DEV Community

Cover image for Iam 12 . My web mentor KODA Is Now in Your Editor. Here Is How I Built a Cursor-Killer Extension on a $150 Phone.
Harun - solo dev
Harun - solo dev

Posted on

Iam 12 . My web mentor KODA Is Now in Your Editor. Here Is How I Built a Cursor-Killer Extension on a $150 Phone.

I am 12 years old.
My development machine is a POCO C55 ($150 USD).
I live in Tamil Nadu, India.

For months, KODA lived on the web. It taught beginners how to code using the "Problem → Cause → Solution → Practice" method. It spoke every language on Earth. It survived model deprecations with a fallback chain. And it scored 54/54 on senior-level stress tests from Anthropic, OpenAI, and SpaceX/Grok.

But developers don’t live on websites. They live in their editors.

So today, I’m expanding KODA. Not launching a new product. Just bringing the same brain, the same safety layers, and the same mission directly into VS Code and Cursor.

This is KODA v0.1.0 for IDEs. Built entirely on a phone. No TypeScript. No bundler. No node_modules. Just three vanilla JavaScript files totaling ~45KB.

⚡ WHY THIS MATTERS

Most AI coding tools fall into two traps:

  1. Autocomplete Bots (Copilot): They predict your next token. Fast, but shallow. You copy-paste code you don’t understand. Technical debt explodes.
  2. Chat Wrappers (Cursor/Web Apps): They explain well, but force you to switch tabs. Friction kills flow.

KODA bridges this gap. It doesn’t just predict or chat. It acts. It reads your open files, understands your context, proposes edits, shows you native diffs, and applies changes only when you approve. All while explaining why it made those changes.

And because it’s the same KODA platform, it inherits everything that made the web version robust:

  • Constitutional AI Safety: Hardcoded 200ms budget. If a suggestion violates truthfulness or harmlessness principles, it self-corrects before hitting your editor.
  • Unlimited Language Support: Type in Tamil, Hindi, Spanish, Japanese. KODA replies fluently in your language. Code stays in English.
  • Live Web Search: Toggle search to pull real-time docs for React, Vue, Rust, etc., with clickable citations [1], [2].
  • Fallback Chain Resilience: If Groq’s primary model fails, KODA automatically retries with secondary models. You never see an error.

🛠️ THE ARCHITECTURE: ZERO BUILD STEPS

Building a VS Code extension usually requires a complex pipeline: TypeScript compilation, Webpack bundling, dependency management. On a phone, that’s impossible. So I stripped it down to the bare metal.

Total Footprint:

  • extension.js: ~13KB (Vanilla JS logic)
  • media/chat.html: ~30KB (UI, CSS, Markdown Renderer)
  • package.json: ~2KB (Manifest)
  • icon.svg: ~1KB

No dependencies. No build step. VS Code loads these files directly. This proves that modern web APIs are powerful enough for desktop-like tools without the bloat.

How It Works: The Agentic Loop

When you highlight code and press Ctrl+Alt+I (Cmd+Alt+I on Mac), here is the journey:

  1. Context Gathering (The Eyes):
    The extension reads your active file, your selection, and up to 6 open tabs (capped at 20KB each to save tokens). It packages this into a clean JSON object.

  2. Secure Transmission (The Bridge):
    This data is sent via HTTPS POST to my Cloudflare Worker. No keys are stored locally. The Worker handles CORS, authentication, and routing.

  3. