# Claude Code for VS Code

> Claude Code for VS Code is an officially published IDE extension from Anthropic. Anomity scores its risk at 100 out of 100 (critical). It matches 4 dangerous capability combinations.

- **Canonical URL:** https://catalog.anomity.ai/extension/claude-code-for-vscode
- **Kind:** IDE extension
- **Publisher:** Anthropic
- **Trust level:** official
- **Risk score:** 100/100 (critical)
- **Website:** https://docs.claude.com/en/docs/claude-code/ide-integrations
- **Last updated:** 2026-09-02
- **JSON:** https://catalog.anomity.ai/api/entries/extension/claude-code-for-vscode

## Description

Anthropic's extension that runs Claude Code inside VS Code — the same agent as the CLI, surfaced in the editor with inline diffs, a sidebar session, and the editor's own file context feeding the agent.

The capability surface is that of a full coding agent rather than a completion tool: it reads and writes files across the workspace, runs shell commands through its Bash tool, reaches the network for model calls, and holds an API credential. That combination matches Anomity's full-control pattern, which is the honest description of any agent that can edit and execute. Anthropic-published, so it takes the official trust adjustment; the operational controls that matter are its permission prompts and allow-lists, which should not be blanket-approved on repositories that hold production credentials.

## Why it scored 100

The score starts at the catalog's neutral base of 50 and moves only through the signals below. The formula is published at https://catalog.anomity.ai/about — there is no model and no hidden heuristic.

| Signal | Contribution | Severity | Evidence |
| --- | --- | --- | --- |
| Published by the vendor | -40 | trust offset |  |
| 3 high-risk capabilities: filesystem:write, shell:execute, credentials:access | +30 | critical |  |
| Data exfiltration risk (high) | +15 | high | Shell execution combined with outbound network access can exfiltrate arbitrary data from the machine. |
| Credential theft risk (high) | +15 | high | Filesystem write combined with credentials access can plant persistent credential stealers. |
| Persistence + execution risk (medium) | +5 | medium | Shell execution plus filesystem write means the agent can plant persistent backdoors (e.g. modifying startup scripts). |
| Full-control risk (critical) | +25 | critical | Shell + filesystem write + network is effectively a remote shell on the employee machine. |

Clamped result: **100/100**, band **critical**.

## Capabilities

| Capability | Name | Security implication |
| --- | --- | --- |
| `filesystem:read` | Filesystem read | Can read files on the host system. Used for context, indexing, or analysis. |
| `filesystem:write` | Filesystem write | Can create, edit, or delete files on the host system. High-impact capability — anything from helpful edits to planting persistence. |
| `shell:execute` | Shell execution | Can run arbitrary shell commands. Combined with network access this becomes effectively a remote shell. |
| `network:outbound` | Outbound network | Can make outbound network requests. Required for hosted model providers and remote APIs; also the path for data exfiltration if combined with read access. |
| `credentials:access` | Credentials access | Reads provider API keys, OAuth tokens, or other secrets from the host keychain or environment. |

## Dangerous combinations matched

### Data exfiltration risk (high)

Shell execution combined with outbound network access can exfiltrate arbitrary data from the machine.

Capabilities: `shell:execute`, `network:outbound`

### Credential theft risk (high)

Filesystem write combined with credentials access can plant persistent credential stealers.

Capabilities: `filesystem:write`, `credentials:access`

### Persistence + execution risk (medium)

Shell execution plus filesystem write means the agent can plant persistent backdoors (e.g. modifying startup scripts).

Capabilities: `shell:execute`, `filesystem:write`

### Full-control risk (critical)

Shell + filesystem write + network is effectively a remote shell on the employee machine.

Capabilities: `shell:execute`, `filesystem:write`, `network:outbound`

## Related IDE extensions

- [Cline](https://catalog.anomity.ai/extension/cline) — risk 100 (critical)
- [Kilo Code](https://catalog.anomity.ai/extension/kilo-code) — risk 100 (critical)
- [OpenAI Codex for VS Code](https://catalog.anomity.ai/extension/openai-codex-vscode) — risk 100 (critical)
- [Roo Code](https://catalog.anomity.ai/extension/roo-code) — risk 100 (critical)
- [Refact.ai](https://catalog.anomity.ai/extension/refact-ai) — risk 100 (critical)
- [Continue](https://catalog.anomity.ai/extension/continue) — risk 75 (high)

---

Source: Anomity Catalog (https://catalog.anomity.ai/). Scoring methodology: https://catalog.anomity.ai/about. Machine-readable index: https://catalog.anomity.ai/llms.txt · https://catalog.anomity.ai/openapi.json
