5.5
GitHub Copilot Chat
💻 VS Code ExtensionGitHub
AI chat features powered by Copilot
74,689,024 usersRating: 3.127329192546584/5v0.48.1Updated 2026-05-15T22:33:59.763Z
Medium Risk5.5/10
Scanned June 2, 2026
Risk Flags
Shares data with external services: External HTTP endpoints, Anthropic API
Some data is transmitted without HTTPS encryption
Policy concern: extension makes network requests but no privacy documentation found
No privacy policy found, despite requesting multiple permissions
5.7
Permissions
9.5
Developer
4.5
Data Privacy
2.0
Policy Match
Permissions (9)
Starts automatically when VS Code opens
activation:onStartupFinished
Can be activated by external URIs
activation:onUri
Activates when accessing files
activation:onFileSystem:ccreq
Activates when accessing files
activation:onFileSystem:ccsettings
Provides terminal profiles — can execute commands
contributes:terminal
Extends TypeScript language server
contributes:typescriptServerPlugins
Registers 137 commands — very large surface area
commands:extensive
Runs an HTTP server inside VS Code
dep:express
Sends data to Anthropic API
dep:@anthropic-ai/sdk
Developer
NameGitHub
Verified PublisherYes
Known EntityRecognized
Data Flows
External HTTP endpoints3rd party
Encryptedoutbound requests
Anthropic API3rd party
Encryptedcode context, prompts
Local HTTP server
Unencryptedaccepts connections
Privacy Policy Analysis
Policy Status
No policy found
Actual Data Collection
- outbound requests
- code context
- prompts
- accepts connections
Policy Mismatches Found
- Extension makes network requests but no privacy documentation found
Alternatives to Consider
Know what your tools are really doing.