Policy result for this exact artifact
Exact artifact intelligence
Jupyter
ms-toolsai.jupyter@2026.6.2026071001Security outcomeReview needed
The extension exposes sensitive capabilities or non-confirmed risk evidence that needs context.
100% analysis coverage · exact version onlyms-toolsaivs-marketplaceArtifact
e35e1d43645852e1Review decision-relevant behavior before installation.
Review the grouped evidence, affected locations, and whether each behavior matches the extension’s purpose.
58/100Review needed
Diagnostic risk index for this exact artifact — not a probability of malice.
100
Required analyzers completed
0
Diagnostic index, not probability
7 contextual groups kept separate
Power describes access, not intent
10 behavior groups need context before approval.
Call target resolved via computed member access: CallExpression[...](...) (line 1)
e35e1d43645852e1b343105be910431af4a5331d78ba317d8df553f65de50616Build 9a51c780c109 · ruleset 2026.07.19
Evidence that drives review
Call target resolved via computed member access: CallExpression[...](...) (line 1)
24 observed locations · review evidence
Native binary dist/node_modules/zeromq/prebuilds/linux-arm64/node.napi.glibc.node has no companion checksum or signature file and no documented provenance.
3 observed locations · review evidence
Extension contains 3 native artifacts (e.g. dist/node_modules/zeromq/prebuilds/linux-arm64/node.napi.glibc.node).
1 observed location · review evidence