Taskit — AI code review tasks for VS Code
Taskit adds a sidebar to Visual Studio Code. It asks the AI model you choose (Google Gemini, OpenAI or Anthropic Claude) to review your workspace, and turns what it finds into tasks in three tabs:
Tick a task and, after you confirm, Taskit has the AI carry it out. It shows live progress, checks every change and makes it undoable.
Your code is sent to the AI provider you select, and to nobody else. Read Privacy and security before you use Taskit on code you are not allowed to share with that provider.
Contents
Features
Three providers, your choice.
- Choose Google (Gemini), OpenAI or Anthropic (Claude) from a dropdown.
- Taskit loads the models your API key can use straight from the provider's API. If that isn't possible, it falls back to a maintained list.
Your API key is protected.
- Keys are kept in VS Code's secret storage, which uses the macOS Keychain, the Windows Credential Manager or libsecret on Linux.
- Once saved, a key is only ever shown masked, as
sk-proj-••••3456.
- You can replace or remove a key at any time.
Check now.
- Collects the relevant parts of your workspace, sends them to your provider, and gets back at most 10 findings as strict JSON.
- The response is validated before anything is added.
- Progress is real (collecting context, waiting for the AI, receiving, validating), and you can cancel at any time.
Cards you can act on. Each card shows:
- the category, priority and date found (Found: 27 Sep 2026)
- the title and a short description
- a link to the file and line
- a checkmark and a remove button
Each card also holds a hidden, AI-written task prompt. It is never shown in the UI and is used only when the task runs.
Task execution you stay in control of.
- The checkmark always asks Execute task? first. Cancel does nothing.
- Execute runs the task through visible phases (Planning, Applying changes, Validation, Done), streaming the AI response.
- A success marks the task completed and saves that.
- A failure shows the error, leaves the task open and offers Retry.
No duplicates. Taskit fingerprints every finding and compares it with the ones already tracked, both open and completed, so work you've finished is never recreated.
Tidy lists.
- A Show completed toggle that is remembered.
- Remove asks for confirmation first.
- Tasks are stored per workspace and survive restarts.
Built for VS Code.
- Works with light, dark and high-contrast themes.
- Fully usable from the keyboard.
- Supports multi-root workspaces.
- Uses the editor's undo, and respects unsaved editors.
- Honours
.gitignore.
Installation
- In VS Code, open the Extensions view: ⇧⌘X on macOS, Ctrl+Shift+X on Windows and Linux.
- Search for Taskit and click Install.
The Taskit icon (a checklist with a sparkle) then appears in the Activity Bar.
Requirements
- VS Code 1.95 or later.
- An API key for at least one supported provider.
- A folder or workspace opened in a trusted window.
Getting started
- Open Taskit. Click the Taskit icon in the Activity Bar.
- Set up the provider. Click Set up AI provider, or the ⚙ gear.
- Choose a Provider.
- Paste your API key. The Get an API key link opens the right page for your provider.
- Taskit loads the models your key can use. Pick one, or choose Enter a model id… to type one.
- Optionally pick an Analysis depth (see Settings).
- Click Test connection to send a tiny request, or go straight to Save. Save checks the key with the provider first, and a key the provider rejects is not saved.
- Run a check. Click Check now. It stays disabled, with a hint explaining why, until a provider, key and model are configured.
- Review the tasks in the Errors, Features and Security tabs.
- Carry one out. Click a task's circle and confirm with Execute.
Using Taskit
- The header shows the active provider and model, for example
OpenAI · gpt-5, and a gear button for settings.
- The prominent Check now button sits below it.
- While a check is running, the button turns into Cancel check. A progress card then shows each stage:
- Collect project context, with a real progress bar.
- Review by <provider>, with the number of characters received so far.
- Validate findings.
- VS Code's own progress bar also runs along the top of the view.
Tabs and cards
- Each tab shows how many tasks are still open.
- Cards are sorted by priority (critical, high, medium, low), then newest first. Completed cards come after them.
