Free IDE extension for risk-free vibe coding — keep secrets out of AI.
Platform coverage
SoterAI secures the places AI actually enters your company: VS Code and its derivative IDEs (Cursor, Windsurf, Kiro, Antigravity, VSCodium), the browsers employees use for ChatGPT and Gemini, workflow automations in n8n, Make, and Zapier, and any application through one API. Scanning runs locally, secrets and India PII are redacted before data leaves the machine, and every surface shares one policy engine and audit trail.
Every link below goes to the live listing or the documented install route. IDE builds are runtime-verified per editor; the browser extension ships with a manual install guide until its store listings are live.
Microsoft's extensible code editor
Scans open files, selections, and workspace context for secrets, PII, prompt injection, risky MCP tools, and dangerous terminal commands before AI reads them.
code --install-extension soterai.soterai-ide-guard
AI-native development environment
Guards context before Claude or GPT inside Cursor sees it — including the MCP configs Cursor uses for agent tools.
cursor --install-extension soterai.soterai-ide-guard
Agentic IDE (now Devin)
Scan Before AI Prompt reviews context before Cascade runs; MCP config scanning flags over-permissioned agent tools; the terminal guard reviews risky commands.
windsurf --install-extension soterai.soterai-ide-guard
VS Code-compatible editors
The same local scanner runs in any editor built on the VS Code extension platform, with per-editor install commands and Open VSX distribution.
kiro / antigravity / codium --install-extension soterai.soterai-ide-guard
20+ AI tools: ChatGPT, Claude, Gemini, Copilot
Browser Guard scans prompts in real time, redacts secrets and India PII in place, enforces organization policy offline, and surfaces shadow-AI usage.
AI workflow automation
Guard nodes sit before and after every AI step: input checks, output checks, redaction, RAG document risk, and whole-workflow security audits.
JavaScript/TypeScript, Python, REST
Input guard, output guard, RAG document scanning, and grounding checks behind one API call, with self-hosting for teams that need hard data boundaries.
API keys, tokens, database URLs, and credentials are detected in the editor or browser and redacted before the prompt leaves your machine.
Instruction-override text hidden in files, repositories, tool output, and web content is flagged before it can steer a model.
MCP servers are inventoried with their requested capabilities so over-broad filesystem, shell, or network access is caught before enablement.
The AI Memory Inspector records what context was shared per session, so exposure can be reviewed and credentials rotated quickly.
Local analyzer checks complete in under 50ms at p95 on CPU, so scanning happens inline instead of becoming a separate review step.
The IDE extension and its local scanning are free to install and work without an account; team policy sync is an optional cloud feature.
These are the coverage holes we hear about most from security reviews — and the honest reasons SoterAI exists, stated the way we would want a vendor to state them to us.
Most AI-security vendors offer only a server-side API. SoterAI inspects context inside the editor and browser, where the leak or injection actually starts.
Agent tool ecosystems are growing faster than their controls. SoterAI reviews MCP permissions where tools are adopted — the workspace — not after an incident.
Detection covers Aadhaar-like numbers, PAN, GSTIN, UPI IDs, IFSC codes, and Hinglish phrasing — the least-covered capability among general-purpose vendors.
Scanning runs locally on CPU with no network call, so it works in restricted enterprise and government environments where cloud guardrails cannot.
Observability platforms score interactions after the fact; SoterAI blocks, redacts, or requests approval before data crosses the boundary.
Teams can run the full stack on their own infrastructure and keep IDE, browser, workflow, and API enforcement under one policy and audit trail.
Windsurf can be used safely for many tasks, but its Cascade agent reads project context deeply and supports MCP tools. Secure windsurf AI usage by reviewing these boundaries before giving the agent access to a sensitive repository, and keep an access ledger so exposure can be audited.
Open files, terminal output, and nearby project files can contain credentials that silently enter AI prompts. Scan and redact before running Cascade.
Instructions hidden in repository files, documentation, or tool output can steer the agent away from the developer's intended task.
An MCP server with broad filesystem, shell, or network access exposes more than the task requires. Review permissions before enabling agent tools.
Agent-suggested commands can delete files, upload data, or expose environment variables. High-impact commands should be reviewed before execution.
Using Windsurf with production credentials today? Install the extension from Open VSX with windsurf --install-extension soterai.soterai-ide-guard, run Scan Before AI Prompt, and rotate anything that may already have been shared.
Windsurf can be used with appropriate controls, but no agentic IDE is risk-free. Safety depends on what code and credentials it can read, which MCP tools it can call, provider data settings, and whether commands are reviewed. Keep secrets out of context, restrict tool permissions, and scan sensitive content before sharing it.
The main risks are accidental secret or PII exposure through project context, indirect prompt injection hidden in files or tool output, over-permissioned MCP servers, and destructive or exfiltration-prone terminal commands.
VS Code, Cursor, Windsurf, Kiro, Antigravity, and VSCodium. The extension is runtime-verified on the first four and published on Open VSX for the rest, with per-editor install commands.
Not yet. Until the store listings are live, Chrome and Edge installs use a documented manual route on the Browser Guard pages that takes about a minute and delivers the same build.
No. n8n-nodes-soterai is published in the n8n community node registry and on npm, so you install it from n8n Settings → Community Nodes without the command line.
Yes. The IDE extension, browser guard, workflow nodes, and API enforce the same policy engine, so an organization sets rules once and gets one audit trail across surfaces.
Free for developers. Scan secrets, prompts, MCP tools, and terminal commands locally before they ever reach an AI model — in the editor, the browser, and your workflows.