VS Code command: URI execution from untrusted workspace source editor

This rule detects the use of the VS Code command line interface to install extensions, specifically by monitoring for the 'workbench.extensions.installExtension' command. This activity can be indicative of automated installation of extensions, which could be used for malicious purposes or persistence if an attacker installs a malicious extension.