35 karma · joined June 24, 2025
Despite their best efforts, the marketplace is getting increasingly dangerous. The list published here is of malicious extensions that were discovered only after allowing them free reign on the marketplace - imagine how many are still out there.
The paper outlines a 3-part automated system: 1. Risk profile VS Code Extensions 2. Generate per-extension sandboxing policies automatically 3. Enforce sandboxing at runtime without disrupting existing system
The goal was an extremely low-profile system that doesn't require additional software. This could be an important asset in the increasingly dangerous and unregulated VSCode extension ecosystem.
Btw, the risk-profiling section is an evolution of my free extension scanner vscan.dev. If you any questions about vscan.dev, you can reach out at vscandevteam@gmail.com.
I restricted it to one expanded at a time since more than one felt a bit crowded but that's something I might look into.
As for the raw name, most extensions should work if you just put the display name. The search algorithm directly pulls from the vscode marketplace.