About immutable reports
Future scans cannot replace the findings, coverage, ruleset, or artifact hash shown on this URL.
- Scan
f8b69ba0-fb45-4f83-a573-4ef3817539f6- Artifact
ed18caf3e3cd…cbf5be19
GitHub Copilot
GitHub.copilot@1.388.0Completed analysis for this exact extension version. Use the summary below to decide what your team should do next.
The extension exposes sensitive capabilities or non-confirmed risk evidence that needs context.
- Required action
- Record a team decision before approval
Review decision-relevant behavior before installation.
Review the grouped evidence, affected locations, and whether each behavior matches the extension’s purpose.
The extension exposes sensitive capabilities or non-confirmed risk evidence that needs context.
This result applies only to the scanned artifact SHA-256, not to future releases or a publisher generally.
Review the grouped evidence and record the accountable team decision before approval.
Required analysis completed for this exact artifact; evidence remains scoped to scanner coverage.
- 1Artifact boundExtension, version, hash, and scan identity fixed
- 2Analysis checkedExecutable-file coverage
- 3Evidence grouped1 actionable · 20 contextual
- 4Policy appliedExact-release ruleset evaluated
- 5Review neededCurrent decision for this artifact
Diagnostic risk index for this exact artifact — not a probability of malice.
Policy result for this exact artifact
7/7 required analyzers completed
Diagnostic index, not probability
20 contextual notes kept separate
Power describes access, not intent
1 behavior group needs context before approval.
The extension exposes sensitive capabilities or non-confirmed risk evidence that needs context.
ed18caf3e3cd23eac8b9141f0b0a6fb30022cfdf7575a7113b6a9885cbf5be19Build ebc6ba89193a · ruleset 2026.08.21-obfuscated-bundle.1
17 observed locations · review evidence