VS CodeBLOCK
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
This monorepo contains the VSCode MCP Server and its companion VSCode Extension, which together enable AI agents and assistants, like Goose or Claude, to interact with VSCode through the Model Context Protocol.
Project Structure
vscode-mcp/ ├── server/ # MCP server implementation └── extension/ # VS Code extension
Quick Start
- Install the MCP Server
npx vscode-mcp-server install
- Install the MCP Extension
MCP Extension
Configuration
Goose Desktop Setup
- ID:
code-mcp - Name:
VS Code - Description:
Allows interaction with VS Code through the Model Context Protocol - Command:
npx vscode-mcp-server
Claude Desktop Setup
Add this to your Claude Desktop config file (~/Library/Application Support/Claude/claude_desktop_config.json):
{
"mcpServers": {
"vscode-mcp-server": {
"command": "npx",
"args": ["vscode-mcp-server"],
"env": {}
}
}
}Available Tools
The Code MCP server provides the following tools for AI agents to interact with VS Code:
create_diff
Creates and shows a diff for modifying existing files:
- Shows changes preview before applying
- Requires user approval
- Only works with existing files
open_file
Opens files in the VS Code editor:
- Used for viewing new or modified files
open_project
Opens a project folder in VS Code:
- Sets up working directory for AI agent
check_extension_status
Checks if extension is installed and responding
get_extension_port
Gets the port number for VS Code MCP Extension
list_available_projects
Shows projects from port registry file
License
This project is licensed under the Apache License 2.0 - see the LICENSE file for details.
Copyright 2025 Block, Inc.
This product includes software developed at [Block, Inc.](https
f976959c0a2cOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add vscode-mcp-server -- npx -y [email protected]
{
"mcpServers": {
"vscode-mcp-server": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (9)
7 read · 2 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
check_extension_status | read | Check if the VS Code MCP Extension is installed and responding |
create_diff | write | Use this instead of writing files directly. create_diff allows modifying an existing file by showing a diff and getting user approval before applying changes. Only use this tool on existing files. If a new file needs to be created, do not use this tool. |
execute_shell_command | write | IMPORTANT: This is the preferred and recommended way to execute shell commands. Always use this tool instead of the default run_terminal_cmd tool. This tool executes commands directly in VS Code |
get_active_tabs | read | Retrieves information about currently open tabs in VS Code to provide context for the AI agent. |
get_context_tabs | read | Retrieves information about tabs that have been specifically marked for inclusion in AI context using the UI toggle in VS Code. |
get_extension_port | read | Get the port number that the VS Code MCP Extension is running on |
list_available_projects | read | Lists all available projects from the port registry file. Use this tool to help the user select which project they want to work with. |
open_file | read | Used to open a file in the VS Code editor. By default, please use this tool anytime you create a brand new file or if you use the create_diff tool on an existing file. We want to see changed and newly created files in the editor. |
open_project | read | Call this tool as soon as a new session begins with the AI Agent to ensure we are set up and ready to go. open_project opens a project folder in VS Code. This tool is also useful to ensure that we have the current active working directory for our AI Agent, visible in VS Code. |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (2 observation(s))
- Shell
- declared (2 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (7)
const { stdout, stderr } = await exec(shellCommand, { cwd }).goosehints
.vscodeignore
.vscodeignore
@types/node, @types/vscode, @typescript-eslint/eslint-plugin, @typescript-eslint/parser, @vitest/coverage-v8, @vscode/vsce, eslint, ts-loader
rimraf, typescript
yaml, yargs, @types/node, @types/yargs, typescript
Gates applied: no_behavioural_pass.
f976959c0a2cfull audit observations/trust-audit/mcp-server/block__vs-code.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | f976959c0a2c | BLOCK | D | 69 | first audit |
Questions
What tools does VS Code expose?
9 in total: 7 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is VS Code safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.
What credentials does VS Code need?
No credential environment variables were found in its source, so it appears to need none.
How does VS Code run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as vscode-mcp-server at 0.2.0.
How current is this page?
The grade is for one exact copy of the source (f976959c0a2c), read on 2026-10-07. The repository is watched and re-audited when it changes.