- Each card shows:
- The category, priority and Found date. Hover over the date for the exact time.
- The title and description. Long descriptions fold up; use Show more to expand them.
- The location (
src/index.ts:42). Click it to open the file at that line.
- A checkmark (empty circle) and a remove (🗑) button.
- A ⋯ menu with Execute task…, Mark as completed / Mark as not completed, Open file and Remove task….
- When a task is completed, the circle turns into a filled green check and the title is struck through. The card also shows:
- Completed: <date>
- a summary of what was done
- the files that were changed or created
- any follow-up steps for you, such as "run
npm test", since Taskit never runs commands itself
- Show completed hides or shows completed tasks and is remembered. When everything in a tab is done and hidden, the tab says so.
Executing a task
Click the circle. VS Code asks Execute task?, naming the task and the provider its files will be sent to.
Cancel closes the dialog. The task stays exactly as it was.
Execute starts the task. The card shows the live steps:
- Analyzing relevant files
- Planning changes
- Updating <file> (one step per file)
- Applying changes
- Running validation
A phase bar (Plan › Apply › Validate › Done) shows where the task is.
Every step reflects real work; nothing is animated for show.
On success, the changes are applied through the editor, so Undo (⌘Z / Ctrl+Z) reverts them. The changed files are saved, and the task is marked completed and stored.
On failure, the card shows the error and the step that failed, and nothing is left half-changed. The task stays open with Retry. After a restart, the card still shows the last error with a Retry link.
Cancel is available while a task runs. Only one AI operation runs at a time.
Supported providers and models
| Provider |
API used |
Models listed |
Key header |
| Google (Gemini) |
generativelanguage.googleapis.com v1beta, streamGenerateContent (SSE) |
Every model that supports generateContent, except embedding, image, audio and live models |
x-goog-api-key, never in the URL |
| OpenAI |
api.openai.com Responses API, streamed, store: false |
GPT, o-series, ChatGPT and Codex text models |
Authorization: Bearer |
| Anthropic (Claude) |
api.anthropic.com Messages API, streamed |
All Claude models (paginated) |
x-api-key |
If model discovery fails for any reason other than a rejected key, for example no network, Taskit shows a maintained fallback list and explains why. The fallback list is:
- Gemini: 2.5 Pro, Flash and Flash-Lite.
- OpenAI: GPT-5, GPT-5 mini, GPT-4.1, GPT-4.1 mini and o4-mini.
- Claude: Opus 5.5, Sonnet 5, Sonnet 4.5 and Haiku 4.5.
You can always type a model id by hand.
Taskit asks each provider for JSON output where the API supports it. If a model rejects that option, Taskit retries once without it.
How it works
Check now
Collect context. Taskit walks the workspace folders without following symbolic links.
- It skips anything excluded (see below).
- It reads open editors first, so unsaved changes are included.
- It scores every eligible file:
- project manifests and configuration rank highest
- then source and markup
- files open in editors get a boost
- tests, migrations and tiny files rank lower
- It fills a token budget in score order. The budget is set by Analysis depth and never exceeds 60% of the model's context window.
- Large files keep their start and end, with a clear marker in between.
- The prompt also includes a compact file tree and the detected projects (package.json, pyproject.toml, *.csproj, go.mod, Cargo.toml, …).
Redact. Before anything leaves your machine, Taskit replaces recognizable credentials with [REDACTED]:
- API keys, tokens and private keys
- passwords in connection strings
- values assigned to secret-looking names
Ask the AI. Taskit asks for at most 10 findings, and lists the findings already tracked (open and completed) so they aren't reported again. The response is streamed so progress is real.
Validate. Taskit parses the JSON, and repairs it when needed:
- It handles code fences, surrounding prose, trailing commas and cut-off output.
- It checks every finding and drops the invalid ones.
- It maps categories and priorities.
- It matches reported file locations against real workspace files.
- It enforces the 10-finding limit, keeping the highest priorities.
