About immutable reports
Future scans cannot replace the findings, coverage, ruleset, or artifact hash shown on this URL.
- Scan
112d3817-1884-4adf-8669-64a889fe9159- Artifact
e05cf0f98231…092db966
C/C++
ms-vscode.cpptools@1.33.4Completed analysis for this exact extension version. Use the summary below to decide what your team should do next.
The extension exposes sensitive capabilities or non-confirmed risk evidence that needs context.
- Required action
- Record a team decision before approval
Review decision-relevant behavior before installation.
Review the grouped evidence, affected locations, and whether each behavior matches the extension’s purpose.
The extension exposes sensitive capabilities or non-confirmed risk evidence that needs context.
This result applies only to the scanned artifact SHA-256, not to future releases or a publisher generally.
Review the grouped evidence and record the accountable team decision before approval.
Required analysis completed for this exact artifact; evidence remains scoped to scanner coverage.
- 1Artifact boundExtension, version, hash, and scan identity fixed
- 2Analysis checkedExecutable-file coverage
- 3Evidence grouped0 actionable · 20 contextual
- 4Policy appliedExact-release ruleset evaluated
- 5Review neededCurrent decision for this artifact
Diagnostic risk index for this exact artifact — not a probability of malice.
Policy result for this exact artifact
6/6 required analyzers completed
Diagnostic index, not probability
20 contextual notes kept separate
Power describes access, not intent
No behavior group currently requires review.
The extension exposes sensitive capabilities or non-confirmed risk evidence that needs context.
e05cf0f982318849bae3ddf2ce930954826ad7075095e05c685befb8092db966Build 700e9036a4de · ruleset 2026.07.24-policy-v3-calibration.6