Policy result for this exact artifact
Exact artifact intelligence
Python Debugger
ms-python.debugpy@2026.7.11831010Security outcomeReview needed
The extension exposes sensitive capabilities or non-confirmed risk evidence that needs context.
100% analysis coverage · exact version onlyms-pythonvs-marketplaceArtifact
3fbf31448bd8cf7cReview decision-relevant behavior before installation.
Review the grouped evidence, affected locations, and whether each behavior matches the extension’s purpose.
52/100Review needed
Diagnostic risk index for this exact artifact — not a probability of malice.
100
Required analyzers completed
0
Diagnostic index, not probability
5 contextual groups kept separate
Power describes access, not intent
7 behavior groups need context before approval.
YARA rule ide_scanner_embedded_pe matched bundled/libs/debugpy/_vendored/pydevd/_pydevd_sys_monitoring/_pydevd_sys_monitoring_cython.cp314-win_amd64.pyd.
3fbf31448bd8cf7cab2d7f00645d38813f1fe66a8b122e275632321eb65bbb89Build 9a51c780c109 · ruleset 2026.07.19
Evidence that drives review
YARA rule ide_scanner_embedded_pe matched bundled/libs/debugpy/_vendored/pydevd/_pydevd_sys_monitoring/_pydevd_sys_monitoring_cython.cp314-win_amd64.pyd.
13 observed locations · review evidence
Native binary bundled/libs/debugpy/_vendored/pydevd/pydevd_attach_to_process/attach_amd64.dll has no companion checksum or signature file and no documented provenance.
6 observed locations · review evidence
InputBox prompt or options appear to request credential-related data.
1 observed location · review evidence