Frequently asked

Questions, answered
the way we work.

Short answers with links into the methodology, so every claim has a page behind it.

ScopeProduct, privacy, pricing
Methodology claimsAlways linked
Local analysisStays local
Free tierFull public reports
Missing something? Ask and we will add it here

What does Guardrails actually check?

Published IDE extension releases. A report examines an exact release: requested permissions, capabilities that changed since the previous version, dependency additions, and the coverage of the evidence behind each finding. Findings are normalized into six scoring dimensions and mapped to a decision you can act on.

Browse the detection catalog

Do you install or execute extensions to scan them?

No. Website analysis inspects the published package without running it inside your editor. The local CLI can examine extensions already installed on your machine, and that analysis happens on your machine — nothing is uploaded unless you explicitly export a portable report.

Choose an analysis path

What do ALLOW, REVIEW, BLOCK, and INCOMPLETE mean?

They are the four report decisions. ALLOW means findings stayed within normal behavior. REVIEW flags changes that deserve human judgment. BLOCK marks behavior that should stop an install or update in governed environments. INCOMPLETE means we could not verify enough to decide — an honest outcome, not a pass.

Read the scoring methodology

Where does my imported report live?

In your browser. Report bundles dropped into Analyze or Reports are parsed and stored locally; the importer does not upload them. You remove them from the Reports library whenever you want.

Open the Reports library

How does release monitoring decide what to tell me?

You watch specific extensions. When a new release publishes, GuardRails compares its capability surface against previous versions and notifies you only about meaningful changes — quiet re-publishes without behavioral change do not page anyone. Notifications arrive by email, Slack, Jira, or a weekly digest depending on your workspace settings.

See Release Monitoring

Which editors are supported?

Analysis covers extensions published to marketplace registries used by editors such as VS Code, Cursor, and Windsurf. Guardrails is an independent reviewer — it is not affiliated with or endorsed by those platforms, and it does not modify your editors.

Search the registry

How much does it cost?

Scanning costs nothing and stays free: public exact-release reports, the registry, and the local CLI. Beyond that there are no prices yet — guided reviews of extensions you care about are free during launch with limited weekly slots, release monitoring is open to founding members through early access, and team pricing gets set together with design partners. Nothing pretends to be a checkout before billing exists.

See access options

How validated is the scanner itself?

Openly. A published benchmark runs the scanner against a reproducible corpus and states coverage and limitations alongside results, so you can see where detection is strong and where it is honest about gaps.

Review validation and limits

A finding looks wrong — or an extension looks malicious. Now what?

Both go through Contact. Report disputes should include the exact-release link and what you believe was missed; corrections ship as visible methodology updates. Suspected malicious extensions can be flagged for urgent review at security@abscissa.dev.

Contact the team
ScoringDecisions, severities, and boundaries.BoundariesWhat runs where, what is retained.TermsThe agreement, in plain language.