Agents in VS Code¶
An agent normally works in its own space: its files live in its own workspace, and anything it runs happens there. That is the right arrangement for an agent doing work on your behalf, and the wrong one for an agent helping you write software — the code you care about is on your machine, in your checkout, with your dependencies already installed.
With the VerinFast extension for VS Code, you can connect a Kwirker agent to the folder you have open, so its file and command tools act on your code instead of its own workspace.
Turning on Editor access¶
An organization owner or admin opens the agent, goes to Settings → Main, and turns on Editor access. You'll be asked to confirm, and to sign in again if you haven't recently.
Nothing else lets an agent reach outside its own workspace. The switch is the consent step, and it is enforced by Kwirker, not by the editor: an editor offering its workspace to an agent without Editor access is refused. Turning it off takes effect immediately — including for a reply that is already in progress.
Editor access doesn't change what the agent does anywhere else. In the web app, on your phone, in a routine, it works exactly as before.
Connecting from VS Code¶
Install the VerinFast extension, then:
- VerinFast: Sign In — enter the address you open Kwirker at, then either sign in with your browser (your usual sign-in, including your organization's identity provider) or paste a personal API key for a remote or headless setup. The credential is kept in VS Code's secret storage, never in a settings file.
- VerinFast: Select Organization.
- VerinFast: Select Agent — only agents with Editor access are listed.
- VerinFast: Open Chat (
Ctrl/Cmd+Shift+D).
The organization and agent are remembered per folder, so different projects can use different agents.
What changes while you're connected¶
For each message you send from VS Code, six of the agent's tools are answered by your editor:
| Tool | Where it acts |
|---|---|
read_file, list_files, search_files |
Your open folder |
write_file, edit_file |
Your open folder, after you review a diff |
run |
Your checkout, after you approve the command |
Everything else is unchanged: the agent's memory, skills, routines, integrations and web search work as they do anywhere else. Conversations started from VS Code appear in the agent's history like any other.
What you approve¶
The agent runs on Kwirker; the consequences land on your machine. So the editor asks before anything changes:
- File changes are shown as a diff before they are written, and applied through VS Code's own edit system, so they sit on the normal undo stack. If you save your own change while the diff is open, the agent's edit is abandoned rather than overwriting yours.
- Commands run directly, not through a shell. The command is split into a
program and its arguments and exactly that is started — the program found on
your PATH, never one sitting in the folder. Out of the box only
git statusandgit logrun without asking; anything else is shown to you first, with the program it will run, and you can approve it once or allow it (for examplenpm test) from then on. - A command that needs a shell is always shown to you. A pipe, a redirect,
&&, a$VARor a*glob only works through a shell, so such a command runs through one — but only after you've read it and said yes. It is never approved automatically and can't be saved as an allowed command. On Windows this includes batch-file programs such asnpm(npm.cmd). - Denied commands always win. A command that starts with a denied entry, such
as
git push --force, is refused even if you'd approve it. - File paths can't leave the folder you have open — symbolic links included —
and
.gitis always off limits. - These rules are yours, not the repository's. The allowed and denied
commands, the edit mode and the Kwirker address are read from your user
settings only; a
.vscode/settings.jsonchecked into a repository can't change them. - An allowed command trusts its program. Allowing
npm testallows whatever the project's test script does. Prefer specific entries. - Files the agent sends are virus-scanned before they reach your editor.
If you decline something, the agent is told you declined — not that the tool failed — and is instructed to ask rather than try again. In a read-only conversation the agent can read and search your folder, but not change it or run anything.
Stopping, and when the editor goes away¶
Stop stops the agent's work, and anything still waiting for your approval is abandoned — saying yes afterwards changes nothing.
If you close the laptop, lose the network, or leave an approval sitting, the agent waits a few minutes and is then told the editor didn't answer. It costs that reply, not the conversation: pick it up again when you're back.