About immutable reports
Future scans cannot replace the findings, coverage, ruleset, or artifact hash shown on this URL.
- Scan
8b589d8a-f791-44d9-8153-f60cfcc49b15- Artifact
c7fb78223cf1…7a709bbe
Azure Account
ms-vscode.azure-account@0.13.0Completed analysis for this exact extension version. Use the summary below to decide what your team should do next.
The extension exposes sensitive capabilities or non-confirmed risk evidence that needs context.
- Required action
- Record a team decision before approval
Hash-pinned as a credential sensitive case. The exact artifact identity matches the frozen cohort; the current decision above comes only from this scan's evidence.
Review decision-relevant behavior before installation.
Review the grouped evidence, affected locations, and whether each behavior matches the extension’s purpose.
The extension exposes sensitive capabilities or non-confirmed risk evidence that needs context.
This result applies only to the scanned artifact SHA-256, not to future releases or a publisher generally.
Review the grouped evidence and record the accountable team decision before approval.
Required analysis completed for this exact artifact; evidence remains scoped to scanner coverage.
- 1Artifact boundExtension, version, hash, and scan identity fixed
- 2Analysis checkedExecutable-file coverage
- 3Evidence grouped1 actionable · 10 contextual
- 4Policy appliedExact-release ruleset evaluated
- 5Review neededCurrent decision for this artifact
Diagnostic risk index for this exact artifact — not a probability of malice.
Policy result for this exact artifact
7/7 required analyzers completed
Diagnostic index, not probability
10 contextual notes kept separate
Power describes access, not intent
1 behavior group needs context before approval.
The extension exposes sensitive capabilities or non-confirmed risk evidence that needs context.
c7fb78223cf1b0e1afd380734835ab43f2e1778276989fe25f0b755d7a709bbeBuild 6aab1d4caaf6 · ruleset 2026.07.24-policy-v3-calibration.6
5 observed locations · review evidence