Skip to content
Hacker News front page

Implant gives coding agents live access to VS Code APIs via an MCP tool

Implant – an extension to VS Code that exposes its APIs to coding agents

Pavel Mikhailovskii released a VS Code extension that exposes the editor's internal APIs to coding agents like Copilot Chat, Claude Code, and Cursor. It provides a single MCP tool, run_vscode_script, which executes JavaScript snippets inside the extension host; every invocation opens a webview for user approval. On install it writes five config files (.mcp.json, .cursor/rules, etc.) so agents can directly use language services such as Find References, Rename, and quick-fixes. The HTTP server binds only to 127.0.0.1 and regenerates a per-session bearer token stored in a gitignored session.yml, but the author warns against running it on shared machines since any process under the same user can read the token file.

Why it matters: Direct idea, concrete mechanism, natural appeal for AI coding tool users. Deduction because the security model is unclear—running arbitrary JS in the extension host with no spelled-out permission boundaries or safeguards keeps this in experimental territory for now.

Read the original ↗Export Markdown