Policy result for this exact artifact
Exact artifact intelligence
Cline
saoudrizwan.claude-dev@4.0.8Security outcomeReview needed
The extension exposes sensitive capabilities or non-confirmed risk evidence that needs context.
100% analysis coverage · exact version onlysaoudrizwanopenvsxArtifact
a92973db05d0c293Review decision-relevant behavior before installation.
Review the grouped evidence, affected locations, and whether each behavior matches the extension’s purpose.
57/100Review needed
Diagnostic risk index for this exact artifact — not a probability of malice.
100
Required analyzers completed
0
Diagnostic index, not probability
15 contextual groups kept separate
Power describes access, not intent
5 behavior groups need context before approval.
undici@7.26.0 has 7 OSV finding(s). Version match: range-derived.
a92973db05d0c293b55a2f4fe348559be00267e55f0a257d2c5de59ce90ca170Build fedc47d31ef5 · ruleset 2026.07.19
Evidence that drives review
undici@7.26.0 has 7 OSV finding(s). Version match: range-derived.
9 observed locations · review evidence
Code uses shell-style process execution.
6 observed locations · review evidence
Extension webview in dist/extension.js declares a Content-Security-Policy with an unsafe directive (unsafe-inline, unsafe-eval, or a wildcard script-src).
1 observed location · review evidence