Exact artifact intelligence

Pylance

ms-python.vscode-pylance@2026.2.106
Security outcomeReview needed

The extension exposes sensitive capabilities or non-confirmed risk evidence that needs context.

100% analysis coverage · exact version only
ms-pythonvs-marketplaceArtifact c1de51d2e7ba5e0d
Security brief

Review decision-relevant behavior before installation.

Review the grouped evidence, affected locations, and whether each behavior matches the extension’s purpose.

55/100Review needed

Diagnostic risk index for this exact artifact — not a probability of malice.

OutcomeReview needed

Policy result for this exact artifact

Coverage
100

Required analyzers completed

Malware signal
0

Diagnostic index, not probability

Evidence groups4

7 contextual groups kept separate

Capabilities5

Power describes access, not intent

Why this outcome

4 behavior groups need context before approval.

Native binary dist/bundled/bin/win32-arm64/pylance-service.exe has no companion checksum or signature file and no documented provenance.

Exact artifactc1de51d2e7ba5e0d3aebc3895e341bb628032f94da6ba660b306da824b185e2f

Build 9a51c780c109 · ruleset 2026.07.19

Evidence that drives review
MEDIUM
Native binary dist/bundled/bin/win32-arm64/pylance-service.exe has no companion checksum or signature file and no documented provenance.

2 observed locations · review evidence

MEDIUM
YARA rule ide_scanner_embedded_pe matched dist/bundled/bin/win32-x64/pylance-service.exe.

1 observed location · review evidence

MEDIUM
Extension contains 2 native artifacts (e.g. dist/bundled/bin/win32-arm64/pylance-service.exe).

1 observed location · review evidence