Visual Studio Code
Cortex for Visual Studio Code
Project-aware coding, security findings, change review and connected workflows in Visual Studio Code.
Cortex for Visual Studio Code combines a chat experience with editor actions, security result views and commands for reviewed project work. It supports the developer’s path from understanding code to proposing, checking and delivering a change.
Get started
Section titled “Get started”- Install Pervaziv AI Cortex using the button above or your managed extension catalog.
- Open a folder or workspace.
- Open Cortex from the Activity Bar and sign in.
- Start a chat, attach selected context, or run a scan from the Cortex Commands view or VS Code Command Palette.
Scan results identify affected code and severity. Select a result to navigate to the relevant line; review the proposed diff before applying a fix. The chat can also explain code, plan changes, run validation and coordinate durable workflows.
Published surfaces
Section titled “Published surfaces”- The Cortex Activity Bar container includes Chat History, File Scan Results, Repo Scan Results, SCA Results, and Commands.
- The secondary sidebar provides the Cortex Chat view.
- The editor context menu provides selection actions for explanation, fixes, tests, review, and documentation.
- VS Code Chat exposes the
@cortexparticipant with/review,/security,/explain,/connectors, and/customize.
See VS Code commands and VS Code settings.
Code assistance and editor context
Section titled “Code assistance and editor context”Selection actions include Explain, Fix, Generate Tests, Review and Document. Notebook-cell context has a dedicated command, and related repository selection helps define a broader investigation. These entry points let the request start with the code already open in the editor.
The optional native VS Code Chat participant exposes @cortex commands for
review, security, explanation, connector management and customization. The
dedicated Cortex Chat view provides the extension’s own conversation surface.
Findings, patches and validation
Section titled “Findings, patches and validation”File, repository and SCA views keep different kinds of findings separate. Published actions include Explain Finding, Remediate Finding, Secure Patch and Verify, and validation of selected or changed-file findings. Filters can hide fixed or accepted-risk findings and focus on stale findings.
Working-tree and base-branch security reviews support checking the change under development. Change-review commands let users inspect, keep or undo Cortex edits, while command-output and terminal actions expose the associated execution results. See security workflows and change review.
Evidence and delivery workflows
Section titled “Evidence and delivery workflows”Evidence workspace commands collect selected context and start an implementation from supporting evidence. Governed workflow recipes provide an entry point for eligible multi-step tasks. Pull-request commands create or open a PR in the integrated browser and push updates to reviewed work.
Evidence workflows and pull requests describe these interfaces.
Conversation organization and customization
Section titled “Conversation organization and customization”Chat History supports search, refresh, renaming, forks, pinning, parent-chat navigation and collections. Collection actions include moving, archiving and restoring conversations. These controls help separate investigations while keeping related work discoverable.
Connector management and customizations have dedicated commands. Generate Agents File provides a starting point for repository guidance. The installed extension, signed-in plan and organization policy determine which views, tools and settings are available.
Plan, implement and prove the result
Section titled “Plan, implement and prove the result”For a larger change, begin with the requirement and available evidence rather than asking for a patch immediately. Cortex can help identify relevant project context, separate implementation from verification and propose acceptance conditions. Use published evidence-workspace and workflow commands when the task needs supporting sources or coordinated steps.
Personal Coding Style preferences help align comments, documentation, naming, error handling, typing and tests with the project’s expectations. Test Design Specification focuses the checks on observable behavior and meaningful failure cases. Verification examines whether the change and evidence address the original request; it does not replace the team’s review or merge requirements.
Threat modeling and implementation review
Section titled “Threat modeling and implementation review”AI Threat Model considers assets, entry points and trust boundaries before a design becomes code. AI Security Review examines implementation risks such as authorization gaps, injection, secret exposure and unsafe defaults. Working tree and base-branch review commands let the check start with the code under development rather than an unrelated repository snapshot.
Use finding navigation and remediation actions to investigate the affected lines, then inspect the patch and test results. Fixed, accepted-risk and stale finding filters help distinguish follow-up states; they do not make an older scan applicable to newly changed code.
Connected workspace responsibilities
Section titled “Connected workspace responsibilities”A connected VS Code workspace can receive eligible objectives started in a browser or on mobile through Cortex Connect. The workspace supplies its code and permitted development tools; the other client supplies access to progress and decisions. Local actions remain subject to approval and policy.
Choose Cortex Cloud when eligible work needs managed execution. A selected Cloud destination should not silently become local execution if Cloud is unavailable. Review the task result in the context of its source revision and execution target.

