Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Aqiron Security’s design puts VS Code integration in the extension and security operations in a separate TypeScript/Node.js process, linked by newline-delimited JSON over standard input and output. The split gives the project a defined boundary between editor-facing code and its security runtime—but it also creates protocol and lifecycle work that a small extension may not need.

What Aqiron separates—and what it does not

In Aqiron Security’s account, the extension is the client for the developer environment. It handles activation, commands, diagnostics, webviews and settings interactions, editor state, and workspace-facing UI. A client or process manager starts the core, which performs scanner orchestration, output parsing, finding normalization and correlation, project analysis, reporting, and AI-related operations. The author summarizes the division this way: “The VS Code extension owns the developer environment. The core owns security operations. The protocol connects them.” Aqiron Security’s architecture article

This is a project-level boundary, not a replacement for VS Code’s extension host. Microsoft documents that extensions use the extension API and run in a separate extension-host process; Aqiron describes adding another process boundary for its own core. Microsoft’s Source Code Organization documentation

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How the process boundary works

The two processes communicate through newline-delimited JSON (NDJSON) on standard input and output. Each message occupies a line, giving the client and core a simple framing rule for exchanging serialized messages. Aqiron describes request and response messages associated by IDs, event messages for asynchronous updates, a versioned compatibility handshake, and explicit cancellation operations. Aqiron Security’s architecture article

That makes the IPC channel more than a transport detail: it is an API contract between two separately running parts of the application. The sides need to agree on message shapes, request identity, protocol compatibility, which side owns or emits events, how cancellation is represented, and how failures are reported. If either side changes those expectations without coordination, the other may not interpret its messages correctly.

Why request IDs, events, and cancellation matter

  • Request IDs let the client match a response to the operation that initiated it, including when work overlaps.
  • Events provide a way to report asynchronous progress or pipeline updates without making every update a final response.
  • Cancellation gives the client an explicit way to ask the core to stop work that is no longer needed.
  • Version negotiation makes compatibility an explicit startup concern rather than an assumption about matching message formats.

Why put security operations in a core?

Keep domain logic independent of VS Code APIs

A security engine can reason about workspaces, scans, findings, projects, and reports without importing editor-specific objects such as VS Code workspace APIs, webview panels, text documents, or diagnostic collections. The extension translates between those editor concepts and the core’s domain concepts. That direction can make the security logic easier to isolate from the UI layer, while keeping editor-specific interaction where it belongs.

Rank #2
TypeScript Programming Language - Software Engineer & Coder T-Shirt
  • TypeScript implements a superset of syntax for strictly typed development, facilitating deep static analysis and enhanced development environment integration. The compiler translates source into standard script formats, ensuring parity across any runtime.
  • TypeScript is ideal for front-end developers, full-stack engineers, and software architects who build large-scale web applications. It serves those looking to improve code excellence, reduce bugs through static checking, and maintain complex projects more.
  • Lightweight, Classic fit, Double-needle sleeve and bottom hem

Give long-running work an explicit lifecycle

Finding files, running scanners, parsing and normalizing results, correlating findings, and generating reports can form a multi-stage workflow. Treating the engine as a service makes its startup, cancellation, failure, and restart behavior visible architectural decisions. It does not make those concerns disappear; it gives the project a distinct place to manage them.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Make the integration contract concrete

Without a process boundary, code can call across module boundaries directly. With IPC, the project must represent requests, responses, events, versions, and errors as data. That discipline can help clarify what the core offers and what the extension expects, particularly as the project grows. It is useful only if the team is prepared to maintain that contract.

How scanner output becomes a common finding

Scanners can report equivalent facts using different field names or formats—for example, severity, file path, and line number. Aqiron describes parsing scanner-specific output into a shared finding model, then correlating and reporting those findings. Downstream features can therefore work with the common model instead of each scanner’s native schema. Aqiron Security’s architecture article; Aqiron Security’s Flutter workbench article

  1. Run a scanner and receive its native output.
  2. Parse that output using scanner-specific handling.
  3. Normalize the parsed result into the shared finding model.
  4. Correlate findings and use the normalized data for analysis or reporting.

This is a boundary within the security core as well as between the core and extension: scanner-specific differences are handled before the rest of the application consumes findings.

What the split costs

A separate runtime adds operational responsibilities that an in-process module boundary does not. The project must handle process startup and restart, malformed input, disciplined separation of protocol output from diagnostic logging, partial failures, cancellation, shutdown, concurrent requests, and serialization overhead. These are engineering costs, not evidence that the architecture is inherently too complex or too slow.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Startup and restart: define what happens if the core cannot launch or exits while work is underway.
  • Protocol and compatibility: keep both sides aligned on message formats and version expectations.
  • Logging and malformed messages: preserve a readable failure trail without confusing logs with protocol data, and decide how invalid input is handled.
  • Partial failure and cancellation: define what the client sees if one stage fails or work is cancelled after it has begun.
  • Concurrency and shutdown: determine how overlapping requests and process termination affect outstanding operations.
  • Serialization: account for the cost and constraints of converting data to and from messages.

When a separate core is worth considering

The choice depends on the workload, boundary discipline, and product direction—not on a universal rule that extensions should or should not spawn a process.

Question A separate core is more compelling when… A single extension runtime may be enough when…
Dependency direction Security logic should operate without importing VS Code APIs, and the extension can translate between editor and domain concepts. The logic is small and tightly tied to editor interactions.
Workload and lifecycle Long-running operations benefit from explicit startup, cancellation, failure, and restart handling. Commands are brief and do not need an independently managed runtime.
Contract discipline Explicit request, response, event, version, and error shapes are useful to the team. The additional protocol is more maintenance than the separation is worth.
Operational capacity The project can own logging, malformed messages, partial failures, shutdown, concurrent requests, and serialization. The team cannot justify maintaining those process and protocol concerns.
Distribution plans Multiple real clients may eventually need a shared core, and coordinated releases are justified. A private bundled core meets the project’s current needs.

Aqiron’s author describes the boundary as potentially excessive for a small, command-based extension, and more compelling for a growing security platform with multiple subsystems and long-running work. That is the project author’s judgment about this design, not a general VS Code recommendation. Aqiron Security’s architecture article

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What Aqiron’s current implementation does—and does not—show

Aqiron’s September 23, 2026 article describes the project as version 0.0.1 and under active development. It says packages/core is private and bundled into the extension, rather than published independently. Workspace operations require a Flutter workspace; external scanners are optional; quick file scans use a separate direct extension path. The author says independent Core, CLI, and Desktop packages do not yet exist. The split is therefore an internal boundary in the described implementation, not evidence that multiple independently shipped clients already use the core. Aqiron Security’s architecture article

A separate project post describes native rules and optional integrations including Betterleaks, OSV-Scanner, Semgrep OSS, Trivy, and MobSF, and presents the workbench as focused on Flutter. Those are project-reported details; the post does not independently establish that every integration remains in the current implementation. Aqiron Security’s Flutter workbench article

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The architectural lesson

Aqiron’s example is useful as a case study in drawing a line between editor responsibilities and domain operations. The benefit is a clearer dependency and runtime boundary; the price is owning an IPC protocol and another process lifecycle. Whether that trade is worthwhile turns on the complexity of the security workflow, the value of isolation from VS Code APIs, and the team’s ability to maintain the boundary.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.