If the response is malformed, Taskit asks the AI once to repair it. If the context is too large for the model, it retries once with half the budget.
Deduplicate and store. New findings become tasks. Duplicates are skipped, and the result banner tells you how many.
Files that are never sent (and never edited):
- Folders:
.git, node_modules, dist, out, build, coverage, bin, obj, target, vendor, virtual environments, caches and IDE folders.
- Generated files (
*.min.js, *.map, *.g.cs, *_pb2.py, snapshots, …).
- Lock files, binaries, and unknown file types.
- Files that usually hold credentials:
.env*, *.pem, *.key, *.pfx, *.p12
secrets.json, credentials.json, .npmrc, .netrc, id_rsa
*.tfvars, terraform.tfstate
.aws/, .ssh/, and so on
- Anything ignored by
.gitignore (nested files and negation included).
- Anything matching your
taskit.context.excludePatterns.
- Files over 1 MB.
Duplicate detection
Every finding gets a normalized fingerprint. It is a SHA-256 hash of:
- its category
- its normalized file path
- the significant words of its title, after:
- splitting identifiers
- removing stop words
- mapping synonyms
- light stemming
A new finding is a duplicate of an existing task, open or completed, when any of these hold:
- Same fingerprint.
- Same category, with similar text:
- the titles are very similar (word overlap ≥ 0.72), or
- title and description together are similar (≥ 0.55), with a lower bar (≥ 0.40) when both point at the same file.
- When they point at different files, the bar is much higher (≥ 0.90), so the same kind of problem in two places is kept twice.
- Across categories, only when both point at the same file and the titles are nearly identical.
Completed tasks count, so finished work is never recreated. Removed tasks are forgotten, so the same issue can come back in a later check.
Task execution
Context. Taskit gathers a focused context of up to 48k tokens, redacted like a check:
- the task's file
- files and identifiers mentioned in its hidden prompt
- related files
Plan. The AI returns a plan: a summary, the changes (path and modify or create), blockers and follow-up steps for you. The plan is checked against the safety policy first:
- if the AI says it can't complete the task, or reports blockers, the task fails with that explanation
- an unsafe plan is refused, with the reason
Edits. For each file the AI returns exact search-and-replace edits, or the full content for new files. It sees the file with its credentials replaced by placeholders, and Taskit restores the real values locally. An edit that would write a placeholder into the file is refused.
- Edits are applied in memory, with tolerant matching for whitespace and indentation, and must match exactly one place.
- If an edit doesn't apply, the AI gets one retry with the concrete problem.
Validation, before anything is written.
- The file isn't empty.
- It contains no placeholders like
// ... existing code.
- JSON and JSONC are still valid.
- XML is still well-formed.
- Brackets are balanced in C-family languages.
- The size limits hold.
Apply. Taskit backs up the original files, then applies all changes at once through a VS Code WorkspaceEdit:
- it's one undoable operation
- it respects open editors
- it can optionally go through the Refactor Preview
If a file changed since planning, nothing is applied (edit conflict). Changes to files that tools execute (build scripts, tool configuration) always go through the Refactor Preview for your approval. Afterwards Taskit reads every file back to verify it. It saves the files, except those that already had unsaved changes of yours.
Rollback. If anything fails after applying, all changes are reverted. Backups are kept for 30 days: Taskit: Reveal Backups Folder.
Privacy and security
What is sent, and where.
- Check now sends parts of your workspace's files to the one provider you selected, over HTTPS to that provider's official API host only. That is the redacted, filtered context described above.
- Execute sends the task's hidden instructions, a focused context and the content of the files the task changes. Credentials in those files are replaced by numbered placeholders (
[REDACTED-SECRET-1]). The AI edits around them, and Taskit puts the real values back on your machine, so a task that removes a hard-coded key never sends that key.
- The settings panel and the confirmation dialogs say this every time it matters.
- Taskit never sends anything to any other service.
- Taskit collects no telemetry.
