GuardRails Research

Security research for decisions you can defend.

Practical field notes about IDE extension capability, exact-release evidence, and the line between a useful signal and an unsupported conclusion.

01Exact artifact before reputation02Evidence before interpretation03Limitations beside every conclusion
Featured field note · Methodology · 6 min

Capability is not malware

Why shell, network, filesystem, and credential access need intent and correlation before they become a security conclusion.

Read the field note
Research library

Short reads. Explicit boundaries.

Written for developers and reviewers who need to understand what an extension can do, what changed, and what remains unknown.

02
Supply chain · 12 July 2026 · 5 min

The extension artifact is the boundary

A repository, publisher name, and download count cannot substitute for the exact bytes installed in the IDE.

03
Field guide · 12 July 2026 · 7 min

Reading an IDE extension decision

A practical guide to ALLOW, REVIEW, BLOCK, and INCOMPLETE without mistaking scores for certainty.

Start with the evidence

Inspect an exact extension release.

Open the registry to see artifact identity, analysis freshness, capability boundaries, and immutable report evidence together.

Explore the registry