Codebase GuardCodebase Guard checks an opened codebase for suspicious code and risky project configuration without running anything. It works across JavaScript and TypeScript projects, PHP and Laravel applications, Composer packages, Python, Ruby, shell scripts, CI files, editor tasks, containers, and common framework configuration. It supports VS Code Restricted Mode: you do not need to trust a repository to scan it. Codebase Guard is open source under the MIT License. Its scanner runs locally, does not execute project code, and does not send repository data anywhere. Safety boundaryAt runtime Codebase Guard:
This is a local developer safety layer, not a replacement for GitHub CI, Semgrep, CodeQL, secret scanning, EDR, code review, or incident response. What it checks
The UI uses three actionable severities:
Scores organize warnings by urgency. A warning is a clue to review, not proof that a file is malicious. Commands
The Codebase Guard control center keeps Scan workspace / Scan again as its single main action. Findings appear in compact cards with named, always-visible actions to open the file, hide the reviewed alert, skip the file, or skip a parent folder. A separate current-location panel can scan or skip the active file and skip its parent folder. The skipped-items manager remains visible with its current count. Live scans on open and rechecks only changed relevant files through one bounded queue. On open performs the startup scan without leaving change monitoring active. Manual runs nothing in the background while keeping workspace and current-file commands available. Findings also appear in the Problems panel and status bar. Critical findings produce at most one summarized popup per workspace scan or changed-file batch. Additional Critical findings update the persistent Control Center, Problems panel, finding tree, and status bar without creating a queue of duplicate notifications. Startup discovery prioritizes editor automation and other security-sensitive configuration. Remaining files are read with at most two concurrent workers. Large change bursts are deduplicated by path, so a checkout that reports the same file repeatedly produces one pending recheck for its latest state rather than one timer per event. Settings and Restricted ModeThe existing The finding row provides two explicit actions: hide only the reviewed finding fingerprint in User settings, or skip its exact file or any parent folder in the opened codebase. Folder choices are derived directly from the finding path, so no Finder dialog or full-codebase picker is required. Critical findings require a deliberate modal confirmation before either action can hide them. Default discovery excludes generated/dependency areas such as InstallVS Code
You can also install it from the Visual Studio Marketplace. CursorCodebase Guard is distributed publicly through Open VSX, the extension registry used by Cursor. After the public listing is available:
Cursor may hold a newly published version for marketplace security scanning before it appears in search. For release testing, install DevelopmentThe installed extension never invokes development tools. Building the extension itself uses Node, TypeScript, tests, and
Use Node.js 22. The packaged VSIX is written to
Before proposing a scanner rule, UI change, or documentation correction, read CONTRIBUTING.md. Contributions must preserve the runtime boundary: no project execution, process launching, direct Node filesystem access, network access, telemetry, or automatic workspace writes. Issues and security reportsNever post credentials, proprietary source code, or unredacted findings in a public issue. See SECURITY.md and SUPPORT.md. Remote workspacesAnalysis runs entirely inside the active VS Code extension environment and Codebase Guard creates no network connection. For local codebases this is local. With Remote SSH, WSL, Dev Containers, or Codespaces, VS Code may run this workspace extension in the remote workspace extension host. See SECURITY.md and docs/RULES.md for the threat model, limitations, and rule behavior. LicenseCodebase Guard is available under the MIT License. |