About immutable reports
Future scans cannot replace the findings, coverage, ruleset, or artifact hash shown on this URL.
- Scan
c226181b-7ab4-4a59-aea6-12329c524563- Artifact
b7ae0e17eaf1…c148cd4e
Kubernetes
ms-kubernetes-tools.vscode-kubernetes-tools@1.4.0Completed analysis for this exact extension version. Use the summary below to decide what your team should do next.
Prevent execution pending review: high-confidence abuse-chain evidence matched (remote-vsix-install-chain). This is a preventive policy decision, not a confirmed-malicious label.
- Required action
- Do not install this version
Hash-pinned as a credential sensitive case. The exact artifact identity matches the frozen cohort; the current decision above comes only from this scan's evidence.
This exact artifact should not be installed.
Inspect the evidence that supports this do-not-install policy decision.
Prevent execution pending review: high-confidence abuse-chain evidence matched (remote-vsix-install-chain). This is a preventive policy decision, not a confirmed-malicious label.
This result applies only to the scanned artifact SHA-256, not to future releases or a publisher generally.
Do not install this exact artifact. Record an exception only with accountable approval.
Required analysis completed for this exact artifact; evidence remains scoped to scanner coverage.
- 1Artifact boundExtension, version, hash, and scan identity fixed
- 2Analysis checkedExecutable-file coverage
- 3Evidence grouped1 actionable · 15 contextual
- 4Policy appliedExact-release ruleset evaluated
- 5Do not installCurrent decision for this artifact
Diagnostic risk index for this exact artifact — not a probability of malice.
Policy result for this exact artifact
7/7 required analyzers completed
Diagnostic index, not probability
15 contextual notes kept separate
Power describes access, not intent
1 evidence group support this do-not-install decision.
Prevent execution pending review: high-confidence abuse-chain evidence matched (remote-vsix-install-chain). This is a preventive policy decision, not a confirmed-malicious label.
b7ae0e17eaf14e98675abd413546311b4fd6fa000ff1dce2011a502bc148cd4eBuild 6aab1d4caaf6 · ruleset 2026.07.24-policy-v3-calibration.6
1 observed location · review evidence