Skip to content
| Marketplace
Sign in
Visual Studio Code>Programming Languages>PRSniffer TestNew to Visual Studio Code? Get it now.
PRSniffer Test

PRSniffer Test

prsniffer

| (0) | Free
AI code review + AppSec for your working tree: inline findings, editable fixes, repro steps, and agent handoff.
Installation
Launch VS Code Quick Open (Ctrl+P), paste the following command, and press enter.
Copied to clipboard
More Info

PRSniffer for VS Code, Cursor and Windsurf

Reviews your changes before anyone else does. The static tier runs entirely on your machine for free; the AI tier is optional and uses a provider key you supply.

What it does

Static review — free, offline, no API key. Runs on every review and always works:

Scan Looks for
secret Hardcoded keys, tokens and passwords
sca Dependencies with known vulnerabilities
sast Injection, XSS, unsafe deserialization, weak crypto, command injection
iac Terraform and Kubernetes misconfiguration
container Dockerfile and image problems
license Dependency licence problems
malware Known malicious packages
api_security Hardcoded credentials and auth weaknesses in API code

Rules run through OpenGrep plus a set of in-process checks. Measured on the bundled benchmark corpus: 27/27 planted defects found, 0 false positives on correct code.

AI review — optional. If you configure a provider, each finding also gets an explanation, numbered reproduction steps, and a suggested fix. Bring your own key from any of 22 providers, or point at a PRSniffer backend. Set prsniffer.offline to true to skip it entirely.

Working a finding. Every finding can be opened at its line, previewed as an editable diff, approved, rejected, or handed to your AI agent. Nothing is applied without your say-so.

Screenshots

Welcome Review running
Findings Static tier only
Clean run AI settings

Getting started

  1. Open a repository folder.
  2. Press Cmd+Shift+P (or Ctrl+Shift+P) and run PRSniffer: Review Changes.
  3. Results land in the PRSniffer panel in the activity bar.

That is the whole free tier. For AI review, run PRSniffer: AI Settings, pick a provider, and save a key.

You can review all changes, only committed ones, or only uncommitted ones — see PRSniffer: Set Review Scope.

Commands

All 40 commands are available from the Command Palette.

Reviewing

Command What it does
PRSniffer: Review Changes Review your working tree (default)
PRSniffer: Review Committed Changes Review only committed changes
PRSniffer: Review Uncommitted Changes Review only uncommitted changes
PRSniffer: Review All Changes (Committed + Uncommitted) Committed and uncommitted together
PRSniffer: Stop Review Stop a running review
PRSniffer: Set Review Scope Choose the default scope
PRSniffer: Select Files to Review Pick specific files
PRSniffer: Select Base Branch Override the base branch used for the diff
PRSniffer: Set Auto-Review Mode Never / ask / auto after commits
Refresh Review Surfaces Reload the panel and findings tree
PRSniffer: Clear Findings Empty the current results

Working a finding

Command What it does
Open Review Panel Show the panel
Open Finding Jump to the finding in your code
Show Diff Preview the suggested fix as an editable diff
PRSniffer: Apply Fix Generate a fix, edit it, then apply
Apply Fix Apply the fix for the selected finding
Approve Fix Approve a fix awaiting your approval
Reject Fix Decline a fix; the finding stays open
Dismiss Finding Hide a finding from the list
Ignore Ignore a finding
Collapse Collapse a finding's thread
Copy Fix Brief Copy a self-contained fix brief to the clipboard
Copy Steps to Reproduce Copy numbered reproduction steps
PRSniffer: Generate Docstrings Generate docstrings for reviewed code
PRSniffer: Generate Tests Generate tests for reviewed code

AI agent handoff

Command What it does
Fix with AI Hand one finding to your AI agent
PRSniffer: Fix All with AI Agent Hand every finding to your agent
PRSniffer: Set AI Agent for Fix Choose Copilot, Claude Code, Codex CLI, OpenCode, Cline, Roo or Kilo

AI provider and settings

Command What it does
PRSniffer: AI Settings Provider, model, key, budget and refinement
PRSniffer: Open Settings Open VS Code settings
Configure AI Provider Choose a provider
Set AI Provider Key Save a provider key securely
Clear AI Provider Key Remove the stored key
PRSniffer: Test AI Provider Check the provider is reachable
PRSniffer: Refresh AI Models Reload the model list

PRSniffer backend

These are only needed if you use a PRSniffer backend for reviews, fixes or PR comments. The static tier does not need them.

Command What it does
Connect to PRSniffer Store the backend URL and key
Test Connection Check the backend is reachable
Clear Stored Credentials Remove the stored backend key
PRSniffer: Ask Chat Ask the backend about the current findings

Getting started

Command What it does
Show Quickstart Reopen the welcome panel

Settings

There are 27 settings. The ones worth knowing:

Setting Default What it does
prsniffer.reviewScope all Default scope: all, committed or uncommitted
prsniffer.baseBranch auto-detected Branch the diff is taken against
prsniffer.aiProvider none Provider for the AI tier
prsniffer.aiProviderApiKey — Provider key (use Set AI Provider Key instead)
prsniffer.aiTokenBudget — Token budget per review
prsniffer.aiRefine false Run a refinement pass over AI findings
prsniffer.offline false Static heuristics only, zero tokens
prsniffer.maxFiles — Cap on files per AI review
prsniffer.severityFilter all Minimum severity shown in the tree
prsniffer.agentType — Which agent handles agent handoff

The rest cover base URLs, per-provider regions, refinement tuning, and token limits. All of them are documented in VS Code settings.

Review instructions

Teach it your conventions. Add path_instructions to .prsniffer.yaml:

path_instructions:
  - paths: ["src/api/**"]
    instructions: "All handlers must validate input and check the caller's role."

Or add a repo-wide brief at .prsniffer/instructions.md. Existing guides (AGENTS.md, CLAUDE.md, .cursorrules) are detected too.

Requirements

  • VS Code 1.80 or later (Cursor and Windsurf work the same way)
  • OpenGrep on your PATH for the full static tier. Without it PRSniffer still reports what its built-in heuristics find, and tells you in the output channel.

Privacy

  • The static tier makes no network calls.
  • The AI tier sends only the files you reviewed, to the provider you chose, using your key.
  • Keys are stored in VS Code SecretStorage, never in settings or logs.
  • prsniffer.offline disables the AI tier completely.

Known limitations

  • The static tier is pattern- and rule-based, not full dataflow analysis. It will miss vulnerabilities that need cross-file reasoning.
  • Rule coverage is strongest in JavaScript, TypeScript and Python.
  • AI review quality depends entirely on the provider and model you pick.

License

MIT

  • Contact us
  • Jobs
  • Privacy
  • Manage cookies
  • Terms of use
  • Trademarks
  • Your Privacy Choices
  • Consumer Health Privacy
© 2026 Microsoft