This product was not featured by Product Hunt yet.
It will not be visible on their landing page and won't be ranked (cannot win product of the day regardless of upvotes).

Product Thumbnail

ExtGuard

Audit the VS Code extensions already running on your machine

Open Source
Developer Tools
GitHub
Security
Visit WebsiteSee on Product HuntVisual Studio MarketplaceCloudflare PagesGithub

Hunted byBright Asare  BediakoBright Asare Bediako

VS Code has no permission model. Any extension you install runs as ordinary Node.js with the full reach of your account: your files, your SSH keys, your terminal. Nothing had to ask, so nothing prompted you. ExtGuard audits the ones you already have, against 1,981 known-malicious records and 1,300 blocked publishers, for credentials hardcoded into shipped code, and for what each can reach. Runs entirely on your machine. No account, no telemetry, no network calls while scanning. Free and MIT.

Top comment

I built this after noticing something obvious I had never actually thought about: I had 81 extensions installed and had read the source of none of them. VS Code has no permission model. No prompt, no sandbox, no list of what an extension asked for, because it never had to ask. The interesting part was not detection, it was restraint. My first version flagged 57 of my 82 extensions. That is not a security tool, that is a tool you learn to ignore, and then you ignore the one finding that mattered. Today it flags zero on the same machine and I trust it more for that. It will not catch a competent attacker. Pattern matching never does. It catches the careless majority: typosquats, credentials left in shipped code, and extensions pulled from the marketplace that are still sitting on your disk. Free, MIT, runs locally. If it flags something of yours incorrectly, send me the extension ID and I will fix it.

Comment highlights

No comment highlights available yet. Please check back later!

About ExtGuard on Product Hunt

Audit the VS Code extensions already running on your machine

ExtGuard was submitted on Product Hunt and earned 0 upvotes and 1 comments, placing #117 on the daily leaderboard. VS Code has no permission model. Any extension you install runs as ordinary Node.js with the full reach of your account: your files, your SSH keys, your terminal. Nothing had to ask, so nothing prompted you. ExtGuard audits the ones you already have, against 1,981 known-malicious records and 1,300 blocked publishers, for credentials hardcoded into shipped code, and for what each can reach. Runs entirely on your machine. No account, no telemetry, no network calls while scanning. Free and MIT.

ExtGuard was featured in Open Source (68.8k followers), Developer Tools (518.5k followers), GitHub (41.4k followers) and Security (2.9k followers) on Product Hunt. Together, these topics include over 130.6k products, making this a competitive space to launch in.

Who hunted ExtGuard?

ExtGuard was hunted by Bright Asare Bediako. A “hunter” on Product Hunt is the community member who submits a product to the platform — uploading the images, the link, and tagging the makers behind it. Hunters typically write the first comment explaining why a product is worth attention, and their followers are notified the moment they post. Around 79% of featured launches on Product Hunt are self-hunted by their makers, but a well-known hunter still acts as a signal of quality to the rest of the community. See the full all-time top hunters leaderboard to discover who is shaping the Product Hunt ecosystem.

Want to see how ExtGuard stacked up against nearby launches in real time? Check out the live launch dashboard for upvote speed charts, proximity comparisons, and more analytics.