Back to extension profile
Extension Security Summary

GitHub Copilot Chat

GitHub.copilot-chat@0.48.1
Security outcomeReview needed

The extension exposes sensitive capabilities or non-confirmed risk evidence that needs context.

Checked version0.48.1
Analysis statusCompleted
Scan date
What this means

The key information before you install.

This is a plain-language summary of the completed analysis for this exact extension version. Technical evidence and workspace actions are available after sign-in.

Permission Passport · exact release

What this extension can reach.

Six consistent access categories, tied to version 0.48.1. Capability describes power—not malicious intent.

Current analysisLatest release @0.48.1
5 categories observed@0.48.1 analyzed releaseBound artifact identity
Workspace and filesystem accessFiles

Filesystem · Agent Filesystem · Destructive File Activity

Observed
Commands, processes, and install scriptsTerminal

Agent Shell · Lifecycle Scripts · Process Execution

Observed
Outbound connections and remote servicesNetwork

Network · Agent Network

Observed
Credentials, environment, and sensitive configurationSecrets

Not observed in this scan—not a guarantee of absence.

Not observed
Editor commands, webviews, and user interactionEditor

Ide Contributions

Observed
AI models, autonomous tools, MCP, and delegationAgents & tools

Agentic · Agent Shell · Agent Network · Agent Filesystem

Observed
This passport never carries forward to another version.
Review evidence
Release context

Versions

0.48.1Review needed0.45.1Not analyzed0.44.2Not analyzed0.44.1Not analyzed0.43.0Not analyzed0.43.2026040705Not analyzed