The VS Code extension
The extension is a client over the same engine the CLI drives. It builds the threat model, lists every exposure worst-first against the line it describes, and puts the two tiers on different sides of VS Code’s workspace-trust boundary.
Availability
Section titled “Availability”The extension is Bravos 0.9.1, marked preview, and it is published nowhere.
Queried on 10 September 2026: the VS Code Marketplace extension query API
returns a total count of 0 for bravos.bravos, and Open VSX answers
Extension not found: bravos.bravos. There is no VSIX release to link either.
So this page describes what it does rather than how to install it. Everything below is read from the extension manifest it ships with. Install steps land when there is something to install.
It is a client, not a copy: bravos.enginePath (default bravos) names the
engine binary it runs, so the CLI has to be present.
The two tiers, in the editor
Section titled “The two tiers, in the editor”The manifest declares limited support for untrusted workspaces, and the line it draws is the same one the CLI draws:
The model tier runs in an untrusted folder: it reads code and annotations and sends no traffic anywhere. The verify tier does not: a run that fires live exploits reads this repository to decide what to attack, which is not a decision to take on a workspace you have not trusted. Trust the folder to enable it.
Four settings are ignored from workspace settings until you trust the folder:
bravos.enginePath, bravos.targetUrl, bravos.model and
bravos.providerMode. A repository that could set them could name the program
to run and the host to attack.
What it contributes
Section titled “What it contributes”A Bravos activity-bar container with a Threat model view, and 21 commands. The ones that matter, by tier:
| Command | Tier | Does |
|---|---|---|
Bravos: Analyse this repository |
model | picks what to do from what the machine has: builds the model when there is none, opens the findings when there is one |
Bravos: Build the threat model |
model | titled “reads code, sends nothing” |
Bravos: Annotate this repo |
model | has the agent write annotations |
Bravos: Results / Open report / Open dashboard |
model | reads what a run produced |
Bravos: Check environment |
model | probes for the engine and its dependencies |
Bravos: Test my app for security problems |
verify | the guided path into a scan |
Bravos: Run scan |
verify | titled “sends live exploit traffic” |
Bravos: Verify an exposure is exploitable… |
verify | “sends live probes”. Always asks, and shows the target in its consent dialog |
Bravos: Resume a halted run |
verify | “continues live probing” |
Bravos: Propose an entitlement… |
triage | proposes that a capability is by design |
Bravos: Review entitlement proposals |
triage | titled “writes @entitles to your source” |
The command titles carry their own consequences, so the command palette states what a command does before it runs rather than after.
Annotations against the code
Section titled “Annotations against the code”The extension contributes four theme colours: bravos.exposesBackground and
bravos.exposesForeground for an @exposes annotation, described as “a
hypothesis, not yet tested”, and bravos.confirmedBackground and
bravos.confirmedForeground for an @confirmed one, “a probe proved it
exploitable”.
Findings in the Threat model view are listed worst-first and each is marked tested or untested with the reason the engine recorded, which is the same distinction the ledger makes. The view can be searched, filtered by severity, and filtered by triage disposition.
Where the model comes from
Section titled “Where the model comes from”Three settings decide it, and they narrow each other:
| Setting | Decides |
|---|---|
bravos.model |
the model used for annotation and for the judgment inside a scan. Set through Bravos: Select model rather than typed. Empty means Bravos asks once, at the first annotate or scan |
bravos.providerMode |
what that picker may offer: auto (both), host-lm (this editor’s models only), or cli (installed coding-agent CLIs only, for CI and headless profiles) |
bravos.agentModel |
the model passed to a coding-agent CLI as --model. Free text, because each vendor names and renames its own models and the CLI is what validates the id |
host-lm is the editor’s own model, reached through Bravos’s bridge provider
instead of a separate coding-agent CLI. That is not only convenience: a CLI
agent is spawned with its approval prompts disabled and can touch your machine,
while the bridge sends a prompt to the editor’s model and cannot. See
Authorization and blast radius.
bravos.fallbackChain names the order to try other coding agents when one
fails.
A scan still comes from a plan
Section titled “A scan still comes from a plan”bravos.targetUrl only pre-fills the single-exposure verify command. Per the
manifest, Bravos: Run scan ignores it outright:
a complete scan takes its target, identities, lens order, depth and out-of-band channel from a plan you review and approve (
bravos intake), because those are the facts that decide what a run is worth and a settings key states none of them.
Related
Section titled “Related”- Run the loop unattended: the plan the scan command wants.
- Triage and entitlements: what an
@entitlesproposal argues, and what it may not argue.

