feat(llm-security): add /security ide-scan — VS Code / JetBrains extension prescan (v6.3.0)

New standalone scanner (prefix IDE) discovers installed VS Code extensions
across forks (Cursor, Windsurf, VSCodium, code-server, Insiders, Remote-SSH)
and runs 7 IDE-specific threat checks: blocklist match (CRITICAL),
theme-with-code, sideload (unsigned .vsix), dangerous uninstall hook (HIGH),
wildcard activation, extension-pack expansion, typosquat (MEDIUM).

Per-extension reuse of UNI/ENT/NET/TNT/MEM/SCR scanners with bounded
concurrency. Offline-first; --online opt-in. JetBrains discovery stubbed
for v1.1. 22 new tests (1296 total, was 1274).

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
This commit is contained in:
Kjell Tore Guttormsen 2026-04-17 16:23:35 +02:00
commit 6252e55700
33 changed files with 1849 additions and 20 deletions

View file

@ -0,0 +1,6 @@
// benign-ext entry point
function activate(context) {
console.log('benign-ext activated');
}
function deactivate() {}
module.exports = { activate, deactivate };

View file

@ -0,0 +1,14 @@
{
"publisher": "publisher",
"name": "benign-ext",
"version": "1.0.0",
"displayName": "Benign Extension",
"description": "A normal extension with no issues",
"engines": { "vscode": "^1.80.0" },
"main": "./extension.js",
"activationEvents": ["onCommand:benign.hello"],
"contributes": {
"commands": [{ "command": "benign.hello", "title": "Say Hello" }]
},
"categories": ["Other"]
}