Back to extension profile
Extension Security Summary

YAML

redhat.vscode-yaml@1.25.2026082008
Security outcomeDo not install

Prevent execution pending review: high-confidence abuse-chain evidence matched (remote-vsix-install-chain). This is a preventive policy decision, not a confirmed-malicious label.

Checked version1.25.2026082008
Analysis statusCompleted
Scan date
What this means

The key information before you install.

This is a plain-language summary of the completed analysis for this exact extension version. Technical evidence and workspace actions are available after sign-in.

Permission Passport · exact release

What this extension can reach.

Six consistent access categories, tied to version 1.25.2026082008. Capability describes power—not malicious intent.

Current analysisLatest release @1.25.2026082008
3 categories observed@1.25.2026082008 analyzed releaseBound artifact identity
Workspace and filesystem accessFiles

Filesystem

Observed
Commands, processes, and install scriptsTerminal

Process Execution

Observed
Outbound connections and remote servicesNetwork

Network

Observed
Credentials, environment, and sensitive configurationSecrets

Not observed in this scan—not a guarantee of absence.

Not observed
Editor commands, webviews, and user interactionEditor

Not observed in this scan—not a guarantee of absence.

Not observed
AI models, autonomous tools, MCP, and delegationAgents & tools

Not observed in this scan—not a guarantee of absence.

Not observed
This passport never carries forward to another version.
Review evidence
Release context

Versions

1.25.2026082008Do not install1.25.2026081908Not analyzed1.25.2026081408Not analyzed1.25.2026080708Not analyzed1.25.2026080108Not analyzed1.25.2026073109Not analyzed