Twinny ↗
Twinny is a community-maintained IDE extension from twinnydotdev. Anomity scores its risk at 50 out of 100 (medium).
Analysis summary
Twinny is a community-maintained IDE extension from twinnydotdev. Anomity scores its risk at 50 out of 100 (medium).
Twinny is a free, open-source VS Code extension providing completion and chat against locally-run models via Ollama or any OpenAI-compatible endpoint, with no account and no telemetry by default.
It reads the workspace and writes accepted completions, reaching only the local or configured endpoint. Pointed at a local model it is about as private as an AI assistant gets, and its risk score reflects a genuinely small surface. The caveat is trust in the package rather than the model: it is a community extension whose updates arrive through the marketplace, and an extension with workspace write access is a meaningful supply-chain position — pin versions where that matters.
Why this entry scored 50 out of 100
This profile starts at the catalog's neutral base of 50. Because the entry is community-maintained, trust adjusts the score by -10. Declared high-risk capabilities add +10 (capped at +30). It matches no dangerous capability combinations. The clamped result is 50, placing it in the medium band.
Findings
-
Established community project Trust offset
-
1 high-risk capability: filesystem:write High
Capabilities
Every capability the entry declares, with the security implication of each.
-
filesystem:readFilesystem readCan read files on the host system. Used for context, indexing, or analysis. -
filesystem:writeFilesystem writeCan create, edit, or delete files on the host system. High-impact capability — anything from helpful edits to planting persistence. -
network:outboundOutbound networkCan make outbound network requests. Required for hosted model providers and remote APIs; also the path for data exfiltration if combined with read access.