Policy result for this exact artifact
Exact artifact intelligence
snyk-vulnerability-scanner
snyk-security.snyk-vulnerability-scanner@2.31.0Security outcomeReview needed
The extension exposes sensitive capabilities or non-confirmed risk evidence that needs context.
100% analysis coverage · exact version onlysnyk-securityvs-marketplaceArtifact
5e6ea92b390f7552Review decision-relevant behavior before installation.
Review the grouped evidence, affected locations, and whether each behavior matches the extension’s purpose.
75/100Review needed
Diagnostic risk index for this exact artifact — not a probability of malice.
100
Required analyzers completed
0
Diagnostic index, not probability
5 contextual groups kept separate
Power describes access, not intent
7 behavior groups need context before approval.
uuid@8.3.2 has 1 OSV finding(s). Version match: exact.
5e6ea92b390f755218f17b5fbee4273406909dbcf0bf33e273558546dc8998b4Build fedc47d31ef5 · ruleset 2026.07.19
Evidence that drives review
uuid@8.3.2 has 1 OSV finding(s). Version match: exact.
1 observed location · review evidence
Extension creates a webview in out/snyk/common/views/summaryWebviewProvider.js without a detected Content-Security-Policy meta tag.
8 observed locations · review evidence
Package defines a lifecycle script: vscode:uninstall.
1 observed location · review evidence