DebugAI 2.12: indexing works again, and it sends less from your machine
Index Entire Workspace found no files from 2.10.0 to 2.11.0. 2.12 fixes it, stops sending git context, and sends no code from .env or credential files.
DebugAI 2.12: indexing works again, and it sends less from your machine

This release started as an audit. We read what the extension actually sends, compared it with what our README and privacy page said, and found three things we got wrong. 2.12 fixes them. It ships with a new engine, which has been answering since 10 October.
What was wrong
Index Entire Workspace stored nothing, from 2.10.0 to 2.11.0. The pattern that picks which files to index nested one group of braces inside another. VS Code's file search cannot use that pattern, so the startup index and the Index command found no files. Files still reached the index one at a time, as you opened or saved them, which is why it took us this long to see it. The pattern is flat now, and Index Entire Workspace indexes your project again.

Every debug in a git repository sent git context, and nothing read it. Up to 2.11.0, a debug in a git repository carried your branch name, up to 20 changed file paths, three counts and up to 3,000 characters of git diff. Our privacy page said diff text is never sent. Our API never read any of it. 2.12 does not collect it or send it.
A focused .env could go out with a debug. A debug sends the code around your cursor in whichever file is focused. If that file was a .env, its lines were sent as they stood.
What 2.12 changes
Less leaves your machine.
- No git context with a debug: no diff, no branch name, no changed paths.
- No code from an environment file, a key or certificate file, or a credential file (
.npmrc,.netrc,.git-credentials, anything under.sshor.aws), and none from a window that holds a private key. The error text still goes, so the debug still works, and the status bar says what was held back. - A source file that is only named like a secret still sends its code (
credentials.ts,Password.tsx,secrets.py), and so does.env.example. - The MCP servers read no local files when their project root would be your home directory, a folder above it or the filesystem root. The reply says so, and asks the agent for a
projectRoot.

This is a real run from our release check, with that .env focused. The answer still came back, and it never mentions PLATYPUS_CAP or its value. The file it says has not been shared is src/flags.js, which the pasted error named and the test project does not have.

You control automatic indexing. Indexing at startup and on every open or save now has a setting, debugai.autoIndex, and the first automatic index tells you what it sends. The Index commands and the scan work either way.
A fix lands in the file it is for. When the fix belongs to a different file from the one the error named, Apply opens the diff against that file.
The engine. Claude Haiku 5.5 now answers what Haiku 4.5 did: every Free-plan debug, and simple errors on any plan. On paid plans, Sonnet 4.6 still answers errors the router rates complex, debugs where your index supplies project files, and errors of a less common type. GPT-4o-mini still answers when Claude cannot.
How we measured
Before an engine change ships, we run it on our own eval corpus: 12 bugs from our own history, each with a hidden check that decides whether the applied fix worked. Attempts are spaced so that none sees another.
- The score: the new engine fixed 7 of the 12 with both versions of our MCP server. The old one fixed 8 with MCP 2.6.0 and 7 with 2.7.0.
- Consistency: on the new engine, each bug got the same verdict on all four of its attempts.
- What changed: one bug the old engine missed now passes. One it fixed now fails: the answer says the fix needs an
import json, but its edit leaves the import out. We are fixing that one next. - Who answered: our benchmark account is on a paid plan, so Sonnet 4.6 answered 7 of the 12 and Haiku 5.5 answered 5. We have not yet measured a Free-plan account, where Haiku 5.5 answers every debug.
Update
- VS Code: updates on its own. To do it now: Extensions, DebugAI, Update. The version should read 2.12.0.
- Cursor, Windsurf, VSCodium: the same, from Open VSX.
- AI agents (Claude Code, Cursor agent mode):
npx -y @debugai/mcp setupsigns you in and sets up each agent client it finds to run the latest@debugai/mcp(2.7.0).
Everything that changed is in the changelog ↗. What a debug, an index and a scan send, and where it goes, is on the privacy page ↗.
If an answer is wrong, the thumbs-down in the result panel reaches us, and so does the support page ↗.
Debug faster starting today.
Free VS Code extension · 10 sessions/day · no credit card