Policy result for this exact artifact
Exact artifact intelligence
Pylance
ms-python.vscode-pylance@2026.2.108Security outcomeReview needed
The extension exposes sensitive capabilities or non-confirmed risk evidence that needs context.
100% analysis coverage · exact version onlyms-pythonvs-marketplaceArtifact
1658b9309a1baeceReview decision-relevant behavior before installation.
Review the grouped evidence, affected locations, and whether each behavior matches the extension’s purpose.
55/100Review needed
Diagnostic risk index for this exact artifact — not a probability of malice.
100
Required analyzers completed
0
Diagnostic index, not probability
7 contextual groups kept separate
Power describes access, not intent
4 behavior groups need context before approval.
Native binary dist/bundled/bin/win32-arm64/pylance-service.exe has no companion checksum or signature file and no documented provenance.
1658b9309a1baece010bac3eb5aaa3c5924d6a5f1eab65bd9f23bc0d99d04cefBuild 9a51c780c109 · ruleset 2026.07.19
Evidence that drives review
Native binary dist/bundled/bin/win32-arm64/pylance-service.exe has no companion checksum or signature file and no documented provenance.
2 observed locations · review evidence
YARA rule ide_scanner_embedded_pe matched dist/bundled/bin/win32-x64/pylance-service.exe.
1 observed location · review evidence
Extension contains 2 native artifacts (e.g. dist/bundled/bin/win32-arm64/pylance-service.exe).
1 observed location · review evidence