Skip to main content

Use case · Developers

The security finding on the line that causes it.

A finding that arrives in a report a week later is a context switch. The VS Code extension puts it under the line you just wrote, explains why it matters, and offers the fix, in VS Code, Cursor and Windsurf.

VS Code extension · Vulkro for Salesforce · Vulkro Core

01The problem

Security findings usually arrive after the code is merged

By the time a pull request or a quarterly review flags it, the code is merged and the person who wrote it is three tasks further on.

  • Late

    A finding raised in CI, or after release, costs a re-read of code you no longer have in your head.

  • Unexplained

    A rule id and a severity tell you something is wrong, not why it matters here or what to write instead.

  • Sharing mode is not shown

    In Apex, whether a class runs with or without sharing changes everything, and nothing on screen tells you.

03The workflow

Steps from first scan to fix

  1. 01

    Install once

    Run install-extension from vulkro or vulkro-sf. It finds your editor and installs the extension.

    VS Code extension
  2. 02

    Open a file

    Findings appear under the lines that cause them, with how each Apex class runs shown above it.

    Vulkro for Salesforce
  3. 03

    Hover and read

    Why it matters, and what to write instead, without leaving the file.

    VS Code extension
  4. 04

    Fix and save

    Apply the fix from the lightbulb or write your own. Saving re-runs the engine and the line clears.

    VS Code extension
  5. 05

    Match CI

    Check that the editor and the CI scan agree, so nothing surprises you on the pull request.

    Vulkro Core

04What you get

What you get

On the line
Diagnostics in the gutter and the Problems panel, the same engine as the CLI.
Explained
Rule, severity, why it matters and the remediation, on hover.
You approve every fix
No edit is applied until you accept it, deterministic or AI-drafted.
Local
Scanning runs on your machine. AI help, when you turn it on, uses a local model by default.
Same as CI
A suppression comment silences the same finding in the editor and in the pipeline.

Questions

Common questions

Is it on the Visual Studio Marketplace?
Not yet. It installs from a .vsix with one command, `vulkro install-extension` or `vulkro-sf install-extension`, which detects VS Code, Cursor, Windsurf and VSCodium.
What about JetBrains IDEs?
There is no JetBrains plugin. The language server works with editors that speak the Language Server Protocol, and ships ready-made setups for Neovim, Helix and Emacs.
Does it slow down typing?
No. Typing only republishes cached results. The engine runs on open and on save, or on file changes if you turn on watch mode.
Does my code leave the machine?
No. The extension runs the scanner locally. Using your editor’s own cloud AI model is opt-in, behind an explicit confirmation.

Fix security findings as you write the code.