by unit-mesh
AutoDev - ๐งโthe AI-powered coding wizard . Put the most loved AutoDev AI assistant into your VSCode, and have things done quickly
# Add to your Claude Code skills
git clone https://github.com/unit-mesh/autodev-vscodeGuides for using ai agents skills like autodev-vscode.
Last scanned: 5/18/2026
{
"issues": [
{
"type": "npm-audit",
"message": "@langchain/anthropic: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@langchain/core: LangChain serialization injection vulnerability enables secret extraction",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@mozilla/readability: @mozilla/readability Denial of Service through Regex",
"severity": "low"
},
{
"type": "npm-audit",
"message": "@tootallnate/once: @tootallnate/once vulnerable to Incorrect Control Flow Scoping",
"severity": "low"
},
{
"type": "npm-audit",
"message": "@vitest/coverage-v8: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@vscode/test-cli: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@xenova/transformers: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "cacache: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "dompurify: DOMPurify contains a Cross-site Scripting vulnerability",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "esbuild: esbuild enables any website to send any requests to the development server and read the response",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "fast-xml-parser: fast-xml-parser XMLBuilder: XML Comment and CDATA Injection via Unescaped Delimiters",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "http-proxy-agent: Vulnerability found",
"severity": "low"
},
{
"type": "npm-audit",
"message": "langsmith: LangSmith Client SDKs has Prototype Pollution in langsmith-sdk via Incomplete `__proto__` Guard in Internal lodash `set()`",
"severity": "high"
},
{
"type": "npm-audit",
"message": "make-fetch-happen: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "mocha: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "monaco-editor: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "node-gyp: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "onnx-proto: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "onnxruntime-web: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "prismjs: PrismJS DOM Clobbering vulnerability",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "protobufjs: Arbitrary code execution in protobufjs",
"severity": "critical"
},
{
"type": "npm-audit",
"message": "react-syntax-highlighter: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "refractor: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "serialize-javascript: Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString()",
"severity": "high"
},
{
"type": "npm-audit",
"message": "sqlite3: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "tar: node-tar Vulnerable to Arbitrary File Creation/Overwrite via Hardlink Path Traversal",
"severity": "high"
},
{
"type": "npm-audit",
"message": "vite: Vite middleware may serve files starting with the same name with the public directory",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "vite-node: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "vite-plugin-externalize-deps: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "vite-plugin-static-copy: vite-plugin-static-copy files not included in `src` are possible to access with a crafted request",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "vitest: Vulnerability found",
"severity": "medium"
}
],
"status": "FAILED",
"scannedAt": "2026-05-18T08:05:54.791Z",
"semgrepRan": false,
"npmAuditRan": true,
"pipAuditRan": true
}No comments yet. Be the first to share your thoughts!
Requires a passing catalog security scan. Resolve the flagged issues and resubmit to enable featuring.
๐งโAutoDev: the AI-powered coding wizard with multilingual support ๐, auto code generation ๐๏ธ, and a helpful bug-slaying assistant ๐! Customizable prompts ๐จ and a magic Auto Dev/Testing/Document/Agent feature ๐งช included! ๐
JetBrains' IDE Version: https://github.com/unit-mesh/auto-dev
Documentation: https://vscode.unitmesh.cc/
Contributing Documentation: https://vscode.unitmesh.cc/development
If you are interested in AutoDev, you can join our WeChat group by scanning the QR code above.
๏ผๅฆๆ็พคไบ็ปด็ ่ฟๆ๏ผๅฏไปฅๆทปๅ ๆ็ๅพฎไฟกๅท๏ผphodal02๏ผๆณจๆ AutoDev๏ผๆๆไฝ ๅ
ฅ็พค๏ผ
Normal features
| Feature | VSCode Status | IDEA Status |
|---|---|---|
| Chat mode | โ | โ |
| Code completion | โ | โ |
| AutoDoc | โ | โ |
| Custom Prompt | โ | โ |
| Prompt Overwrite | โ | โ |
| Commit Message | โ | โ |
| Gen API Data | โ | โ |
| AutoTest | โ | โ |
| Refactoring: Rename | โ | โ |
| Refactoring: fix | โ | โ |
| Refactoring: with Lint | โ | โ |
| CLI Suggest | โ | โ |
Natural Language search features
| Feature | VSCode Status | IDEA Status |
|---|---|---|
| Custom RAG | โ | โ |
| NL Semantic Search | โ | โ |
| Multiple RAG Strategy | โ | โ |
DevOps features
| Feature | VSCode Status | IDEA Status |
|---|---|---|
| Dockerfile | โ | โ |
| CI/CD | โ | โ |
AI Agent features
| Feature | VSCode Status | IDEA Status |
|---|---|---|
| AI Agent: DevIns Lang | โ | โ |
| AI Agent: Custom Agent | โ | โ |
| AI Agent: AutoCRUD | โ | โ |
| AI Agent: AutoArkUI | โ | โ |
| AI Agent: AutoSQL | โ | โ |
| AI Agent: AutoPage | โ | โ |
Inspired and based on๏ผ
AutoDev VSCode is licensed under the Apache 2.0 license as defined in LICENSE.