Skip to content
| Marketplace
Sign in
Visual Studio Code>Other>Nifty Extension Audit: Extension Security CheckNew to Visual Studio Code? Get it now.
Nifty Extension Audit: Extension Security Check

Nifty Extension Audit: Extension Security Check

Nifty

| (0) | Free
See what your installed extensions can do: activation, processes, network, native code, telemetry and secrets access, scored and reported, with an allowlist policy for teams.
Installation
Launch VS Code Quick Open (Ctrl+P), paste the following command, and press enter.
Copied to clipboard
More Info

Nifty Extension Audit

See what your installed extensions can do: activation, processes, network, native code, telemetry and secrets access, scored and reported, with an allowlist policy for teams.

Maintained. No sign-in. No telemetry. Works in VS Code, Cursor, Windsurf, VSCodium and other editors that use Open VSX.

Features

The audit report: installed extensions scored riskiest first, with what each can do

The audit of one extension: activation, network, secret-looking environment variables, clipboard and telemetry

  • Know what you've installed. Audit Installed Extensions looks inside every extension you have and writes a report, riskiest first. For each one it shows what it can do:
    • starts with every window
    • runs other programs
    • uses the network
    • runs code built at runtime (eval)
    • reads secret-looking environment variables
    • mentions credential files (.ssh, .aws/credentials)
    • reads the clipboard
    • sends telemetry
    • ships native binaries or scripts
    • contains obfuscated code
    • uses proposed APIs, or keeps running in untrusted folders
  • Scored, not judged. Each extension gets a score and a level (high, medium, low, none). A Git tool has to run git, so the report says what an extension can do and leaves the call to you. It's the obfuscated code and credential-file access from unknown publishers that deserve a second look.
  • Warnings on install. When a newly installed extension scores high, you're told what it can do and can uninstall it on the spot.
  • Team policy. Put allowed and blocked lists (wildcards like ms-python.* work) in .vscode/extensions-policy.json or your settings. Anything blocked, or missing from an allowlist, is flagged in every audit.
  • Local and private. Everything is read from disk on your machine; nothing is sent anywhere.

Commands

Command What it does
Nifty Extension Audit: Audit Installed Extensions Audit everything and open the report
Nifty Extension Audit: Audit an Extension… Audit one extension

Settings

Setting Default What it does
nifty.audit.allowed [] Extension IDs your team allows (with a list, anything else is flagged)
nifty.audit.blocked [] Extension IDs to flag as blocked
nifty.audit.checkNewExtensions true Warn about high-risk extensions as they're installed
nifty.audit.includeBuiltin false Include VS Code's built-in extensions

The checks read an extension's manifest, its JavaScript and its file list. They're heuristics: they show capabilities and can't prove intent. Use them to decide where to look closer.

Install

  • VS Code: search for "Nifty Extension Audit" in the Extensions view, or install from the Visual Studio Marketplace.
  • Cursor, Windsurf, VSCodium, Kiro, Antigravity: install from Open VSX.

Privacy

This extension collects no telemetry and needs no account.

More Nifty tools

  • Nifty Dependency Guard: Package Security Check: Catch risky dependencies before you install them: made-up (AI-hallucinated) packages, lookalike names, brand-new versions, install scripts and deprecations, in package.json and requirements.txt. (Open VSX)
  • Nifty Licenses: Dependency License Checker & SBOM: See the license of every dependency (npm, Python, Cargo, Go, NuGet, Composer), get warned about GPL and unknown licenses, and export an SBOM or third-party notices. (Open VSX)
  • Nifty Settings Sync: Sync via GitHub Gist: Sync settings, keybindings, snippets and extensions between VSCodium, Cursor, Windsurf and VS Code through a private GitHub Gist, with a diff before anything is overwritten. (Open VSX)
  • Nifty Team Settings: Shared Settings for Teams: Share VS Code settings with your team: a committed base file, per-OS blocks, personal overrides that stay out of git, and a required-extensions check. (Open VSX)
  • Nifty .NET Explorer: Solution & Test Explorer: A solution explorer and test explorer for .NET in VS Code, Cursor, Windsurf and VSCodium: projects, references and files from .sln/.slnx, and xUnit, NUnit and MSTest tests in the Testing view. (Open VSX)
  • Nifty Agent Config: AGENTS.md, Rules & MCP Files: See which AGENTS.md, CLAUDE.md, Cursor, Copilot, Windsurf and Gemini rules apply to the file you are editing. Lint rule and MCP files for hidden text, secrets and broken links, and keep them in sync. (Open VSX)

See all 100+ Nifty extensions and web tools at https://getnifty.dev

  • Contact us
  • Jobs
  • Privacy
  • Manage cookies
  • Terms of use
  • Trademarks
  • Your Privacy Choices
  • Consumer Health Privacy
© 2026 Microsoft