Skip to content

Developer Tools

Cortex Developer Tools

Bring project-aware assistance, security workflows and reviewed changes into your editor.

Cortex Developer Tools bring coding assistance and security analysis into Visual Studio Code, Visual Studio and JetBrains IntelliJ IDEA. Code remains the center of the experience: questions, findings and proposed changes can be reviewed alongside the project you are developing.

Install the extension for your editor, open a project and sign in. Follow the guide for VS Code, Visual Studio or JetBrains for the available interface and setup.

Cortex helps explain unfamiliar code, investigate a defect and develop a proposed solution using selected project context. In VS Code, editor selection actions provide dedicated entry points for explanation, fixes, tests, review and documentation. Notebook selections and related repository context also have published commands in the VS Code client.

Conversations support follow-up questions, so a code explanation can become a change request or a security investigation without re-entering the original objective. Saved chats help organize separate pieces of work.

Security scans connect findings to affected files and lines. The result can include an explanation and a suggested remediation, with a diff to inspect before applying changes. VS Code exposes separate views for file scans, repository scans and SCA results, plus finding actions for explanation, remediation and verification.

This places investigation close to implementation. For broader project reporting, dependency analysis and risk progression, the DevSecOps console provides the corresponding product views.

The VS Code client includes commands to review, keep or undo Cortex changes, inspect command output, and start security reviews against the working tree or a base branch. Published pull-request actions connect reviewed work to the integrated browser. Evidence workspaces and governed workflow recipes provide entry points for tasks that require supporting sources or multiple steps.

See change review, security commands and pull-request workflows for the exact actions.

Client Product experience
Visual Studio Code Chat, published editor actions, scan views, change review, customizations and workflow commands
Visual Studio Cortex tool window, coding conversations, active-file scans and review of suggested fixes
JetBrains IntelliJ IDEA Cortex tool window and the project-context features exposed by the installed plug-in

The clients have different command sets. Use the documentation for your editor when checking a particular capability; the VS Code command reference describes the VS Code extension.

Developer Tools are designed for more than generating a snippet. A useful loop begins with understanding the relevant code and requirement, proceeds through a focused change, and ends with tests, security review and inspection of the diff. Workspace context can connect a visible function to related files, so a repository-level investigation need not rely on a pasted selection alone.

For example, ask Cortex to explain a failing behavior, identify the affected files, propose a bounded fix and add regression coverage. Review the patch and validation results before deciding to keep it. A test failure or missing dependency is useful diagnostic information, not a reason to assume the change succeeded.

AI Threat Model and AI Security Review address different questions. Threat modeling explores assets, entry points, trust boundaries and plausible misuse before or during design. Security review examines implementation details such as authorization, input validation, injection, secret handling, insecure defaults and error behavior.

In clients that expose these workflows, use a threat model when choosing an approach and a security review when evaluating the resulting code. A scan can identify likely issues; a suggested fix and its verification are additional steps, not interchangeable outputs.

Carry engineering preferences into the work

Section titled “Carry engineering preferences into the work”

Supported Style Profile settings describe preferences for documentation, comments, names, types, error handling, function size and tests. Test Design Specification helps select acceptance conditions and checks that expose the relevant failure. Together they make it easier to ask for code that fits the project and evidence that demonstrates the intended behavior.

Saved conversations, collections and chat forks in supported clients separate investigation from alternative solutions. A fork preserves the original discussion; a reviewed implementation remains subject to workspace approvals. Consult the editor-specific guide rather than assuming every IDE has the same controls.

With Cortex Connect, a request started on a browser or mobile client can reach an available connected VS Code workspace. The development environment supplies the source and permitted tools; the other client supplies access to the objective, progress and review. This is intent handoff, not a shared desktop.

Choose a connected local workspace for tasks that need its tools or working files. Choose Cortex Cloud for eligible managed execution. In either case, review remains tied to the project and result rather than only to a chat summary.

Eligible sessions can use approved MCP connectors and continue supported work through Cortex Connect. Workspace access and available actions depend on the installed extension, account and organization policy. Review proposed file changes and commands before approval.