Skip to content

The VS Code extension

The extension is a client over the same engine the CLI drives. It builds the threat model, lists every exposure worst-first against the line it describes, and puts the two tiers on different sides of VS Code’s workspace-trust boundary.

The extension is Bravos 0.9.1, marked preview, and it is published nowhere. Queried on 10 September 2026: the VS Code Marketplace extension query API returns a total count of 0 for bravos.bravos, and Open VSX answers Extension not found: bravos.bravos. There is no VSIX release to link either.

So this page describes what it does rather than how to install it. Everything below is read from the extension manifest it ships with. Install steps land when there is something to install.

It is a client, not a copy: bravos.enginePath (default bravos) names the engine binary it runs, so the CLI has to be present.

The manifest declares limited support for untrusted workspaces, and the line it draws is the same one the CLI draws:

The model tier runs in an untrusted folder: it reads code and annotations and sends no traffic anywhere. The verify tier does not: a run that fires live exploits reads this repository to decide what to attack, which is not a decision to take on a workspace you have not trusted. Trust the folder to enable it.

Four settings are ignored from workspace settings until you trust the folder: bravos.enginePath, bravos.targetUrl, bravos.model and bravos.providerMode. A repository that could set them could name the program to run and the host to attack.

A Bravos activity-bar container with a Threat model view, and 21 commands. The ones that matter, by tier:

Command Tier Does
Bravos: Analyse this repository model picks what to do from what the machine has: builds the model when there is none, opens the findings when there is one
Bravos: Build the threat model model titled “reads code, sends nothing”
Bravos: Annotate this repo model has the agent write annotations
Bravos: Results / Open report / Open dashboard model reads what a run produced
Bravos: Check environment model probes for the engine and its dependencies
Bravos: Test my app for security problems verify the guided path into a scan
Bravos: Run scan verify titled “sends live exploit traffic”
Bravos: Verify an exposure is exploitable… verify “sends live probes”. Always asks, and shows the target in its consent dialog
Bravos: Resume a halted run verify “continues live probing”
Bravos: Propose an entitlement… triage proposes that a capability is by design
Bravos: Review entitlement proposals triage titled “writes @entitles to your source”

The command titles carry their own consequences, so the command palette states what a command does before it runs rather than after.

The extension contributes four theme colours: bravos.exposesBackground and bravos.exposesForeground for an @exposes annotation, described as “a hypothesis, not yet tested”, and bravos.confirmedBackground and bravos.confirmedForeground for an @confirmed one, “a probe proved it exploitable”.

Findings in the Threat model view are listed worst-first and each is marked tested or untested with the reason the engine recorded, which is the same distinction the ledger makes. The view can be searched, filtered by severity, and filtered by triage disposition.

Three settings decide it, and they narrow each other:

Setting Decides
bravos.model the model used for annotation and for the judgment inside a scan. Set through Bravos: Select model rather than typed. Empty means Bravos asks once, at the first annotate or scan
bravos.providerMode what that picker may offer: auto (both), host-lm (this editor’s models only), or cli (installed coding-agent CLIs only, for CI and headless profiles)
bravos.agentModel the model passed to a coding-agent CLI as --model. Free text, because each vendor names and renames its own models and the CLI is what validates the id

host-lm is the editor’s own model, reached through Bravos’s bridge provider instead of a separate coding-agent CLI. That is not only convenience: a CLI agent is spawned with its approval prompts disabled and can touch your machine, while the bridge sends a prompt to the editor’s model and cannot. See Authorization and blast radius.

bravos.fallbackChain names the order to try other coding agents when one fails.

bravos.targetUrl only pre-fills the single-exposure verify command. Per the manifest, Bravos: Run scan ignores it outright:

a complete scan takes its target, identities, lens order, depth and out-of-band channel from a plan you review and approve (bravos intake), because those are the facts that decide what a run is worth and a settings key states none of them.