Thanks for your thoughts on the license; we know that it's FRAUGHT, for sure. Our company makes quite a lot of software available under OSI-approved licenses (MIT, etc) and we did think pretty carefully about what to try here, given our goals around both OSS and building a sustainable business.
We do use OpenVSX, yes, like the other forks, and our company is a major sponsor of OpenVSX. Security around the extension ecosystem is a pretty messy, complicated issue both for the proprietary Microsoft marketplace and OpenVSX. For example, the recent Amazon Q story! I currently think about it as conceptually fairly similar to the risks of using packages from PyPI or npm.