VS Code extensions run with your permissions while installs and badges are weak trust signals. Learn how to audit, pin, allowlist, and contain them.
Glossary definition
Security code review is the manual examination of source code and system interactions to identify defects, unsafe assumptions, and exploitable behavior.
Code review is a software quality-assurance activity in which one or several people manually review source code.
In our audits, we carefully study the codebase line by line, often several times, to reach the following goals:
Used in context
VS Code extensions run with your permissions while installs and badges are weak trust signals. Learn how to audit, pin, allowlist, and contain them.
A staged workflow for reviewing unfamiliar repositories with AI agents using read-only mounts, no credentials, restricted networks, and disposable sandboxes.