VS Code ServerSAFE
MCP server to expose VS Code editing features to an LLM for AI coding
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A Visual Studio Code extension (available on the Marketplace) that allows Claude and other MCP clients to code directly in VS Code! Inspired by Serena, but using VS Code's built-in capabilities. Perfect for extending existing coding agents like Claude Code with VS Code-specific capabilities (symbol search, document outlines) without duplicating tools they already have. Note that this extension uses the streamable HTTP API, not the SSE API.
This extension can allow for execution of shell commands. This means that there is a potential security risk, so use with caution, and ensure that you trust the MCP client that you are using and that the port is not exposed to anything. Authentication would help, but as the MCP authentication spec is still in flux, this has not been implemented for now.
PRs are welcome!
Demo Video
https://github.com/user-attachments/assets/20b87dfb-fc39-4710-a910-b9481dde1e90
Installation
- Install the extension from the Marketplace or clone this repository and run
npm installandnpm run compileto build it.
Claude Desktop Configuration
Claude Desktop can be configured to use this extension as an MCP server. To do this, your claude_desktop_config.json file should look like this:
{
"mcpServers": {
"vscode-mcp-server": {
"command": "npx",
"args": ["mcp-remote@next", "http://localhost:3000/mcp"]
}
}
}I also like to use this extension in a Claude project, as it allows me to specify additional instructions for Claude. I find the following prompt to work well:
You are working on an existing codebase, which you can access using your tools. These code tools interact with a VS Code workspace. WORKFLOW ESSENTIALS: 1. Always start exploration with list_files_code on roo
52491feb3c1dOBSERVED · 2026-10-02Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add vscode-mcp-server -- npx -y [email protected]
{
"mcpServers": {
"vscode-mcp-server": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (12)
7 read · 5 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
copy_file_code | read | Copies a file to a new location. WHEN TO USE: Creating backups, duplicating files for testing, creating template files. LIMITATION: Only works for files, not directories. |
create_file_code | write | |
execute_shell_command_code | write | |
get_diagnostics_code | write | CRITICAL: Run this after EVERY series of code changes to check for errors before completing tasks. Analyzes code for warnings and errors using VS Code |
get_document_symbols_code | read | |
get_symbol_definition_code | read | |
list_files_code | read | |
move_file_code | write | Moves a file or directory to a new location using VS Code |
read_file_code | read | Retrieves file contents with size limits and partial reading support. WHEN TO USE: Reading code, config files, analyzing implementations. Files >100k chars will fail. Encoding: Text encodings (utf-8, latin1, etc.) for text files, |
rename_file_code | write | Renames a file or directory using VS Code |
replace_lines_code | read | |
search_symbols_code | read | Searches for symbols (functions, classes, variables) across workspace using fuzzy matching. WHEN TO USE: Finding function/class definitions, exploring project structure, locating specific elements. Search: Supports partial terms (e.g., |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (4)
streamable-http
.vscode-test.mjs
.vscodeignore
@modelcontextprotocol/sdk, @types/express, express, zod, @modelcontextprotocol/inspector, @types/mocha, @types/proxyquire, @types/sinon
Gates applied: no_behavioural_pass.
52491feb3c1dfull audit observations/trust-audit/mcp-server/juehang__vs-code-server.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-02 | 52491feb3c1d | SAFE | B | 89 | first audit |
Questions
What is the VS Code Server MCP server?
MCP server to expose VS Code editing features to an LLM for AI coding
What tools does VS Code Server expose?
12 in total: 7 read-only, 5 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is VS Code Server safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does VS Code Server need?
No credential environment variables were found in its source, so it appears to need none.
How does VS Code Server run?
It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as vscode-mcp-server at 0.4.0.
How current is this page?
The grade is for one exact copy of the source (52491feb3c1d), read on 2026-10-02. The repository is watched and re-audited when it changes.