Skip to content
| Marketplace
Sign in
Visual Studio Code>Programming Languages>Blacklock CodeScanNew to Visual Studio Code? Get it now.
Blacklock CodeScan

Blacklock CodeScan

Blacklock.io

|
9 installs
| (0) | Free
Scan for hardcoded secrets, vulnerable dependencies, risky code patterns, and misconfigured infrastructure — all in one click, without leaving your editor.
Installation
Launch VS Code Quick Open (Ctrl+P), paste the following command, and press enter.
Copied to clipboard
More Info

Blacklock SAST Security Scan

Perform a security scan on your source code as you write. Find hardcoded secrets, vulnerable dependencies, risky code patterns, and misconfigured infrastructure -- all without leaving your editor.

Works with: VS Code | Claude Code | OpenAI Codex CLI

What It Does

Blacklock CodeScan combines five purpose-built scanners into one workflow:

  • Source Code Scanner — SQL injection, XSS, hardcoded secrets, and other risky code patterns
  • Secrets Scanner — hardcoded API keys, tokens, and credentials; the matched value is never shown unmasked in the UI
  • Dependency Scanner — known CVEs in your project's dependencies, with fixed-version suggestions
  • IaC Scanner — misconfigurations in Dockerfiles, Kubernetes manifests, and Terraform
  • Code Quality Scanner — broader code-quality and security linting

Run them together with Scan All, or scope to just Source Code or Dependencies from their own tabs. Findings from every scanner land in one combined list on the All tab — sorted by severity, with the source engine tagged on each row so you can tell which tool found what, and duplicate findings (the same secret or issue found by more than one tool) merged into one entry, keeping the highest reported severity.

Additional behavior worth knowing:

  • Scan the whole workspace, just the current file, or only what's changed (diff lines / diff files)
  • Respects .gitignore for workspace scans, and always skips build artifacts (node_modules, __pycache__, compiled binaries, .env files) regardless of gitignore state
  • Jump straight from a finding to the exact line in your editor
  • Suppress findings you've triaged, per-project
  • Scanning tools (opengrep, trivy, gitleaks, checkov, qlty) install automatically on first use — no manual setup

Quick Start

If you're setting up the Claude Code or Codex CLI plugin, download the matching blacklock-shield binary for your platform from Releases. The VS Code extension installs its own scanning tools automatically — see below.


VS Code Extension

Security scanning across 5 engines, with a dedicated findings panel and inline jump-to-line.

Install

  1. Build the extension:

    git clone https://github.com/blacklock-security/block-ide-plugins.git
    cd block-ide-plugins
    npm install && npm run compile && npx vsce package
    
  2. In VS Code: Ctrl+Shift+X > ... menu > Install from VSIX > select the .vsix file.

How to Use

Open the Blacklock CodeScan sidebar (Activity Bar icon), pick a scope (Workspace / Current File / Diff Lines / Diff Files), and click Scan. Findings appear grouped by tab — All (everything, merged and sorted by severity), Source Code, or Dependencies — or run any scan directly from the Command Palette (Ctrl+Shift+P):

  • CodeScan: Scan All
  • CodeScan: Scan Source Code
  • CodeScan: Scan Dependencies
  • CodeScan: Scan Secrets
  • CodeScan: Scan Infrastructure
  • CodeScan: Scan Quality

Click any finding to jump to its exact location; enable On Save in the sidebar to scan the current file automatically on every save.

Settings

Search "Blacklock" in VS Code Settings (Ctrl+,):

Setting Default What it does
sourceScanner.rules "auto" Opengrep rules config path, or "auto" for defaults
sourceScanner.exclude [] Extra directories to exclude from source scans
dependencyScanner.scanners ["vuln", "secret"] Trivy scanner types to run
dependencyScanner.severity ["CRITICAL", "HIGH", "MEDIUM"] Severity levels to report for dependency vulnerabilities
scanner.executionMode "parallel" Run the 5 scanners concurrently, or one at a time
scanner.persistRawOutput false Write each tool's raw JSON to .blacklock/scan-results/ for debugging
scanOnSave false Automatically scan the current file on save

Claude Code Plugin

A plugin that gives Claude 7 security scanning commands, plus a post-edit hook that automatically scans every file Claude touches.

Install

mkdir -p ~/.claude/plugins/blacklock-shield
cp -r claude-code-plugin/{hooks,commands,mcp.json,shield.config.json} ~/.claude/plugins/blacklock-shield/

Restart Claude Code.

Commands

/shield:audit                         Full audit (source + deps + infra)
/shield:source                        Source code scan only
/shield:deps                          Dependency CVE scan
/shield:infra                         Infrastructure config scan (Docker, K8s, Terraform)
/shield:triage                        Filter findings by severity/category/engine
/shield:details <file>                Scan a specific file (or show cached results)
/shield:autoscan on|off               Toggle auto-scan after every edit

Triage Options

/shield:triage severity=CRITICAL
/shield:triage severity=HIGH,CRITICAL category=injection
/shield:triage engine=SOURCE

Example Prompts

/shield:audit
"Fix all critical and high findings, then re-run the audit"

/shield:deps
"Upgrade all vulnerable packages to their fixed versions"

/shield:details src/auth/login.py
"Is the SQL query on line 42 actually vulnerable?"

/shield:infra
"Fix the Dockerfile issues and add a non-root USER"

/shield:autoscan on
"Now write me a new API endpoint for user registration"
(Claude auto-scans after every edit)

"Run a security audit and fix anything critical"
(Claude runs the audit, then makes fixes)

Codex CLI Plugin

An MCP skill that registers security scanning tools Codex can call on its own. Supports text, json, and sarif output formats.

Install

cd block-ide-plugins/codex-plugin
bash setup.sh

This copies the skill to ~/.codex/skills/blacklock-shield/, registers the MCP server in ~/.codex/config.toml, and installs scanning tools if missing. Restart Codex CLI.

Commands

$blacklock-shield audit                 Full audit (source + deps + infra)
$blacklock-shield source                Source code scan only
$blacklock-shield deps                  Dependency CVE scan
$blacklock-shield infra                 Infrastructure config scan
$blacklock-shield triage                Filter findings by severity/category/engine
$blacklock-shield details [file]        Scan a specific file (or show cached results)
$blacklock-shield autoscan on|off       Toggle auto-scan after every edit

Triage Options

$blacklock-shield triage severity=CRITICAL engine=SOURCE
$blacklock-shield triage category=injection

Example Prompts

$blacklock-shield audit
"Fix all critical findings and re-run the audit"

$blacklock-shield deps
"Upgrade every vulnerable package to the fixed version"

$blacklock-shield details src/api/handler.go
"Is this actually exploitable?"

$blacklock-shield autoscan on
"Refactor the auth module"
(Codex auto-scans after every edit)

"Check this project for security issues and fix anything critical"
(Codex picks the right tools automatically)

Building from Source

cd blacklock-shield
cargo build --release
# Binary: target/release/blacklock-shield

License

MIT -- see LICENSE.

Support

  • GitHub Issues
  • support@blacklock.io
  • Contact us
  • Jobs
  • Privacy
  • Manage cookies
  • Terms of use
  • Trademarks
  • Your Privacy Choices
  • Consumer Health Privacy
© 2026 Microsoft