Visual Studio Code is a code editor that supports editing, navigating, understanding, debugging, and extending software projects. Developers use it for the edit-build-debug cycle, and the catalogue add-ons provide skills, instructions, and agents for working within the editor.
Borrowing it
Nothing to install: this file belongs to microsoft/vscode. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/microsoft/vscode/main/.github/prompts/component.prompt.mdgit clone --depth 1 https://github.com/microsoft/vscodeWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/microsoft/vscode/component)<a href="https://agentmods.dev/commands/microsoft/vscode/component"><img src="https://agentmods.dev/badge/commands/microsoft/vscode/component.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00009 | $0.00543 |
| Opus 5 | $0.00005 | $0.00271 |
| Sonnet 5 | $0.00002 | $0.00109 |
| Haiku 4.5 | $0.00001 | $0.00054 |
Grade A, and why
component scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 59 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Location: src/vs/[path/to/component]
Type: [Service/Contribution/Extension/API/etc.]
Layer (if applicable): [base/platform/editor/workbench/code/server]
Purpose
Brief description of what this component does and why it exists.
Scope
- What functionality is included
- What is explicitly out of scope
- Integration points with other components
Architecture
High-Level Design
[Architectural diagram or description of key patterns used]
Key Classes & Interfaces
- [ClassName]: Brief description of responsibility
- [InterfaceName]: Purpose and main methods
- [ServiceName]: Service responsibilities
Key Files
List all the key files and a brief description of their purpose:
src/vs/[path/to/component]/[filename.ts]: [Purpose and main exports]src/vs/[path/to/component]/[service.ts]: [Service implementation details]src/vs/[path/to/component]/[contribution.ts]: [Workbench contributions]
Development Guidelines
- Reserve a section for any specific development practices or patterns relevant to this component. These will be edited by a developer or agent as needed.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 59 lines · 9 tokens per session scan A e3a84dd74499
component is a command published in the GitHub repository microsoft/vscode (191,195 stars, last pushed today), licensed MIT. It adds 9 tokens to every session and 543 once invoked, about $0.0000 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-06.
Other commands, from other repositories
plugin-commands
:::info This document covers all build, test, and smoke commands for eIsland native plugins. Each plugin lives under plugins/ and has its own package.json with independent scripts. ::.
esa-commands
:::info This document covers the ESA (Edge Security Acceleration) CDN cache purge commands for clearing cached content on Alibaba Cloud ESA. These commands use the official @alicloud/esa20240910 SDK. ::.
release-commands
:::info This document covers the release and changelog commands for publishing eIsland builds and generating release notes. For packaging the installer locally, see Package Commands. ::.
package-commands
:::info This document covers the packaging and lifecycle commands for building distributable installers and managing native modules. For development commands (dev, build, preview), see Development Commands. ::.
quality-commands
:::info This document covers the code quality commands for validating comment standards and i18n completeness in the eIsland frontend. ::.
dev-commands
:::info This document covers the core development commands for building, running, and previewing the eIsland application. For environment setup and prerequisites, see Frontend Setup. ::.