0.11.0

    Datamates

    Empower your data engineering with the Datamates — intelligent, secure, and seamlessly integrated into your development environment.

    Rank#-993
    Publisher altimateaiRegistry openvsx227,504Last scanned Sep 23, 2026, 04:15 PMRegistryHomepageGitHub

    Security Findings

    21

    Dynamic exec of remote content (VSX)

    SuspiciousScanner

    Download-and-execute in webview_panels/dist/assets/index.js: curl -fsSL https://www.altimate.sh/install | bash

    webview_panels/dist/assets/index.js

    Dynamic exec of remote content (VSX)

    SuspiciousScanner

    Fetched content reaches a dynamic exec sink in dist/datamate-cli.js: fetch(

    dist/datamate-cli.js

    Dynamic exec of remote content (VSX)

    SuspiciousScanner

    Fetched content reaches a dynamic exec sink in dist/extension.js: fetch(

    dist/extension.js

    Dynamic exec of remote content (VSX)

    SuspiciousScanner

    Fetched content reaches a dynamic exec sink in dist/pyodide/pyodide.asm.js: fetch(

    dist/pyodide/pyodide.asm.js

    Dynamic exec of remote content (VSX)

    SuspiciousScanner

    Fetched content reaches a dynamic exec sink in dist/pyodide/pyodide.js: fetch(

    dist/pyodide/pyodide.js

    Hardcoded secrets/API keys6×

    SuspiciousScanner

    Secret Keyword: https...****

    Secret Keyword: Basic...****

    Secret Keyword: ****

    Secret Keyword: priva...****

    Private Key: BEGIN...****

    Secret Keyword: use s...****

    dist/datamate-cli.js

    Hardcoded secrets/API keys7×

    SuspiciousScanner

    Secret Keyword: Basic...****

    Secret Keyword: ****

    Secret Keyword: priva...****

    Private Key: BEGIN...****

    Secret Keyword: use s...****

    Secret Keyword: https...****

    Secret Keyword: altim...****

    dist/extension.js

    Sensitive file access

    SuspiciousScanner

    Access to sensitive file: /etc/passwd

    Dangerous security bypass flags

    SuspiciousScanner

    Bypass flag in content: --trust

    Install-lifecycle script shipped

    SuspiciousScanner

    package.json postinstall script is shipped (inert on VSIX install but a build-hygiene / dev-tooling tell): patch-package && husky