Analyze your code, identify security vulnerabilities, receive AI-powered remediation guidance, and interact with Conviso AI—all without leaving Visual Studio Code.
Analyze code and receive AI-powered security recommendations.
Detect potential vulnerabilities, understand the risks, and receive practical remediation guidance without leaving your editor.
Automatically generate secure code fixes.
Apply AI-assisted fixes directly to your code, speeding up vulnerability remediation and improving code quality.
Review vulnerabilities from Conviso Platform.
Browse application and repository vulnerabilities, inspect details, and update their status directly from Visual Studio Code.
Track security requirements and pipeline breaks.
Stay aligned with your application's security requirements and quickly investigate pipeline failures related to security findings.
Chat with Conviso AI using your project context.
Attach code selections and workspace context to receive more accurate security guidance and development assistance.
Run local repository security analysis.
Execute repository security checks directly from your editor to identify issues before committing or opening a pull request.
🔑 Getting Access
To use the extension, you need a Conviso Platform account and valid credentials.
If you don't have an account yet, you can sign up or start a free trial:
👉 https://resources.convisoappsec.com/en/convisoplatform-free
🛠️ Installation & Configuration
✅ Install the Extension
- Open Visual Studio Code.
- Go to the Extensions view (
Ctrl+Shift+X or ⌘⇧X on macOS).
- Search for Conviso Platform and install the extension.
- Reload Visual Studio Code if prompted.
- Input settings and API key when prompted
🚀 How to Use
Open the Conviso view from the Visual Studio Code Activity Bar.
Choose the feature you want to use:
- AI Autonomous AppSec — Ask security questions, analyze code, or request AI-assisted fixes.
- Vulnerabilities — Review and manage vulnerabilities from Conviso Platform.
- Repository Vulnerabilities — Explore findings detected in your repository.
- Projects and Requirements — View your projects and application's security requirements.
- Pipeline Breaks — Investigate security-related pipeline failures.
Use the available editor actions or commands to analyze code, request secure code suggestions, or run repository security analysis directly from Visual Studio Code.
⌨️ Available Commands
Open the Visual Studio Code Command Palette (Ctrl+Shift+P or ⌘⇧P on macOS) and search for Conviso Platform. The extension provides the following commands:
AI Chat
| Command |
Description |
Conviso Platform: Open Chat |
Open Conviso AI Chat and automatically connect to the configured chat channel. |
Conviso Platform: Configure Chat Endpoint |
Set or change the endpoint used by the chat channel. |
Conviso Platform: Connect |
Manually connect to the configured chat channel. |
Conviso Platform: Send Chat Message |
Send a message to Conviso AI from Visual Studio Code. |
Conviso Platform: Disconnect |
Disconnect from the active chat channel. |
| Command |
Description |
Conviso Platform: Configure API Access |
Configure access to Conviso Platform. The extension uses your API key to discover the required account settings automatically. |
Conviso Platform: Refresh Vulnerabilities |
Retrieve the latest vulnerabilities directly from Conviso Platform. |
Conviso Platform: Refresh Requirements |
Retrieve the latest projects, security requirements, and activities directly from Conviso Platform. |
Conviso Platform: Open Vulnerability Details |
Open the complete details of the selected vulnerability. |
Conviso Platform: Update Item Status |
Update the status of the selected vulnerability and provide the required reason. |
You can also access contextual commands from the Conviso views. For example, select a vulnerability to open its details, or right-click it to update its status.
💡 Pro Tip
Use Conviso Platform throughout your development workflow—not only to remediate vulnerabilities, but also to understand security issues, review repository findings, and receive AI-assisted guidance while you code.
Build secure software without leaving Visual Studio Code using Conviso Platform.