# Tabnine

> Tabnine is a community-maintained IDE extension from Tabnine. Anomity scores its risk at 50 out of 100 (medium).

- **Canonical URL:** https://catalog.anomity.ai/extension/tabnine
- **Kind:** IDE extension
- **Publisher:** Tabnine
- **Trust level:** community
- **Risk score:** 50/100 (medium)
- **Website:** https://tabnine.com
- **Last updated:** 2026-09-02
- **JSON:** https://catalog.anomity.ai/api/entries/extension/tabnine

## Description

Tabnine is one of the original AI code completion extensions, predating most of its current competitors and notable for offering both cloud-hosted and fully on-premises deployment models. It supports VS Code, JetBrains IDEs, Visual Studio, Neovim, Eclipse, and several other editors, and ships with enterprise features around codebase indexing, single-tenant deployment, and air-gapped model hosting.

The extension reads source files in the open workspace to assemble context for completions and chat, makes outbound network requests to Tabnine's hosted model or to a self-hosted Tabnine endpoint, and accesses stored credentials for the user's Tabnine account. It does not request filesystem write access for completions — accepted suggestions are inserted by the IDE itself — and does not execute shell commands.

Tabnine is a community trust level in Anomity's catalog because it is not a marketplace-first-party vendor. The credential + outbound network pairing is shared with most coding assistants and is not by itself a dangerous combination, but teams with strict data-handling requirements should evaluate the self-hosted plan rather than the SaaS one.

## Why it scored 50

The score starts at the catalog's neutral base of 50 and moves only through the signals below. The formula is published at https://catalog.anomity.ai/about — there is no model and no hidden heuristic.

| Signal | Contribution | Severity | Evidence |
| --- | --- | --- | --- |
| Established community project | -10 | trust offset |  |
| 1 high-risk capability: credentials:access | +10 | high |  |

Clamped result: **50/100**, band **medium**.

## Capabilities

| Capability | Name | Security implication |
| --- | --- | --- |
| `filesystem:read` | Filesystem read | Can read files on the host system. Used for context, indexing, or analysis. |
| `network:outbound` | Outbound network | Can make outbound network requests. Required for hosted model providers and remote APIs; also the path for data exfiltration if combined with read access. |
| `credentials:access` | Credentials access | Reads provider API keys, OAuth tokens, or other secrets from the host keychain or environment. |

## Related IDE extensions

- [Claude Code for VS Code](https://catalog.anomity.ai/extension/claude-code-for-vscode) — risk 100 (critical)
- [Cline](https://catalog.anomity.ai/extension/cline) — risk 100 (critical)
- [Kilo Code](https://catalog.anomity.ai/extension/kilo-code) — risk 100 (critical)
- [OpenAI Codex for VS Code](https://catalog.anomity.ai/extension/openai-codex-vscode) — risk 100 (critical)
- [Roo Code](https://catalog.anomity.ai/extension/roo-code) — risk 100 (critical)
- [Blackbox AI](https://catalog.anomity.ai/extension/blackbox-ai) — risk 80 (critical)

---

Source: Anomity Catalog (https://catalog.anomity.ai/). Scoring methodology: https://catalog.anomity.ai/about. Machine-readable index: https://catalog.anomity.ai/llms.txt · https://catalog.anomity.ai/openapi.json
