Security Scanner
Scans your local git changes for security issues and helps you fix them, right inside VS Code. It combines three engines:
- Gitleaks — hardcoded secrets, API keys, and credentials.
- Semgrep — SQL injection, XSS, command injection, weak crypto, path traversal, insecure CORS, and more.
- AI (OpenAI) — catches logic-level bugs the static tools miss (IDOR, missing rate limiting, SSRF, broken auth), and filters out false positives.
Findings appear as editor squiggles, in the Problems panel, and in a Security Fixes sidebar — and you act on each one with a Cmd+. quick fix.
Requirements
The extension shells out to two command-line tools. Install them and make sure they're on your PATH:
# macOS
brew install gitleaks semgrep
On Linux/Windows, follow the Gitleaks and Semgrep install docs. Verify with gitleaks version and semgrep --version.
The AI features need your own OpenAI API key. Your key and code are sent only to OpenAI (for the AI features) and nowhere else, and you're billed by OpenAI directly. Set it in VS Code settings:
{ "securityScanner.openaiApiKey": "sk-...your-key" }
or export an OPENAI_API_KEY environment variable. Without a key, Gitleaks + Semgrep still run — only the AI scan and AI fixes are skipped.
Usage
Scan: Cmd+Shift+P → Security Scanner: Scan Changes (or use the Security Fixes view in the Explorer sidebar). It also auto-scans shortly after your git changes update.
Act on a finding — put your cursor on a flagged line and press Cmd+.:
- Apply AI fix — preview the change as a diff, then apply it (written and saved to disk).
- Mark as fixed — suppress the finding so it won't come back.
- Ignore rule in this file — hide that rule for this file.
- Explain this issue — open a panel with the full explanation and fix.
The Security Fixes sidebar lists every finding with a concise fix, a "Why is this a bug?" button (opens the detail panel), and Apply / Mark as fixed buttons. The same findings show up as squiggles and in the Problems panel.
What it catches
- Secrets (Gitleaks): API keys, tokens, private keys, and database connection strings with passwords.
- Static vulnerabilities (Semgrep, multiple rulesets): SQL injection, XSS, command/
eval injection, weak crypto (MD5/SHA1/DES), path traversal, insecure CORS, sensitive data in logs, SSRF, open redirects, insecure deserialization, and more.
- Logic bugs (AI): the things pattern scanners structurally can't see — IDOR / broken access control, missing rate limiting, SSRF, subtle auth mistakes — with a false-positive filter so already-guarded code isn't flagged.
Settings
| Setting |
Default |
Description |
securityScanner.openaiApiKey |
"" |
Your OpenAI API key (required for AI features). |
securityScanner.aiScanEnabled |
true |
Run the AI scan at all. |
securityScanner.aiHighImpactOnly |
true |
AI flags only high-impact (critical/high) issues. Turn off to also surface medium/low. |
securityScanner.aiDetectionPasses |
3 |
AI passes per file on a fresh scan. Higher catches more; lower is cheaper. |
securityScanner.semgrepRuleset |
p/owasp-top-ten |
Primary Semgrep ruleset (extra rulesets run alongside it automatically). |
securityScanner.autoScanOnCommit |
true |
Auto-scan when your git changes update. |
Suppressing findings
- Mark as fixed (quick fix or sidebar) hides a finding until that line of code changes. Review and restore them with
Cmd+Shift+P → Security Scanner: View Suppressed Issues.
- For a Semgrep false positive you'd rather handle in the code, add a
// nosemgrep comment on the flagged line.
Notes
- The AI's findings, fix, and false-positive verdict are cached per file by content, so re-scanning unchanged code is stable and makes no extra API calls — the AI only re-runs when a file actually changes.
- Save your file after fixing. The scanners read files from disk, so a hand-edited fix only "sticks" once saved (Apply AI fix saves for you).
Troubleshooting
| Symptom |
Fix |
| "Not inside a git repository" |
Open the folder that contains .git, not a parent folder. |
| "No changes to scan" |
Make a local change to a tracked file, then scan. |
| AI features do nothing |
Set securityScanner.openaiApiKey (or the OPENAI_API_KEY env var). |
| A fixed issue keeps reappearing |
Save the file after fixing — the scanners read from disk. |
| Semgrep flags already-safe code |
Add // nosemgrep on the line, or Mark as fixed. |
| Commands missing from the palette |
Reload the window: Cmd+Shift+P → Developer: Reload Window. |
Building from source
npm install
npm run compile # compiles TypeScript into out/
Press F5 in VS Code to launch an Extension Development Host, or run vsce package to build an installable .vsix.