install-vscode-extension

Fail

Audited by Socket on Feb 27, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

This instruction/skill is a legitimate automation for installing VS Code extensions but represents a supply-chain and autonomy risk: it allows an agent to install arbitrary (including pre-release) extensions that will be downloaded and executed inside the user's editor. The explicit guidance to bypass checks (skipCheck: true) and the lack of source validation, version pinning, or enforced user confirmation increase the attack surface. There is no direct evidence of embedded malware or obfuscation in the instruction text itself, but using it without additional safeguards can enable installation of malicious extensions. Recommendations: require explicit per-install human confirmation, restrict/allowlist extension IDs or publishers, enforce marketplace origin and signature/version pinning where possible, avoid pre-release installs by default, and do not bypass existence/validation checks.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 27, 2026, 07:44 PM
Package URL
pkg:socket/skills-sh/microsoft%2Fvscode-copilot-chat%2Finstall-vscode-extension%2F@e36e454166239a16d2fce0c2e6c6913117fc783a