Exact artifact intelligence

Cline

saoudrizwan.claude-dev@4.0.8
Security outcomeReview needed

The extension exposes sensitive capabilities or non-confirmed risk evidence that needs context.

100% analysis coverage · exact version only
saoudrizwanopenvsxArtifact a92973db05d0c293
Security brief

Review decision-relevant behavior before installation.

Review the grouped evidence, affected locations, and whether each behavior matches the extension’s purpose.

57/100Review needed

Diagnostic risk index for this exact artifact — not a probability of malice.

OutcomeReview needed

Policy result for this exact artifact

Coverage
100

Required analyzers completed

Malware signal
0

Diagnostic index, not probability

Evidence groups5

15 contextual groups kept separate

Capabilities8

Power describes access, not intent

Why this outcome

5 behavior groups need context before approval.

undici@7.26.0 has 7 OSV finding(s). Version match: range-derived.

Exact artifacta92973db05d0c293b55a2f4fe348559be00267e55f0a257d2c5de59ce90ca170

Build fedc47d31ef5 · ruleset 2026.07.19

Evidence that drives review
MEDIUM
undici@7.26.0 has 7 OSV finding(s). Version match: range-derived.

9 observed locations · review evidence

MEDIUM
Code uses shell-style process execution.

6 observed locations · review evidence

MEDIUM
Extension webview in dist/extension.js declares a Content-Security-Policy with an unsafe directive (unsafe-inline, unsafe-eval, or a wildcard script-src).

1 observed location · review evidence