Back to extension profile
Extension Security Summary

Code Runner

formulahendry.code-runner@0.12.2
Security outcomeDo not install

Reject this exact artifact: authoritative vulnerability intelligence matched (known-vulnerable-extension). This is a vulnerability policy decision, not a malware label.

Checked version0.12.2
Analysis statusCompleted
Scan date
What this means

The key information before you install.

This is a plain-language summary of the completed analysis for this exact extension version. Technical evidence and workspace actions are available after sign-in.

Permission Passport · exact release

What this extension can reach.

Six consistent access categories, tied to version 0.12.2. Capability describes power—not malicious intent.

Current analysisLatest release @0.12.2
1 categories observed@0.12.2 analyzed releaseBound artifact identity
Workspace and filesystem accessFiles

Filesystem

Observed
Commands, processes, and install scriptsTerminal

Not observed in this scan—not a guarantee of absence.

Not observed
Outbound connections and remote servicesNetwork

Not observed in this scan—not a guarantee of absence.

Not observed
Credentials, environment, and sensitive configurationSecrets

Not observed in this scan—not a guarantee of absence.

Not observed
Editor commands, webviews, and user interactionEditor

Not observed in this scan—not a guarantee of absence.

Not observed
AI models, autonomous tools, MCP, and delegationAgents & tools

Not observed in this scan—not a guarantee of absence.

Not observed
This passport never carries forward to another version.
Review evidence
Release context

Versions

0.12.2Do not install0.12.1Not analyzed0.12.0Not analyzed0.11.8Not analyzed0.11.7Not analyzed0.11.6Not analyzed