Back to extension profile
Immutable Deep Scan reportEvidence is locked to this exact artifact and scan.
About immutable reports

Future scans cannot replace the findings, coverage, ruleset, or artifact hash shown on this URL.

Scan
d89d1fea-fbe5-40a0-85f3-56d2de4b0a1c
Artifact
7edf45e8e93f…8abe18b8
Analysis Report

Python

ms-python.python@2026.5.2026070801

Completed analysis for this exact extension version. Use the summary below to decide what your team should do next.

Scan resultDo not install

Prevent execution pending review: high-confidence abuse-chain evidence matched (remote-vsix-install-chain). This is a preventive policy decision, not a confirmed-malicious label.

Required action
Do not install this version
Export evidence
Decision nowPrevent execution pending review: high-confidence abuse-chain evidence matched (remote-vsix-install-chain). This is a preventive policy decision, not a confirmed-malicious label.Exact artifact only
Actionable evidence115 contextual notes
Capabilities9Observed powers, not intent
Coverage100%Executable-file coverage
Package scope100029 dependencies
Frozen regression fixtureThis exact artifact is in the GuardRails regression corpus.

Hash-pinned as a legitimate privileged case. The exact artifact identity matches the frozen cohort; the current decision above comes only from this scan's evidence.

ms-pythonvs-marketplaceVersion 2026.5.2026070801
Security brief

This exact artifact should not be installed.

Inspect the evidence that supports this do-not-install policy decision.

What changed

Prevent execution pending review: high-confidence abuse-chain evidence matched (remote-vsix-install-chain). This is a preventive policy decision, not a confirmed-malicious label.

Why it matters

This result applies only to the scanned artifact SHA-256, not to future releases or a publisher generally.

Recommended action

Do not install this exact artifact. Record an exception only with accountable approval.

Analysis limits

Required analysis completed for this exact artifact; evidence remains scoped to scanner coverage.

  1. 1Artifact boundExtension, version, hash, and scan identity fixed
  2. 2Analysis checkedExecutable-file coverage
  3. 3Evidence grouped1 actionable · 15 contextual
  4. 4Policy appliedExact-release ruleset evaluated
  5. 5Do not installCurrent decision for this artifact
96/100Do not install

Diagnostic risk index for this exact artifact — not a probability of malice.

OutcomeDo not install

Policy result for this exact artifact

Executable-file coverage
100

7/7 required analyzers completed

Malware signal
0

Diagnostic index, not probability

Evidence groups1

15 contextual notes kept separate

Capabilities9

Power describes access, not intent

Why this outcome

1 evidence group support this do-not-install decision.

Prevent execution pending review: high-confidence abuse-chain evidence matched (remote-vsix-install-chain). This is a preventive policy decision, not a confirmed-malicious label.

Exact artifact7edf45e8e93fd155373fdf80000c56e75344e519442ba570b453da318abe18b8

Build 6aab1d4caaf6 · ruleset 2026.07.24-policy-v3-calibration.6

Evidence supporting this decision
HIGH
Code downloads a VSIX, writes it locally, and invokes the IDE extension installer without visible integrity verification.

1 observed location · review evidence