyzers completed

Malware signal
0

Diagnostic index, not probability

Evidence groups6

11 contextual groups kept separate

Capabilities8

Power describes access, not intent

Why this outcome

6 behavior groups need context before approval.

Call target resolved via computed member access: ThisExpression[...](...) (line 104)

Exact artifactb7ae0e17eaf14e98675abd413546311b4fd6fa000ff1dce2011a502bc148cd4e

Build fedc47d31ef5 · ruleset 2026.07.19

Evidence that drives review
MEDIUM
Call target resolved via computed member access: ThisExpression[...](...) (line 104)

8 observed locations · review evidence

MEDIUM
js-yaml@4.1.1 has 1 OSV finding(s). Version match: range-derived.

3 observed locations · review evidence

MEDIUM
GitHub Actions workflow has dangerous supply-chain posture: .github/workflows/main.yml.

1 observed location · review evidence