PRGuard for VS Code
Catch it before you commit. PRGuard audits every pull request against
your team's own standards. This extension runs the same audit on your
uncommitted changes, right in the editor, and helps you fix what it finds
before a reviewer ever sees it.
Features
- Pre-commit check. Send your staged changes (or all uncommitted changes,
or the whole branch) to PRGuard's audit engine. Findings appear in the
PRGuard panel, in the Problems list and as underlines in the editor, each at
its file and line.
- Fixes you can apply. Where PRGuard has verified that its patch applies
cleanly, Apply fix makes the change, brings it into view and can undo
it again. Apply all fixes applies every verified fix in one step.
- Fix with AI. Hand any finding, with its full explanation, to Claude Code,
Gemini Code Assist or GitHub Copilot Chat. You choose the assistant once;
it is remembered.
- Progress that keeps up with you. Findings tick themselves off as their
fixes land, whether applied here, typed by hand, made by an AI assistant or
merged in from elsewhere. You can also tick off or dismiss a finding
yourself.
- History. Every check is kept in the workspace with its findings, so you
can go back to an earlier run. Your decisions carry across runs of the same
finding.
- Your team's standards, locally. Your organisation's context files, the
rules PRGuard reviews against, sync into a folder in your workspace and
stay up to date.
Getting started
- Install the extension. A PRGuard shield appears in the activity bar.
- Create an API key in PRGuard: Account → API & CLI.
- Run PRGuard: Sign in with API key and paste the key. If you belong to
more than one organisation, pick the one this repository belongs to.
- Stage a change and click Run check: in the PRGuard view, on the
Source Control title bar or on the status bar.
The workspace must be a git repository whose origin remote is a GitHub
repository connected to PRGuard for your organisation.
Full guide: prguard.dev/vscode
What a check costs
A check is a full PRGuard audit: the prompt-injection gatekeeper, your
organisation's standards, the deterministic pre-scan and the model review,
followed by patch verification. It is billed to your organisation's
credits like a pull-request audit. The extension asks before each check;
you can turn that off. Re-running an identical change reuses the earlier
result at no charge.
A check is recorded in your PRGuard dashboard as a Local check. Nothing is
ever posted to GitHub.
Limits per check: 200 files and 4 MiB. Each API key can start up to 10
checks per minute.
Working through findings
| Action |
What it does |
| Apply fix |
Applies PRGuard's verified patch, scrolls to it and highlights the change. It becomes Undo fix. |
| Apply all fixes |
Applies every verified fix that still fits, one undo step per file. |
| Fix with AI |
Sends the finding to your chosen assistant, and copies the prompt to the clipboard as well. |
| Tick off |
Marks the finding done on this machine. The PRGuard report itself is unchanged. |
| Dismiss |
Marks the finding as not a problem here, in this run and in later runs of the same finding. |
| Reopen |
Puts a finding back on the open list. |
If an earlier fix has changed the lines a patch relied on, the finding shows
patch outdated and offers Fix with AI instead.
Settings
| Setting |
Default |
Description |
prguard.serverUrl |
https://prguard.dev |
PRGuard instance to use. Set it before signing in. |
prguard.contextDirectory |
context |
Folder the context files sync into, relative to the workspace root. |
prguard.autoSyncIntervalMinutes |
15 |
How often to check for updated context files. 0 turns it off. |
prguard.check.scope |
staged |
What a check sends: staged, working-tree or branch. |
prguard.check.includeFileContents |
true |
Send each changed file's full contents, which patch verification and the pre-scan need. |
prguard.check.maxFileKilobytes |
512 |
Files larger than this are sent as a diff only. |
prguard.check.confirmBeforeRun |
true |
Ask before each billed check. |
prguard.fixWithAi.assistant |
ask |
Assistant for Fix with AI: claude-code, gemini, copilot or clipboard. |
prguard.fixWithAi.sendAutomatically |
false |
Send the prompt to Copilot Chat straight away, rather than filling it in for you to review and send. |
Commands
Every command is under PRGuard: in the Command Palette.
| Command |
Description |
| Sign in with API key / Sign out |
Store or remove your key. |
| Select organisation |
Switch organisation. The choice is remembered per workspace. |
| Run pre-commit check |
Check the changes in the current scope. |
| Change check scope |
Choose between staged, uncommitted and branch. |
| Apply all verified fixes |
Apply every verified fix from the last check. |
| Choose AI assistant for Fix with AI |
Change the assistant that Fix with AI uses. |
| Show PRGuard panel / Show last check |
Open the panel or the check output. |
| Open last report in browser |
Open the full report in the PRGuard dashboard. |
| Sync context files / Set context files directory |
Pull the latest standards, or choose where they go. |
| Clear findings / Clear check history |
Clear this workspace's findings or its kept runs. |
Privacy and security
- Your key is stored in your operating system's keychain and is only sent
to the configured PRGuard server over HTTPS.
- Your code is uploaded only when you run a check, and only the files that
check covers. PRGuard holds the upload only while the audit runs, then
deletes it. The stored report keeps the findings, including the few lines
each one quotes as evidence, plus paths and hashes. It does not keep your
files, even if a check fails: just run it again from the editor.
- Your workspace is only touched when you apply a fix or sync context
files. Fixes are only written to the finding's own file inside the checked
repository, never through a symbolic link, and every path that comes back
from the server is validated first.
- Your AI assistant is told that a PRGuard finding is a description of a
bug, not instructions to follow. Nothing is sent without you seeing it
unless you turn on
prguard.fixWithAi.sendAutomatically.
- Your settings that affect billing or your AI assistant can only be
changed in your user settings. A repository's
.vscode/settings.json can't
change them.
- Other people can't read your checks through the API. Only you, the
person who started a check, can read its result.
Support
Email support@prguard.dev. The
getting-started guide has setup steps and
answers to common questions.
| |