What each provider keeps.
- OpenAI requests use
store: false.
- Each provider's own data policies apply to what you send. Check them before using Taskit on confidential code.
Your API keys.
- Stored only in VS Code's SecretStorage, which is encrypted by your operating system's keychain, never in settings files.
- Displayed only in masked form after saving. The webview never receives a stored key, and it never persists a key you're typing.
- Kept out of the log:
- every log line passes through a redactor that removes the key in use and any recognizable credential
- error messages are scrubbed the same way
- Google keys go in a header, never in a URL
- Never redirected: Taskit doesn't follow HTTP redirects, so a key is never forwarded to another host.
What the AI cannot do.
- No commands. Taskit never runs commands, scripts, builds or tests. Commands the AI suggests become follow-up steps for you.
- Only workspace files. Tasks can only modify or create files inside the open workspace folders:
- deleting and renaming are refused
- so are paths outside the workspace, and paths that go through symbolic links, junctions or other aliases such as Windows short names
- At most 8 files per task, each up to 400 KB.
- Never edited automatically:
.git, .github and other CI folders
- Git hooks (
.husky, .githooks, pre-commit and lint-staged configuration)
.vscode, .devcontainer and editor folders
- CI files (
.gitlab-ci.yml, Jenkinsfile, azure-pipelines.yml, …)
- shell and PowerShell scripts and executables
- task runners (Makefile, justfile, Rakefile, …)
- lock, generated, binary and credential files
- everything excluded from the context
- Content that would run commands is refused, even inside allowed files:
- changes to
package.json scripts and bin
- new MSBuild
<Exec>, <Target> or <Import> elements
- Python entry-point scripts
- launch-profile executables
- Files that tools execute are only changed after you review them, because editors and build tools can run them when a folder is opened or a file is saved. They always open in VS Code's Refactor Preview, and nothing is applied until you accept. This covers:
- tool configuration scripts:
eslint.config.mjs, vite.config.ts, .prettierrc.js, …
setup.py, conftest.py, build.rs
- Gradle, Maven, CMake, Bazel and Nix files
- MSBuild project files
Gemfile
- When the AI asks for something Taskit won't do, the task fails with a clear explanation (for example, "Taskit will not modify .github/workflows/ci.yml because it is a CI configuration file"). Nothing is done silently.
Trust and isolation.
- Taskit only runs in trusted workspaces and doesn't support virtual workspaces.
- The sidebar webview uses a strict Content Security Policy:
- only Taskit's own script runs
- no remote content is loaded
- AI-generated text is always shown as plain text, never as HTML
- Every message from the webview is validated by the extension.
Settings
The provider, the API key and the model are managed in the Taskit sidebar (⚙). The other options live in VS Code's Settings (search for Taskit):
| Setting |
Default |
Description |
taskit.analysisDepth |
balanced |
Context budget per check: focused (~24k tokens), balanced (~64k) or thorough (~150k). It is always capped at 60% of the model's context window. Also available in the settings panel. |
taskit.context.excludePatterns |
[] |
Extra .gitignore-style patterns that are never sent to the AI or edited, e.g. ["legacy/", "**/*.sql"]. |
taskit.context.respectGitignore |
true |
Skip files ignored by the workspace's .gitignore files. User settings only, so a cloned repository can't turn it off. |
taskit.execution.previewChanges |
false |
Show VS Code's Refactor Preview before any task's changes are applied. Files that tools execute are always previewed. User settings only. |
taskit.execution.saveChangedFiles |
true |
Save the files a task changed. Turn it off to review the changes in unsaved editors first. |
Where each thing is stored:
- Provider, the model chosen for each provider, and the Show completed toggle: Taskit's global state.
- Tasks: Taskit's storage folder, one
tasks.json per workspace, written atomically. Nothing is added to your repository.
- Backups:
…/globalStorage/nuvoling.taskit/backups.
