Policy result for this exact artifact
Exact artifact intelligence
Jupyter
ms-toolsai.jupyter@2026.6.2026071501Security outcomeReview needed
The extension exposes sensitive capabilities or non-confirmed risk evidence that needs context.
100% analysis coverage · exact version onlyms-toolsaivs-marketplaceArtifact
43fd50e5bba11c57Review decision-relevant behavior before installation.
Review the grouped evidence, affected locations, and whether each behavior matches the extension’s purpose.
58/100Review needed
Diagnostic risk index for this exact artifact — not a probability of malice.
100
Required analyzers completed
0
Diagnostic index, not probability
7 contextual groups kept separate
Power describes access, not intent
10 behavior groups need context before approval.
Call target resolved via computed member access: E[...](...) (line 1)
43fd50e5bba11c575bfd6bab5a922015b3272a2d61b317788c8002d2c90337dbBuild 9a51c780c109 · ruleset 2026.07.19
Evidence that drives review
Call target resolved via computed member access: E[...](...) (line 1)
24 observed locations · review evidence
Extension contains a native artifact: dist/node_modules/zeromq/prebuilds/win32-arm64/node.napi.glibc.node.
1 observed location · review evidence
Extension webview in dist/extension.node.js declares a Content-Security-Policy with an unsafe directive (unsafe-inline, unsafe-eval, or a wildcard script-src).
1 observed location · review evidence