Skip to main content

VS Code extension

The security finding, on the line that causes it. With the path and the fix.

Vulkro underlines what an attacker could reach, shows the path from the request to that line, and offers the fix, before the code reaches a pull request. Same engine as the command line and CI, on your machine.

VS Code · Cursor · Windsurf · VSCodium

01The problem

Findings usually arrive after the code is written. The extension shows them on save.

Review usually happens in a pull request or a pipeline, long after the line was written. Hover or tap a stage to see what happens there.

SaveThe extension reports here: the line, the path behind it and the fix, on open and on save.

  1. 01By the time a pipeline reports, the author has moved on to the next task.
  2. 02A finding with no path sends a developer hunting for where the data came from.
  3. 03A fix written in a hurry gets no second check before it merges.

02Why now

AI assistants now write code in your editor

Assistants generate whole files, suggest packages that do not exist and run with their permission prompts switched off. Pick an event to see the weakness behind it and what Vulkro flags.

Every attack and law, with sources

What happened

CISA reported that axios 1.14.1, published to npm on 31 March 2026, pulled in a malicious dependency, plain-crypto-js, which downloads multi-stage payloads including a remote access trojan. It told users to downgrade, delete the dependency and rotate repository, CI, cloud, npm and SSH credentials.

The weakness

A trusted dependency version that adds a new package whose install-time code fetches and runs a remote payload.

Source: CISA: supply chain compromise impacts axios Node Package Manager

What Vulkro flags

Vulkro flags the malicious axios and plain-crypto-js versions in your lockfile as known-malicious, and flags install code that fetches and runs a remote payload.

  • MAL-2026-2307 (axios 1.14.1)
  • MAL-2026-2306 (plain-crypto-js 4.2.1)
  • MAL-LOADER-001

03In the editor

Find, understand and fix a finding without leaving the file

Step through what the extension does with one route file: the underline, the proof on hover, the fix on the lightbulb, your editor's AI asking Vulkro, and the check that CI will agree.

Underlined on open and on save

The open file is painted first with a fast scan, then reconciled with the whole project moments later. Saving re-analyses only the file you saved.

  • Each problem starts with its proof tier in words: proven, unproven or not checked.
  • Typing never triggers a scan, so the editor stays quiet while you work.
1 / 5

04Proof and control

Nothing changes in your files without your approval

Measured detection underneath, and nothing that acts on its own. Try the controls: apply or discard a fix, set the severity floor, choose where AI help runs.

How we measure
planted vulnerabilities found in blind test apps by the engine the extension runs, vulkro 0.30.0
entry points mapped in the same apps, so the path starts at the real route
edits the extension makes to your files without your approval

Every edit

You review every edit before it is applied

src/routes/orders.ts:13Proposed

- const token = Math.random().toString(36).slice(2);
+ const token = randomBytes(32).toString('hex');

The extension never writes to your files on its own: not a suppression, not a fix, not an AI draft.

Severity floor

The editor and CI show the same findings

  • criticalSQL query built from request data
  • highInvoice looked up with no owner check
  • mediumInsecure random used for a session token
  • lowX-Powered-By header not disabled
  • infoDependency with an advisory your code does not reach

The same floor in CI

vulkro scan . --min-severity low

A display floor, not a scan setting: the scanner still detects everything.

AI help, optional

A local model by default, or your editor’s model

Your code and findingsA local model on this machine

Ollama, with qwen2.5-coder:7b by default. Nothing leaves your machine.

AI never changes a finding, a severity or an exit code. Detection uses no model at all.

05How it fits

Two editions, each installed with one command

The command line finds your editor, asks which one, and installs the extension. Install the CLI first if you do not have it; it is the same engine your pipeline runs.

In a Salesforce DX project both run side by side, each on its own files.

The extension
  • VS Code
  • Cursor
  • Windsurf
  • VSCodium
The language server, vulkro lsp
  • Neovim
  • Helix
  • Emacs

JavaScript, TypeScript, Python, Go and Java, plus dependency manifests, infrastructure as code, containers and secrets, with the proof path on hover.

  • The path follows the data across files: from the route that receives it to the query in another file.
  • Quick fixes, explain and triage on the lightbulb, shared with the command line and the console.
terminal
# install the CLI, then the extension
$ curl -fsSL https://dist.vulkro.com/install.sh | bash
$ vulkro install-extension
Extension docs

Find vulnerabilities while you write the code.