Policy result for this exact artifact
Exact artifact intelligence
Python Debugger
ms-python.debugpy@2026.7.11831007Security outcomeReview needed
The extension exposes sensitive capabilities or non-confirmed risk evidence that needs context.
100% analysis coverage · exact version onlyms-pythonvs-marketplaceArtifact
19ad8542132633eeReview decision-relevant behavior before installation.
Review the grouped evidence, affected locations, and whether each behavior matches the extension’s purpose.
52/100Review needed
Diagnostic risk index for this exact artifact — not a probability of malice.
100
Required analyzers completed
0
Diagnostic index, not probability
5 contextual groups kept separate
Power describes access, not intent
6 behavior groups need context before approval.
Native binary bundled/libs/debugpy/_vendored/pydevd/pydevd_attach_to_process/attach_linux_amd64.so has no companion checksum or signature file and no documented provenance.
19ad8542132633eec97064f549fb9e27bf0de78bdf1d506f8d1f15449ff9ef94Build 9a51c780c109 · ruleset 2026.07.19
Evidence that drives review
Native binary bundled/libs/debugpy/_vendored/pydevd/pydevd_attach_to_process/attach_linux_amd64.so has no companion checksum or signature file and no documented provenance.
2 observed locations · review evidence
InputBox prompt or options appear to request credential-related data.
1 observed location · review evidence
Extension contains 2 native artifacts (e.g. bundled/libs/debugpy/_vendored/pydevd/_pydevd_bundle/pydevd_cython.cpython-39-x86_64-linux-gnu.so).
1 observed location · review evidence