Use case · Developers
The security finding on the line that causes it.
A finding that arrives in a report a week later is a context switch. The VS Code extension puts it under the line you just wrote, explains why it matters, and offers the fix, in VS Code, Cursor and Windsurf.
VS Code extension · Vulkro for Salesforce · Vulkro Core
01The problem
Security findings usually arrive after the code is merged
By the time a pull request or a quarterly review flags it, the code is merged and the person who wrote it is three tasks further on.
Late
A finding raised in CI, or after release, costs a re-read of code you no longer have in your head.
Unexplained
A rule id and a severity tell you something is wrong, not why it matters here or what to write instead.
Sharing mode is not shown
In Apex, whether a class runs with or without sharing changes everything, and nothing on screen tells you.
02How Vulkro handles it
What each part of Vulkro does
- Findings on open and save, painted for the current file in a fraction of a second, then reconciled with the whole project
- Hover for the rule, the severity, the message and the fix
- Suppress, explain or apply a one-line fix from the lightbulb, and nothing changes until you accept it
- Installs in VS Code, Cursor, Windsurf and VSCodium with one command
- Apex, LWC, Aura, Visualforce, Flows and permission metadata
- How each Apex class runs, shown above it: system or user mode, with or without sharing
- The data flow behind a finding, source to sink, in the Problems panel
- JavaScript, TypeScript, Python, Go and Java files, scanned the way CI scans them
- A check that your editor shows what your CI gate will enforce
- Optional AI fixes on a local model, offered only after a re-scan confirms the finding is gone
03The workflow
Steps from first scan to fix
- 01VS Code extension
Install once
Run install-extension from vulkro or vulkro-sf. It finds your editor and installs the extension.
- 02Vulkro for Salesforce
Open a file
Findings appear under the lines that cause them, with how each Apex class runs shown above it.
- 03VS Code extension
Hover and read
Why it matters, and what to write instead, without leaving the file.
- 04VS Code extension
Fix and save
Apply the fix from the lightbulb or write your own. Saving re-runs the engine and the line clears.
- 05Vulkro Core
Match CI
Check that the editor and the CI scan agree, so nothing surprises you on the pull request.
04What you get
What you get
- On the line
- Diagnostics in the gutter and the Problems panel, the same engine as the CLI.
- Explained
- Rule, severity, why it matters and the remediation, on hover.
- You approve every fix
- No edit is applied until you accept it, deterministic or AI-drafted.
- Local
- Scanning runs on your machine. AI help, when you turn it on, uses a local model by default.
- Same as CI
- A suppression comment silences the same finding in the editor and in the pipeline.
Questions
Common questions
- Is it on the Visual Studio Marketplace?
- Not yet. It installs from a .vsix with one command, `vulkro install-extension` or `vulkro-sf install-extension`, which detects VS Code, Cursor, Windsurf and VSCodium.
- What about JetBrains IDEs?
- There is no JetBrains plugin. The language server works with editors that speak the Language Server Protocol, and ships ready-made setups for Neovim, Helix and Emacs.
- Does it slow down typing?
- No. Typing only republishes cached results. The engine runs on open and on save, or on file changes if you turn on watch mode.
- Does my code leave the machine?
- No. The extension runs the scanner locally. Using your editor’s own cloud AI model is opt-in, behind an explicit confirmation.