GUARDRAILS Research
Extension security, explained from the evidence.
Technical analysis of IDE capabilities, supply-chain behavior, version changes, and the decisions security teams need to defend.
Capability is not malware
Why shell, network, filesystem, and credential access need intent and correlation before they become a security conclusion.
Read the researchLatest
Field notes and methodology
Supply chain · 12 July 2026 · 5 min
The extension artifact is the boundary
A repository, publisher name, and download count cannot substitute for the exact bytes installed in the IDE.
Field guide · 12 July 2026 · 7 min
Reading an IDE extension decision
A practical guide to ALLOW, REVIEW, BLOCK, and INCOMPLETE without mistaking scores for certainty.