LorySecurity review while you write, not three weeks after you ship.
Lory is Lorikeet Security's AI security analyst. This extension puts it in your editor: it reads the file you are working on and marks the lines that carry a vulnerability, as you write them. Findings land as ordinary editor diagnostics. They squiggle in the gutter, count in the Problems panel, and carry a quick fix. There is no separate panel to check and no scan to remember to run. What it catchesInjection reachable from user input (SQL, OS command, template, deserialization, path traversal, XXE), hardcoded secrets and private keys, missing authorisation on sensitive handlers, broken crypto and predictable randomness, unsafe DOM sinks, SSRF, insecure direct object references, and unsafe framework, container, and cloud configuration. It deliberately does not report style, formatting, naming, or performance. A security marker on a style nit teaches you to ignore security markers. InstallSearch Lory in the Extensions view, or:
No account, no API key, no configuration. The first time it wants to review something it asks permission, once. How it works
Every line sent is numbered before it reaches the model, so a finding points at the statement that causes it rather than a line the model counted to. Findings whose line number falls outside the reviewed range are discarded rather than moved to the nearest line: a marker on innocent code is worse than a marker you never saw. Reviews are cached by content hash. Editing a comment and pressing save does not spend a request, and neither does switching tabs and back. Using it
Ignore comments
Settings
What leaves your machineReviewing code means uploading it. The extension asks before the first review and
does nothing until you agree. Sent, per review:
Not sent, ever: any other file, your repository, its git history, its remotes, your credentials, or your workspace layout. The extension reads no file you do not have open, and the request carries no identifier tying it to you or your machine. Nothing is retained after the review returns. If a path must never be uploaded, put it in
LimitsIt reviews a fragment, not a system. It usually cannot see the caller, your
middleware, or your ORM's escaping, so it states the precondition and marks its
confidence rather than guessing. Filter on It is an assistant, not an audit. It finds defects that are visible in source. It does not prove exploitability, and a clean file is not a certified one. For an actual assessment, Lorikeet runs penetration tests that a human reviews and signs. Requests are rate limited. Thirty a minute anonymously, keyed to your IP — generous
for one developer and tight for a team behind one egress address. If you hit it, raise
Rate limits and access tokens
Run Lory: Set Access Token and paste the The token buys throughput and nothing else. This endpoint reads no finding, no engagement, and nothing else belonging to your company, so the token grants no data access here — it only identifies you well enough to give you your own bucket. It is stored in VS Code's Development
The logic worth testing is deliberately free of
Server sideThe extension talks to LegalUse this on code you are authorised to review. Findings are advisory and reviewing code with it does not constitute a penetration test, a security audit, or a compliance attestation. LicenseMIT. See LICENSE. |