2.1.0

    Continue - Use Code Llama in VS Code

    Open-source copilot for software development - bring the power of ChatGPT to your IDE

    Rank#-4245
    Publisher ContinueRegistry openvsx1,607,968Last scanned Sep 14, 2026, 11:52 PMRegistryHomepageGitHub
    Created
    3 years ago
    Last commit
    2 months ago
    Latest release
    v2.0.0-vscode4 months ago

    Security Findings

    22

    Credential harvesting

    MaliciousScanner

    Hardcoded secret + sensitive file access

    Suspicious URL TLD

    SuspiciousScanner

    URL with suspicious TLD .xyz: https://api.together.xyz/v1/

    Dynamic exec of remote content (VSX)

    SuspiciousScanner

    Download-and-execute in package.json: chmod +x

    package.json

    Dynamic exec of remote content (VSX)

    SuspiciousScanner

    Download-and-execute in gui/assets/index.js: chmod +x

    gui/assets/index.js

    Dynamic exec of remote content (VSX)

    SuspiciousScanner

    Download-and-execute in out/extension.js: chmod +x

    out/extension.js

    Hardcoded secrets/API keys9×

    SuspiciousScanner

    Private Key: PuTTY...****

    Secret Keyword: apiKe...****

    Secret Keyword: strin...****

    Secret Keyword: funct...****

    Secret Keyword: AWS_S...****

    Secret Keyword: Clien...****

    Secret Keyword: API_K...****

    Secret Keyword: x-goo...****

    Secret Keyword: ****

    out/extension.js

    Hardcoded secrets/API keys4×

    SuspiciousScanner

    Secret Keyword: API K...****

    Secret Keyword: missi...****

    Secret Keyword: Requi...****

    Secret Keyword: https...****

    gui/assets/index.js

    Sensitive file access

    SuspiciousScanner

    Access to sensitive file: ~/.aws

    Dangerous security bypass flags

    SuspiciousScanner

    Bypass flag in content: --trust

    Coverage evasion (executable content over cap)

    SuspiciousScanner

    1 executable file(s) totalling 39153592 bytes exceeded the bundle or per-file ceiling and were dropped or head-truncated (42.59% of code-bearing bytes reached the rules)

    Workflow makes outbound network call

    SuspiciousLineage

    [.github/workflows/run-continue-agent.yml] curl -f -X POST https://api.continue.dev/agents