Skip to content
| Marketplace
Sign in
Visual Studio Code>Linters>Future Debt PredictorNew to Visual Studio Code? Get it now.
Future Debt Predictor

Future Debt Predictor

michael-dev

|
2 installs
| (0) | Free
Developer-side security and code-debt scanner: finds CWE-mapped vulnerabilities and future technical debt as you type, with one-click fixes.
Installation
Launch VS Code Quick Open (Ctrl+P), paste the following command, and press enter.
Copied to clipboard
More Info

Future Debt Predictor

Install and go: no server, no account, nothing leaves your machine. The scanner runs inside VS Code. (Optional: set futureDebt.mode to server to use the Future Debt API.)

Scan the whole project

Click the Future Debt shield in the activity bar (or the Scan Project button in the status bar) to scan every file at once. Findings are listed by file; click one to jump to the line. Open Report shows the full page (verdict, counts, filters) and lets you download a PDF (or Markdown/SARIF/JSON) for the security team.

Scan profiles

Most checks apply to any application. A few only make sense for code that moves money (floating-point amounts, client-supplied fees, currency and transfer rules), so they live in the Payments profile. Auto (the default) turns Payments on only when the project contains payment-related files; otherwise you get the General profile. Override it with Future Debt: Choose Scan Profile. The current profile is shown at the top of the results list.

Deeper than patterns: AI Deep Review

The scanner matches known code patterns. Flaws in logic (an account id that is never checked against the caller, a fee taken from the request, a logout that does not end the session) need something that reads the code. Future Debt: AI Deep Review of This File sends each method of the open file to your AI provider with a security checklist and lists what it finds, marked "AI review". It needs Set Up AI Fixes first, uses one request per method (up to 25 per run), and its findings are suggestions to confirm. The checklist is in docs/api-security-review-checklist.md.

Choose what to scan

Use Scan Selected Projects or Folders... (folder icon in the Future Debt view) to tick the projects or folders you want, or right-click a folder in the Explorer and choose Future Debt: Scan This Folder. Add folder names to futureDebt.excludeFolders to skip them every time.

Fixing

  • Findings with a safe, mechanical fix show Fix (lightbulb, tree or report). Apply All Automatic Fixes does them in one go.
  • Fix with AI works on every finding. Run Future Debt: Set Up AI Fixes once and give it an Anthropic API key or an OpenAI-compatible endpoint (OpenAI, Azure OpenAI, your company's gateway). The fix is applied directly and the file is re-scanned to confirm the finding is gone; press Ctrl+Z to undo. Without that set-up it falls back to the AI model already in VS Code (GitHub Copilot).
  • (Details) Every finding also has Fix with AI: it sends the few lines around the finding to the AI model already set up in VS Code (for example GitHub Copilot) and shows a preview you accept or reject. It needs such a model; nothing is sent to Future Debt.

Predicts the future cost of technical debt while you write code. For each flagged line you see what will likely break, when, what triggers it, and how long it takes to fix now versus later.

  • Status bar debt score (0-100) and detected framework; click it for the full panel.
  • Security findings mapped to CWE with severity and "how to fix" guidance, plus one-click quick fixes for safe cases (e.g. verify=False, disabled certificate validation, customErrors mode="Off", weak hashes).
  • Also scans web.config, appsettings.json, .env, Dockerfiles, Kubernetes/Compose YAML and mobile manifests, plus Razor (.cshtml, .razor) and Web Forms (.aspx, .ascx, .master) views, where much ASP.NET XSS lives.
  • Future Debt: Scan Workspace analyses every supported file in the folder (progress, cancellable) and fills the Problems panel. Future Debt: Export Security Report saves a Markdown "READY / NOT READY for security review" report, SARIF 2.1.0 (CI, Azure DevOps, GitHub, SonarQube) or JSON. A cancelled or partial scan is labelled INCOMPLETE and can never say READY. Set the gate with futureDebt.failOn (default medium, i.e. Veracode VL4).
  • Suppress a justified exception with // fdp-ignore: rule_id, reason.
  • Inline warnings; security issues always shown as warnings.
  • Mark predictions "Yes, this is right" or "Not relevant" to help improve the model.

Privacy

Your code is sent to the analysis API for scoring and is never logged or stored; only numeric pattern features are kept. Workspace scans ask for confirmation before sending files to any non-local server (once per server); only supported source files and security-relevant config files are ever sent, never arbitrary JSON/XML, tests, vendored libraries or build output. Set futureDebt.apiUrl to point at a self-hosted deployment. Non-local servers must use HTTPS.

Settings and commands

  • futureDebt.apiUrl - backend base URL (default http://localhost:8000).
  • futureDebt.enabled - turn analysis on or off.
  • Command: Future Debt: Toggle On/Off.
  • Contact us
  • Jobs
  • Privacy
  • Manage cookies
  • Terms of use
  • Trademarks
  • Your Privacy Choices
  • Consumer Health Privacy
© 2026 Microsoft