# Refact.ai

> Refact.ai is a community-maintained IDE extension from Refact.ai. Anomity scores its risk at 100 out of 100 (critical). It matches 3 dangerous capability combinations.

- **Canonical URL:** https://catalog.anomity.ai/extension/refact-ai
- **Kind:** IDE extension
- **Publisher:** Refact.ai
- **Trust level:** community
- **Risk score:** 100/100 (critical)
- **Website:** https://refact.ai
- **Repository:** https://github.com/smallcloudai/refact
- **Last updated:** 2026-09-02
- **JSON:** https://catalog.anomity.ai/api/entries/extension/refact-ai

## Description

Refact.ai is an open-source AI coding assistant offering completion, chat, and an agent mode, with a self-hosted server option so the models can run inside your own infrastructure.

In self-hosted mode it reads and writes the workspace and executes commands in agent mode without sending code to a third party. The catalogued capabilities reflect the agentic configuration — filesystem read and write plus shell execution, with network access to whichever model endpoint is configured. Self-hosting removes the data-residency question but not the agent question: an agent that can edit and execute locally is still an agent that can edit and execute.

## Why it scored 100

The score starts at the catalog's neutral base of 50 and moves only through the signals below. The formula is published at https://catalog.anomity.ai/about — there is no model and no hidden heuristic.

| Signal | Contribution | Severity | Evidence |
| --- | --- | --- | --- |
| Established community project | -10 | trust offset |  |
| 2 high-risk capabilities: filesystem:write, shell:execute | +20 | critical |  |
| Data exfiltration risk (high) | +15 | high | Shell execution combined with outbound network access can exfiltrate arbitrary data from the machine. |
| Persistence + execution risk (medium) | +5 | medium | Shell execution plus filesystem write means the agent can plant persistent backdoors (e.g. modifying startup scripts). |
| Full-control risk (critical) | +25 | critical | Shell + filesystem write + network is effectively a remote shell on the employee machine. |

Clamped result: **100/100**, band **critical**.

## Capabilities

| Capability | Name | Security implication |
| --- | --- | --- |
| `filesystem:read` | Filesystem read | Can read files on the host system. Used for context, indexing, or analysis. |
| `filesystem:write` | Filesystem write | Can create, edit, or delete files on the host system. High-impact capability — anything from helpful edits to planting persistence. |
| `shell:execute` | Shell execution | Can run arbitrary shell commands. Combined with network access this becomes effectively a remote shell. |
| `network:outbound` | Outbound network | Can make outbound network requests. Required for hosted model providers and remote APIs; also the path for data exfiltration if combined with read access. |

## Dangerous combinations matched

### Data exfiltration risk (high)

Shell execution combined with outbound network access can exfiltrate arbitrary data from the machine.

Capabilities: `shell:execute`, `network:outbound`

### Persistence + execution risk (medium)

Shell execution plus filesystem write means the agent can plant persistent backdoors (e.g. modifying startup scripts).

Capabilities: `shell:execute`, `filesystem:write`

### Full-control risk (critical)

Shell + filesystem write + network is effectively a remote shell on the employee machine.

Capabilities: `shell:execute`, `filesystem:write`, `network:outbound`

## Related IDE extensions

- [Claude Code for VS Code](https://catalog.anomity.ai/extension/claude-code-for-vscode) — risk 100 (critical)
- [Cline](https://catalog.anomity.ai/extension/cline) — risk 100 (critical)
- [Kilo Code](https://catalog.anomity.ai/extension/kilo-code) — risk 100 (critical)
- [OpenAI Codex for VS Code](https://catalog.anomity.ai/extension/openai-codex-vscode) — risk 100 (critical)
- [Roo Code](https://catalog.anomity.ai/extension/roo-code) — risk 100 (critical)
- [Continue](https://catalog.anomity.ai/extension/continue) — risk 75 (high)

---

Source: Anomity Catalog (https://catalog.anomity.ai/). Scoring methodology: https://catalog.anomity.ai/about. Machine-readable index: https://catalog.anomity.ai/llms.txt · https://catalog.anomity.ai/openapi.json
