vsce-skills
Pass
Audited by Gen Agent Trust Hub on May 1, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill functions as a structured learning path and reference for VS Code extension development. No malicious behavior, prompt injection, or obfuscation was detected.
- [EXTERNAL_DOWNLOADS]: The skill documentation recommends the installation of standard, well-known development utilities such as
yo,generator-code, and@vscode/vscefrom the official NPM registry. These are industry-standard tools for the VS Code ecosystem. - [COMMAND_EXECUTION]: Includes standard code examples for the VS Code API namespaces (e.g.,
commands,window,workspace). These are correctly used within the context of extension development tutorials. - [DATA_EXFILTRATION]: Guidance on publishing extensions involves the standard use of Personal Access Tokens (PAT) and the official Microsoft Marketplace management portal. No unauthorized data collection or exfiltration patterns were observed.
Audit Metadata