Future Debt PredictorInstall and go: no server, no account, nothing leaves your machine. The scanner runs inside VS Code.
(Optional: set Scan the whole projectClick the Future Debt shield in the activity bar (or the Scan Project button in the status bar) to scan every file at once. Findings are listed by file; click one to jump to the line. Open Report shows the full page (verdict, counts, filters) and lets you download a PDF (or Markdown/SARIF/JSON) for the security team. Scan profilesMost checks apply to any application. A few only make sense for code that moves money (floating-point amounts, client-supplied fees, currency and transfer rules), so they live in the Payments profile. Auto (the default) turns Payments on only when the project contains payment-related files; otherwise you get the General profile. Override it with Future Debt: Choose Scan Profile. The current profile is shown at the top of the results list. Deeper than patterns: AI Deep ReviewThe scanner matches known code patterns. Flaws in logic (an account id that is never checked against the caller, a fee taken from the request,
a logout that does not end the session) need something that reads the code. Future Debt: AI Deep Review of This File sends each method of the
open file to your AI provider with a security checklist and lists what it finds, marked "AI review". It needs Set Up AI Fixes first, uses one request
per method (up to 25 per run), and its findings are suggestions to confirm. The checklist is in Choose what to scanUse Scan Selected Projects or Folders... (folder icon in the Future Debt view) to tick the projects or folders you want, or right-click a folder
in the Explorer and choose Future Debt: Scan This Folder. Add folder names to Fixing
Predicts the future cost of technical debt while you write code. For each flagged line you see what will likely break, when, what triggers it, and how long it takes to fix now versus later.
PrivacyYour code is sent to the analysis API for scoring and is never logged or stored; only numeric
pattern features are kept. Workspace scans ask for confirmation before sending files to any non-local server
(once per server); only supported source files and security-relevant config files are ever sent, never
arbitrary JSON/XML, tests, vendored libraries or build output. Set Settings and commands
|