Developer Tools
Cortex Developer Tools
Bring project-aware assistance, security workflows and reviewed changes into your editor.
Cortex Developer Tools bring coding assistance and security analysis into Visual Studio Code, Visual Studio and JetBrains IntelliJ IDEA. Code remains the center of the experience: questions, findings and proposed changes can be reviewed alongside the project you are developing.
Get started
Section titled “Get started”Install the extension for your editor, open a project and sign in. Follow the guide for VS Code, Visual Studio or JetBrains for the available interface and setup.
Coding assistance in context
Section titled “Coding assistance in context”Cortex helps explain unfamiliar code, investigate a defect and develop a proposed solution using selected project context. In VS Code, editor selection actions provide dedicated entry points for explanation, fixes, tests, review and documentation. Notebook selections and related repository context also have published commands in the VS Code client.
Conversations support follow-up questions, so a code explanation can become a change request or a security investigation without re-entering the original objective. Saved chats help organize separate pieces of work.
Security where the code is
Section titled “Security where the code is”Security scans connect findings to affected files and lines. The result can include an explanation and a suggested remediation, with a diff to inspect before applying changes. VS Code exposes separate views for file scans, repository scans and SCA results, plus finding actions for explanation, remediation and verification.
This places investigation close to implementation. For broader project reporting, dependency analysis and risk progression, the DevSecOps console provides the corresponding product views.
Review, validation and delivery
Section titled “Review, validation and delivery”The VS Code client includes commands to review, keep or undo Cortex changes, inspect command output, and start security reviews against the working tree or a base branch. Published pull-request actions connect reviewed work to the integrated browser. Evidence workspaces and governed workflow recipes provide entry points for tasks that require supporting sources or multiple steps.
See change review, security commands and pull-request workflows for the exact actions.
Editor support
Section titled “Editor support”| Client | Product experience |
|---|---|
| Visual Studio Code | Chat, published editor actions, scan views, change review, customizations and workflow commands |
| Visual Studio | Cortex tool window, coding conversations, active-file scans and review of suggested fixes |
| JetBrains IntelliJ IDEA | Cortex tool window and the project-context features exposed by the installed plug-in |
The clients have different command sets. Use the documentation for your editor when checking a particular capability; the VS Code command reference describes the VS Code extension.
A complete development loop
Section titled “A complete development loop”Developer Tools are designed for more than generating a snippet. A useful loop begins with understanding the relevant code and requirement, proceeds through a focused change, and ends with tests, security review and inspection of the diff. Workspace context can connect a visible function to related files, so a repository-level investigation need not rely on a pasted selection alone.
For example, ask Cortex to explain a failing behavior, identify the affected files, propose a bounded fix and add regression coverage. Review the patch and validation results before deciding to keep it. A test failure or missing dependency is useful diagnostic information, not a reason to assume the change succeeded.
Design review and security review
Section titled “Design review and security review”AI Threat Model and AI Security Review address different questions. Threat modeling explores assets, entry points, trust boundaries and plausible misuse before or during design. Security review examines implementation details such as authorization, input validation, injection, secret handling, insecure defaults and error behavior.
In clients that expose these workflows, use a threat model when choosing an approach and a security review when evaluating the resulting code. A scan can identify likely issues; a suggested fix and its verification are additional steps, not interchangeable outputs.
Carry engineering preferences into the work
Section titled “Carry engineering preferences into the work”Supported Style Profile settings describe preferences for documentation, comments, names, types, error handling, function size and tests. Test Design Specification helps select acceptance conditions and checks that expose the relevant failure. Together they make it easier to ask for code that fits the project and evidence that demonstrates the intended behavior.
Saved conversations, collections and chat forks in supported clients separate investigation from alternative solutions. A fork preserves the original discussion; a reviewed implementation remains subject to workspace approvals. Consult the editor-specific guide rather than assuming every IDE has the same controls.
Start elsewhere, review in the project
Section titled “Start elsewhere, review in the project”With Cortex Connect, a request started on a browser or mobile client can reach an available connected VS Code workspace. The development environment supplies the source and permitted tools; the other client supplies access to the objective, progress and review. This is intent handoff, not a shared desktop.
Choose a connected local workspace for tasks that need its tools or working files. Choose Cortex Cloud for eligible managed execution. In either case, review remains tied to the project and result rather than only to a chat summary.
Product background
Section titled “Product background”- Project-aware security review and threat modeling
- Connected execution with Cortex Connect
- Developer workflow continuity and reviewed changes
Connected services and access
Section titled “Connected services and access”Eligible sessions can use approved MCP connectors and continue supported work through Cortex Connect. Workspace access and available actions depend on the installed extension, account and organization policy. Review proposed file changes and commands before approval.

