Skip to content
| Marketplace
Sign in
Visual Studio Code>Linters>Security ScannerNew to Visual Studio Code? Get it now.
Security Scanner

Security Scanner

jjjyjyjyjj

|
4 installs
| (0) | Free
Scans git changes for security issues using Gitleaks, Semgrep, and AI-powered fix suggestions
Installation
Launch VS Code Quick Open (Ctrl+P), paste the following command, and press enter.
Copied to clipboard
More Info

Security Scanner

Scans your local git changes for security issues and helps you fix them, right inside VS Code. It combines three engines:

  • Gitleaks — hardcoded secrets, API keys, and credentials.
  • Semgrep — SQL injection, XSS, command injection, weak crypto, path traversal, insecure CORS, and more.
  • AI (OpenAI) — catches logic-level bugs the static tools miss (IDOR, missing rate limiting, SSRF, broken auth), and filters out false positives.

Findings appear as editor squiggles, in the Problems panel, and in a Security Fixes sidebar — and you act on each one with a Cmd+. quick fix.

Requirements

The extension shells out to two command-line tools. Install them and make sure they're on your PATH:

# macOS
brew install gitleaks semgrep

On Linux/Windows, follow the Gitleaks and Semgrep install docs. Verify with gitleaks version and semgrep --version.

The AI features need your own OpenAI API key. Your key and code are sent only to OpenAI (for the AI features) and nowhere else, and you're billed by OpenAI directly. Set it in VS Code settings:

{ "securityScanner.openaiApiKey": "sk-...your-key" }

or export an OPENAI_API_KEY environment variable. Without a key, Gitleaks + Semgrep still run — only the AI scan and AI fixes are skipped.

Usage

Scan: Cmd+Shift+P → Security Scanner: Scan Changes (or use the Security Fixes view in the Explorer sidebar). It also auto-scans shortly after your git changes update.

Act on a finding — put your cursor on a flagged line and press Cmd+.:

  • Apply AI fix — preview the change as a diff, then apply it (written and saved to disk).
  • Mark as fixed — suppress the finding so it won't come back.
  • Ignore rule in this file — hide that rule for this file.
  • Explain this issue — open a panel with the full explanation and fix.

The Security Fixes sidebar lists every finding with a concise fix, a "Why is this a bug?" button (opens the detail panel), and Apply / Mark as fixed buttons. The same findings show up as squiggles and in the Problems panel.

What it catches

  • Secrets (Gitleaks): API keys, tokens, private keys, and database connection strings with passwords.
  • Static vulnerabilities (Semgrep, multiple rulesets): SQL injection, XSS, command/eval injection, weak crypto (MD5/SHA1/DES), path traversal, insecure CORS, sensitive data in logs, SSRF, open redirects, insecure deserialization, and more.
  • Logic bugs (AI): the things pattern scanners structurally can't see — IDOR / broken access control, missing rate limiting, SSRF, subtle auth mistakes — with a false-positive filter so already-guarded code isn't flagged.

Settings

Setting Default Description
securityScanner.openaiApiKey "" Your OpenAI API key (required for AI features).
securityScanner.aiScanEnabled true Run the AI scan at all.
securityScanner.aiHighImpactOnly true AI flags only high-impact (critical/high) issues. Turn off to also surface medium/low.
securityScanner.aiDetectionPasses 3 AI passes per file on a fresh scan. Higher catches more; lower is cheaper.
securityScanner.semgrepRuleset p/owasp-top-ten Primary Semgrep ruleset (extra rulesets run alongside it automatically).
securityScanner.autoScanOnCommit true Auto-scan when your git changes update.

Suppressing findings

  • Mark as fixed (quick fix or sidebar) hides a finding until that line of code changes. Review and restore them with Cmd+Shift+P → Security Scanner: View Suppressed Issues.
  • For a Semgrep false positive you'd rather handle in the code, add a // nosemgrep comment on the flagged line.

Notes

  • The AI's findings, fix, and false-positive verdict are cached per file by content, so re-scanning unchanged code is stable and makes no extra API calls — the AI only re-runs when a file actually changes.
  • Save your file after fixing. The scanners read files from disk, so a hand-edited fix only "sticks" once saved (Apply AI fix saves for you).

Troubleshooting

Symptom Fix
"Not inside a git repository" Open the folder that contains .git, not a parent folder.
"No changes to scan" Make a local change to a tracked file, then scan.
AI features do nothing Set securityScanner.openaiApiKey (or the OPENAI_API_KEY env var).
A fixed issue keeps reappearing Save the file after fixing — the scanners read from disk.
Semgrep flags already-safe code Add // nosemgrep on the line, or Mark as fixed.
Commands missing from the palette Reload the window: Cmd+Shift+P → Developer: Reload Window.

Building from source

npm install
npm run compile   # compiles TypeScript into out/

Press F5 in VS Code to launch an Extension Development Host, or run vsce package to build an installable .vsix.

  • Contact us
  • Jobs
  • Privacy
  • Manage cookies
  • Terms of use
  • Trademarks
  • Your Privacy Choices
  • Consumer Health Privacy
© 2026 Microsoft