securient
IDEViewer is an open-source, cross-platform security tool that continuously monitors developer workstations for supply chain threats originating from IDE extensions, software dependencies, plaintext secrets, and AI development tools.
Developer IDEs have become a high-value attack surface. Malicious or over-permissioned VS Code extensions can execute arbitrary code, exfiltrate secrets, and establish persistence. npm lifecycle hooks in dependencies run silently during install. AI coding assistants like Claude Code, Cursor, and MCP servers introduce new data exfiltration vectors through unchecked permissions and network access. IDEViewer addresses this blind spot by scanning extensions across 7+ IDEs, analyzing their permissions against a risk model, detecting plaintext secrets, inventorying all installed packages (including those bundled inside extensions), monitoring for git hook bypasses, and detecting AI tool configurations with their associated permissions.
securient
Staff Security Engineer at Piplabs
Vinod is a Staff Security Engineer at PIP Labs and IEEE Senior Member with over a decade of cybersecurity experience spanning financial services, government, and tech. His career across Amazon, Zapier, and HackerOne has built deep expertise in penetration testing, cloud security architecture, and application security across AWS, GCP, and Azure — now applied at the intersection of traditional enterprise security and Web3/blockchain infrastructure. He is an author and reviewer for the HTTP Archive's Web Almanac, organizer of the Blockchain Security Village at Seasides, and creator of the open-source API Doc Converter Burp Extension. He actively contributes to the security community through writing on Medium, bug bounty programs, and mentoring aspiring security professionals.