VS Code extension · Getting started
The same audit that reviews your pull requests, run on your staged changes from inside VS Code. Findings land at the exact line, verified fixes are one click away, and nothing is posted to GitHub.
Free to install. Each check is billed to your organisation’s credits, like a pull-request audit.
The tour
One short video, seven chapters. Jump to any step, or read the same steps in full below.
The tour video is on its way. The written steps below cover everything it shows.
01
Open the Extensions view in VS Code, search for PRGuard, and click Install. A shield icon appears in the activity bar.
Needs VS Code 1.90 or later and git on your PATH. The extension has no runtime dependencies.
02
In PRGuard, open Account settings → API & CLI and create a key. It starts with prg_ and is shown once — copy it. The same key works for the prguard command-line tool.
One key per account. Creating a new one replaces the old one everywhere; revoke it from the same page if it ever leaks.
Your API key
Shown once. Store it somewhere safe — the extension keeps it in your OS keychain.
03
Click Sign in in the PRGuard view, or run PRGuard: Sign in with API key from the command palette, and paste the key. The extension verifies it, then lists the organisations you belong to. With one, it’s chosen for you.
The organisation is remembered per workspace, so a repo that belongs to one org and another that belongs to a second each keep their own choice. Switch any time from the Context files header.
Paste the API key from Account settings → API & CLI. It is stored in your OS keychain.
04
The rules PRGuard reviews against — your organisation’s context files — are pulled into a context/ folder in your repo, under the org’s name, and kept current. Read them, or point your coding assistant at them. The folder ignores itself in git.
Sync re-checks every 15 minutes and costs one request when nothing changed. A file the injection scan quarantines is withdrawn from disk. The audit itself always reads the server copy.
05
Stage your changes. The Next check section shows exactly which files would be sent. Click Run pre-commit check — in the view, the status bar, or the Source Control title bar — and confirm. The check runs on PRGuard’s servers; you see its phase and elapsed time in the panel, and a verdict in about a minute or two.
Three scopes: staged changes (default), all uncommitted changes, or the whole branch against your default branch. Untracked files count as added outside the staged scope. Running the same diff twice reuses the earlier result at no charge.
06
The PRGuard panel, next to Problems, shows the verdict and every finding with its evidence and suggested fix. Each one is also underlined at its line, and hovering it shows the finding. Where PRGuard wrote a patch and verified it applies to your file, Apply fix makes the change and highlights it, and Undo fix takes it back out. Apply all fixes does the whole check in one step.
Fix with AI hands any finding, with its full explanation, to Claude Code, Gemini Code Assist or GitHub Copilot Chat. Findings tick themselves off as their fixes land. A patch that no longer fits the file, because the lines around it changed, is marked outdated rather than applied in the wrong place.
07
Every check you run in a workspace is kept in the History section with its findings. Click one to load it back into the panel; the link icon opens its report. Ticking off or dismissing a finding carries across runs of the same finding. Your latest run comes back on its own when the window reloads.
History lives on your machine. The audits themselves are in your organisation’s dashboard audit log, marked Local, and never leave a comment on GitHub.
Settings
| Setting | Default | What it does |
|---|---|---|
| prguard.serverUrl | https://prguard.dev | Your PRGuard instance. Set before signing in on a self-hosted server. |
| prguard.contextDirectory | context | Where context files sync, relative to the workspace root. |
| prguard.autoSyncIntervalMinutes | 15 | How often to re-check the bundle. 0 turns the timer off. |
| prguard.check.scope | staged | staged · working-tree · branch. Also on the Next check header. |
| prguard.check.includeFileContents | true | Send each changed file’s full contents for the static scan and patch verification. The model reads only the diff. |
| prguard.check.maxFileKilobytes | 512 | Larger files are sent diff-only. |
| prguard.check.confirmBeforeRun | true | Ask before each billed check. |
Questions
No. A pre-commit check never leaves a comment, review, status or check run. It is recorded in your organisation’s dashboard audit log as a Local check, which teammates can open like any audit — without the uploaded source, which is held only for the run and then cleared.
The same as a pull-request audit of the same change: the gatekeeper screen, the static scan, the detect-and-elaborate passes and the patch verification all run. Typically a few tens of cents for a small change. Running an identical diff again reuses the earlier result for free. The confirmation dialog reminds you before every run.
The diff for the chosen scope, split per file, and — by default — each changed file’s current contents, which the deterministic static scan reads and the patch verification applies fixes to. The model itself reads only the diff. Nothing outside the changed files is uploaded.
In your operating system’s keychain, through VS Code’s secret storage, keyed by server — a key for a staging instance is never sent to prguard.dev. Signing out removes it.
One thing: the pull-request audit also skeletonises files your change references, fetched from GitHub at a trusted commit. Uncommitted code has no trusted commit, so a local check skips that step. Everything else is the same engine and the same standards. The pull-request audit still runs when you open the PR.
AI usage is part of your subscription, not a bill on the side. Every plan includes a set monthly AI credit allowance, and each audit draws from it — no separate API key to bring, no separate token invoice. And if a busy month needs more, top-up credits are available anytime and roll over.
Install, sign in, stage a change, check it. Under five minutes.