Back to extension profile
Immutable Deep Scan reportEvidence is locked to this exact artifact and scan.
About immutable reports

Future scans cannot replace the findings, coverage, ruleset, or artifact hash shown on this URL.

Scan
721d055e-f9b1-4c92-869e-e8f3cc7d4302
Artifact
4c8e4aea7dd0…af03b144
Analysis Report

Code Runner

formulahendry.code-runner@0.12.2

Completed analysis for this exact extension version. Use the summary below to decide what your team should do next.

Scan resultDo not install

Reject this exact artifact: authoritative vulnerability intelligence matched (known-vulnerable-extension). This is a vulnerability policy decision, not a malware label.

Required action
Do not install this version
Export evidence
Decision nowReject this exact artifact: authoritative vulnerability intelligence matched (known-vulnerable-extension). This is a vulnerability policy decision, not a malware label.Exact artifact only
Actionable evidence27 contextual notes
Capabilities2Observed powers, not intent
Coverage100%Executable-file coverage
Package scope1643 dependencies
formulahendryvs-marketplaceVersion 0.12.2
Security brief

This exact artifact should not be installed.

Inspect the evidence that supports this do-not-install policy decision.

What changed

Reject this exact artifact: authoritative vulnerability intelligence matched (known-vulnerable-extension). This is a vulnerability policy decision, not a malware label.

Why it matters

This result applies only to the scanned artifact SHA-256, not to future releases or a publisher generally.

Recommended action

Do not install this exact artifact. Record an exception only with accountable approval.

Analysis limits

Required analysis completed for this exact artifact; evidence remains scoped to scanner coverage.

  1. 1Artifact boundExtension, version, hash, and scan identity fixed
  2. 2Analysis checkedExecutable-file coverage
  3. 3Evidence grouped2 actionable · 7 contextual
  4. 4Policy appliedExact-release ruleset evaluated
  5. 5Do not installCurrent decision for this artifact
99/100Do not install

Diagnostic risk index for this exact artifact — not a probability of malice.

OutcomeDo not install

Policy result for this exact artifact

Executable-file coverage
100

7/7 required analyzers completed

Malware signal
0

Diagnostic index, not probability

Evidence groups2

7 contextual notes kept separate

Capabilities2

Power describes access, not intent

Why this outcome

2 evidence groups support this do-not-install decision.

Reject this exact artifact: authoritative vulnerability intelligence matched (known-vulnerable-extension). This is a vulnerability policy decision, not a malware label.

Exact artifact4c8e4aea7dd07c9c20173e71869759fb2ce2f55b9819c4b374172467af03b144

Build ebc6ba89193a · ruleset 2026.08.21-obfuscated-bundle.1

Evidence supporting this decision
HIGH
The configurable executor command reaches shell-enabled process execution, allowing arbitrary command execution when configuration is attacker-controlled.

1 observed location · block evidence

HIGH
micromatch@4.0.2 has 1 OSV finding(s). Version match: exact.

1 observed location · review evidence