Nifty Extension Audit
See what your installed extensions can do: activation, processes, network, native code, telemetry and secrets access, scored and reported, with an allowlist policy for teams.
Maintained. No sign-in. No telemetry. Works in VS Code, Cursor, Windsurf, VSCodium and other editors that use Open VSX.
Features


- Know what you've installed. Audit Installed Extensions looks inside every extension you have and writes a report, riskiest first. For each one it shows what it can do:
- starts with every window
- runs other programs
- uses the network
- runs code built at runtime (
eval)
- reads secret-looking environment variables
- mentions credential files (
.ssh, .aws/credentials)
- reads the clipboard
- sends telemetry
- ships native binaries or scripts
- contains obfuscated code
- uses proposed APIs, or keeps running in untrusted folders
- Scored, not judged. Each extension gets a score and a level (high, medium, low, none). A Git tool has to run git, so the report says what an extension can do and leaves the call to you. It's the obfuscated code and credential-file access from unknown publishers that deserve a second look.
- Warnings on install. When a newly installed extension scores high, you're told what it can do and can uninstall it on the spot.
- Team policy. Put
allowed and blocked lists (wildcards like ms-python.* work) in .vscode/extensions-policy.json or your settings. Anything blocked, or missing from an allowlist, is flagged in every audit.
- Local and private. Everything is read from disk on your machine; nothing is sent anywhere.
Commands
| Command |
What it does |
Nifty Extension Audit: Audit Installed Extensions |
Audit everything and open the report |
Nifty Extension Audit: Audit an Extension… |
Audit one extension |
Settings
| Setting |
Default |
What it does |
nifty.audit.allowed |
[] |
Extension IDs your team allows (with a list, anything else is flagged) |
nifty.audit.blocked |
[] |
Extension IDs to flag as blocked |
nifty.audit.checkNewExtensions |
true |
Warn about high-risk extensions as they're installed |
nifty.audit.includeBuiltin |
false |
Include VS Code's built-in extensions |
The checks read an extension's manifest, its JavaScript and its file list. They're heuristics: they show capabilities and can't prove intent. Use them to decide where to look closer.
Install
- VS Code: search for "Nifty Extension Audit" in the Extensions view, or install from the Visual Studio Marketplace.
- Cursor, Windsurf, VSCodium, Kiro, Antigravity: install from Open VSX.
Privacy
This extension collects no telemetry and needs no account.
- Nifty Dependency Guard: Package Security Check: Catch risky dependencies before you install them: made-up (AI-hallucinated) packages, lookalike names, brand-new versions, install scripts and deprecations, in package.json and requirements.txt. (Open VSX)
- Nifty Licenses: Dependency License Checker & SBOM: See the license of every dependency (npm, Python, Cargo, Go, NuGet, Composer), get warned about GPL and unknown licenses, and export an SBOM or third-party notices. (Open VSX)
- Nifty Settings Sync: Sync via GitHub Gist: Sync settings, keybindings, snippets and extensions between VSCodium, Cursor, Windsurf and VS Code through a private GitHub Gist, with a diff before anything is overwritten. (Open VSX)
- Nifty Team Settings: Shared Settings for Teams: Share VS Code settings with your team: a committed base file, per-OS blocks, personal overrides that stay out of git, and a required-extensions check. (Open VSX)
- Nifty .NET Explorer: Solution & Test Explorer: A solution explorer and test explorer for .NET in VS Code, Cursor, Windsurf and VSCodium: projects, references and files from .sln/.slnx, and xUnit, NUnit and MSTest tests in the Testing view. (Open VSX)
- Nifty Agent Config: AGENTS.md, Rules & MCP Files: See which AGENTS.md, CLAUDE.md, Cursor, Copilot, Windsurf and Gemini rules apply to the file you are editing. Lint rule and MCP files for hidden text, secrets and broken links, and keep them in sync. (Open VSX)
See all 100+ Nifty extensions and web tools at https://getnifty.dev
| |