Exact artifact intelligence

Dev Containers

ms-vscode-remote.remote-containers@0.467.0
Security outcomeReview needed

The extension exposes sensitive capabilities or non-confirmed risk evidence that needs context.

100% analysis coverage · exact version only
ms-vscode-remotevs-marketplaceArtifact b3bd40702da5dd7d
Security brief

Review decision-relevant behavior before installation.

Review the grouped evidence, affected locations, and whether each behavior matches the extension’s purpose.

56/100Review needed

Diagnostic risk index for this exact artifact — not a probability of malice.

OutcomeReview needed

Policy result for this exact artifact

Coverage
100

Required analyzers completed

Malware signal
0

Diagnostic index, not probability

Evidence groups9

11 contextual groups kept separate

Capabilities10

Power describes access, not intent

Why this outcome

9 behavior groups need context before approval.

Call target resolved via computed member access: ThisExpression[...][...](...) (line 34)

Exact artifactb3bd40702da5dd7d1a99aac697da5c437f28deeec899d0bb6e78dd76a5c1b012

Build fedc47d31ef5 · ruleset 2026.07.19

Evidence that drives review
MEDIUM
Call target resolved via computed member access: ThisExpression[...][...](...) (line 34)

16 observed locations · review evidence

MEDIUM
adm-zip@0.5.16 has 1 OSV finding(s). Version match: range-derived.

1 observed location · review evidence

MEDIUM
Code uses shell-style process execution.

1 observed location · review evidence