Choose the evidence boundary

Start with what
you actually have.

A published extension, an installed editor, and a portable report need different workflows. GuardRails keeps those boundaries explicit instead of pretending a browser can inspect everything.

Before installation

Find a published extension.

Search Visual Studio Marketplace and Open VSX, inspect the latest analyzed release, then compare permissions before an update reaches your editor.

  • Exact marketplace version
  • Permission Passport
  • Deep Scan evidence
Search the Extension Registry
Already installed

Audit your local editors.

The GuardRails CLI finds extensions across supported editors and inspects local snapshots without uploading their source.

Open the CLI guide
Portable evidence

Open a report privately.

Import a canonical report.zip in this browser. Its files remain on this device and the recorded decision is not recalculated.

Already have a GuardRails report?

Drop report.zip here or choose it from your device. Nothing is uploaded.

Clear by design

No misleading “upload and scan” promise.

A website cannot enumerate installed extensions, and a lightweight browser preview is not a security decision. Published packages use Deep Scan; installed packages use the local CLI; portable evidence uses the report importer.