Policy result for this exact artifact
Exact artifact intelligence
rust-analyzer
rust-lang.rust-analyzer@0.4.2976Security outcomeReview needed
The extension exposes sensitive capabilities or non-confirmed risk evidence that needs context.
100% analysis coverage · exact version onlyrust-langvs-marketplaceArtifact
5ff02c55c7d5a732Review decision-relevant behavior before installation.
Review the grouped evidence, affected locations, and whether each behavior matches the extension’s purpose.
41/100Review needed
Diagnostic risk index for this exact artifact — not a probability of malice.
100
Required analyzers completed
0
Diagnostic index, not probability
6 contextual groups kept separate
Power describes access, not intent
3 behavior groups need context before approval.
Call target resolved via computed member access: d[...](...) (line 42)
5ff02c55c7d5a7326e1a5087da6f680e73e14350602d6131b6e86c260e7f3085Build fedc47d31ef5 · ruleset 2026.07.19
Evidence that drives review
Call target resolved via computed member access: d[...](...) (line 42)
5 observed locations · review evidence
Extension creates a webview in out/main.js without a detected Content-Security-Policy meta tag.
1 observed location · review evidence
Extension contributes IDE capability: taskDefinitions.
1 observed location · review evidence