# Augment

> Augment is a community-maintained IDE extension from Augment Code. Anomity scores its risk at 50 out of 100 (medium).

- **Canonical URL:** https://catalog.anomity.ai/extension/augment
- **Kind:** IDE extension
- **Publisher:** Augment Code
- **Trust level:** community
- **Risk score:** 50/100 (medium)
- **Website:** https://augmentcode.com
- **Last updated:** 2026-09-02
- **JSON:** https://catalog.anomity.ai/api/entries/extension/augment

## Description

Augment is an enterprise-focused AI coding assistant whose pitch centers on continuous, full-repository codebase indexing. Instead of feeding a model only the file currently open, Augment maintains a dense semantic index of the entire codebase and feeds the most relevant snippets into every completion, chat, or refactor — which becomes especially valuable on large, polyglot monorepos.

The extension reads files across the open workspace and across any repositories the team has connected to Augment's index, makes outbound network requests to Augment's hosted service for completions, chat, and indexing pushes, and stores credentials for the user's Augment account in the IDE secret store. It does not request filesystem write or shell execute permissions, which makes its declared attack surface narrower than the fully agentic coding extensions.

Augment is community trust in Anomity's catalog because it is an independent vendor rather than a marketplace platform. The active risk signals come from the credential + outbound network pairing, which is the standard cost of any SaaS coding assistant. Teams adopting Augment should validate the vendor's data-handling and code-residency terms — the value of full-repo indexing comes with the cost of transmitting all of that code to the vendor.

## Why it scored 50

The score starts at the catalog's neutral base of 50 and moves only through the signals below. The formula is published at https://catalog.anomity.ai/about — there is no model and no hidden heuristic.

| Signal | Contribution | Severity | Evidence |
| --- | --- | --- | --- |
| Established community project | -10 | trust offset |  |
| 1 high-risk capability: credentials:access | +10 | high |  |

Clamped result: **50/100**, band **medium**.

## Capabilities

| Capability | Name | Security implication |
| --- | --- | --- |
| `filesystem:read` | Filesystem read | Can read files on the host system. Used for context, indexing, or analysis. |
| `network:outbound` | Outbound network | Can make outbound network requests. Required for hosted model providers and remote APIs; also the path for data exfiltration if combined with read access. |
| `credentials:access` | Credentials access | Reads provider API keys, OAuth tokens, or other secrets from the host keychain or environment. |

## Related IDE extensions

- [Claude Code for VS Code](https://catalog.anomity.ai/extension/claude-code-for-vscode) — risk 100 (critical)
- [Cline](https://catalog.anomity.ai/extension/cline) — risk 100 (critical)
- [Kilo Code](https://catalog.anomity.ai/extension/kilo-code) — risk 100 (critical)
- [OpenAI Codex for VS Code](https://catalog.anomity.ai/extension/openai-codex-vscode) — risk 100 (critical)
- [Roo Code](https://catalog.anomity.ai/extension/roo-code) — risk 100 (critical)
- [Blackbox AI](https://catalog.anomity.ai/extension/blackbox-ai) — risk 80 (critical)

---

Source: Anomity Catalog (https://catalog.anomity.ai/). Scoring methodology: https://catalog.anomity.ai/about. Machine-readable index: https://catalog.anomity.ai/llms.txt · https://catalog.anomity.ai/openapi.json
