Policy result for this exact artifact
Exact artifact intelligence
Python Debugger
ms-python.debugpy@2026.7.11831011Security outcomeReview needed
The extension exposes sensitive capabilities or non-confirmed risk evidence that needs context.
100% analysis coverage · exact version onlyms-pythonvs-marketplaceArtifact
7c6e07a3385d901eReview decision-relevant behavior before installation.
Review the grouped evidence, affected locations, and whether each behavior matches the extension’s purpose.
52/100Review needed
Diagnostic risk index for this exact artifact — not a probability of malice.
100
Required analyzers completed
0
Diagnostic index, not probability
5 contextual groups kept separate
Power describes access, not intent
7 behavior groups need context before approval.
Native binary bundled/libs/debugpy/_vendored/pydevd/pydevd_attach_to_process/attach_amd64.dll has no companion checksum or signature file and no documented provenance.
7c6e07a3385d901ecdd5cd9256bf267ecf7d1799e9f7bf8bcf5d36c7b360b58dBuild 9a51c780c109 · ruleset 2026.07.19
Evidence that drives review
Native binary bundled/libs/debugpy/_vendored/pydevd/pydevd_attach_to_process/attach_amd64.dll has no companion checksum or signature file and no documented provenance.
6 observed locations · review evidence
YARA rule ide_scanner_embedded_pe matched bundled/libs/debugpy/_vendored/pydevd/pydevd_attach_to_process/inject_dll_x86.exe.
6 observed locations · review evidence
InputBox prompt or options appear to request credential-related data.
1 observed location · review evidence