NYC

vscode-test-setup

Fail

Audited by Socket on Feb 16, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
scripts/setup-test-env.py

The provided script is a benign scaffolding utility designed to set up testing for a VS Code extension. As presented it is syntactically incomplete and will not run until placeholder content is filled in. There is no direct evidence of data exfiltration, backdoors, or obfuscated malicious payloads in the visible code. The primary security concern is supply-chain exposure: the script executes `npm install` with unpinned package names (and thus pulls code from the network and executes package lifecycle scripts), and it performs filesystem writes that can overwrite project artifacts. Treat this as low-malware-risk but moderate operational/security risk: review and pin dependency versions, inspect packages before install, run with dry-run first, and back up project files before executing.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 16, 2026, 12:48 PM
Package URL
pkg:socket/skills-sh/s-hiraoku%2Fvscode-sidebar-terminal%2Fvscode-test-setup%2F@52b9af7482654f44416a0d6ad5767b5194b06539