Commands
| Command |
What it does |
| Taskit: Check Now |
Analyze the workspace. |
| Taskit: Cancel Running Operation |
Cancel the running check or task. Only listed while something is running. |
| Taskit: AI Provider Settings |
Open the settings panel. |
| Taskit: Show/Hide Completed Tasks |
Toggle completed tasks. |
| Taskit: Show Log |
Open the Taskit output channel. Set its level to Debug for details; the log never contains keys. |
| Taskit: Reveal Backups Folder |
Open the folder with the original files of executed tasks. |
| Taskit: Remove Stored API Key… |
Delete a provider's key from secret storage. |
Errors and how Taskit handles them
| Situation |
What you see |
What Taskit does |
| No API key, provider or model |
Check now disabled with the reason; Set up AI provider |
No request is sent. |
| Invalid API key |
"The API key was rejected by the AI provider." with Open settings |
The key is not saved; nothing is retried. |
| Invalid or unavailable model |
"The selected model is not available…" |
Open settings; the model list comes from the provider. |
| Rate limit (HTTP 429) |
"The AI provider is rate limiting requests…" |
Retried automatically up to 2 times, honouring Retry-After (never waiting more than 30 s). |
| Quota / credits exhausted |
"Your AI provider account has run out of quota or credits." |
Not retried. |
| Provider unavailable (5xx, overloaded) |
"…temporarily unavailable…" |
Retried up to 2 times with back-off. |
| Network or proxy failure |
"Taskit could not reach the AI provider…" |
Retried up to 2 times. Taskit uses VS Code's proxy settings. |
| Timeout |
"The AI provider did not respond in time." |
10 min overall; 4 min without any streamed data. |
| Invalid or malformed response |
"The AI returned a response Taskit could not understand…" |
One automatic repair request, then this error. |
| Response cut off |
"The AI response was cut off…" |
Complete findings are salvaged when possible. |
| Context too large |
"The project context is too large for the selected model…" |
One retry with half the context. |
| Content blocked by the provider |
"…blocked the response because of its content policy." |
Nothing is changed. |
| Execution failure |
The error on the card, with Retry |
The task stays open; no partial changes. |
| File changed during execution |
"…changed while Taskit was working. No changes were kept; retry the task." |
Nothing applied; everything reverted. |
| File modification failure |
"Taskit could not modify / save …" |
Everything reverted; originals in the backups folder. |
| Validation failure |
"The generated changes failed validation…" with the problem |
Nothing written. |
| Unsafe operation |
"Taskit will not … because …" |
Nothing written. |
| User cancellation |
"Check cancelled." / "Execution cancelled. No changes were kept." |
Requests are aborted and edits reverted. |
| Untrusted or no workspace |
A prompt to trust the workspace or open a folder |
Nothing is read. |
Troubleshooting
"Taskit could not reach the AI provider". Check your network and VS Code's http.proxy settings. Corporate proxies that inspect TLS need their certificate trusted by VS Code.
Nothing useful is found in a big repository. Raise Analysis depth, or open the sub-folder you care about. Also check that your .gitignore and taskit.context.excludePatterns don't hide your source.
A task keeps failing with "edit conflict". Save or close the file and don't edit it while the task runs.
I want to review changes first. Turn on taskit.execution.previewChanges, or turn off taskit.execution.saveChangedFiles.
See what happened. Run Taskit: Show Log. At Debug level the log shows:
- file counts and token estimates
- how many values were redacted
- every step of an execution
It never contains API keys.
Limitations
- The AI can be wrong. Review findings before acting on them, and review every change a task makes. Undo and the backups are there for that.
- Nothing is compiled or run. Validation is structural only. Run your build and tests after executing tasks.
- One operation at a time: a single check or a single task.
- Local file systems only. Remote workspaces (SSH, WSL, containers) work, because Taskit runs where the files are. Virtual file systems do not.
- Very large workspaces are sampled. Taskit walks at most 20,000 files and sends only what fits the budget.
License
MIT © 2026 Nuvoling
| |