Exact artifact intelligence

C/C++

ms-vscode.cpptools@1.33.4
Security outcomeReview needed

The extension exposes sensitive capabilities or non-confirmed risk evidence that needs context.

100% analysis coverage · exact version only
ms-vscodevs-marketplaceArtifact e05cf0f982318849
Security brief

Review decision-relevant behavior before installation.

Review the grouped evidence, affected locations, and whether each behavior matches the extension’s purpose.

63/100Review needed

Diagnostic risk index for this exact artifact — not a probability of malice.

OutcomeReview needed

Policy result for this exact artifact

Coverage
100

Required analyzers completed

Malware signal
0

Diagnostic index, not probability

Evidence groups11

12 contextual groups kept separate

Capabilities12

Power describes access, not intent

Why this outcome

11 behavior groups need context before approval.

Native binary debugAdapters/bin/mscorlib.dll has no companion checksum or signature file and no documented provenance.

Exact artifacte05cf0f982318849bae3ddf2ce930954826ad7075095e05c685befb8092db966

Build 8c83a1c11c79 · ruleset 2026.07.19

Evidence that drives review
MEDIUM
Native binary debugAdapters/bin/mscorlib.dll has no companion checksum or signature file and no documented provenance.

195 observed locations · review evidence

MEDIUM
YARA rule ide_scanner_embedded_pe matched debugAdapters/bin/libcoreclr.so.

5 observed locations · review evidence

MEDIUM
Code uses shell-style process execution.

1 observed location · review evidence