How Extuno scans an extension or package.
Every extension and package follows the same seven-stage path. Static, dynamic, and AI analysis feed a single verdict. Each finding under it carries its own evidence.
Each stage below emits SARIF or JSON you can open.
Acquire, static, sandbox, AI, diff, score, report. Each stage writes an artifact the next one reads.
Discover
Extuno finds the extension or package and every published version across its ecosystem, so nothing ships without being seen.
Acquire
It pulls the exact artifact for the version under review, untouched, into an isolated workspace.
Static analysis
1100+ rules read the code without running it. They catch capability abuse, remote-code, credential theft, evasion, and obfuscation.
Dynamic sandbox
The real artifact runs live in an ephemeral, network-segmented micro-VM that records every endpoint, payload, and API call.
Diff
Extuno compares the version against the one before it and reports exactly what this update changed. It flags anything dangerous in that delta.
Score
Static, dynamic, and AI findings are scored together. The scan comes back clean, review, or critical.
Report
The finding ships to your channels with the evidence attached. File, line, payload, why it is dangerous, and the recommended action.
All seven stages leave an artifact you can read.
Every stage emits a structured artifact in SARIF or JSON, plus a signed webhook. Inspect it, diff it, pipe it into your own tooling. Here is what the engine actually runs.
An ephemeral micro-VM per run.
Each artifact executes in its own throwaway, network-segmented VM. Nothing leaves except through a recording proxy, and the VM is destroyed the moment the run completes.
- + Full syscall, DNS, and HTTP(S) capture with exact payloads
- + Filesystem, clipboard, and credential-store diff plus screenshots
- + Deterministic replay from the captured trace
- + No egress to the open internet during analysis
$ extuno scan npm:[email protected] \ --diff 3.3.5 --sarif level rule location ------- --------------- ---------------------- error exfil.cookie flatmap-stream:42 error net.new-host cdn-metrics.io warning perm.escalation package.json verdict: critical
The result: a verdict you can act on.
Clean, review, or critical. Every finding traces back to the change that caused it.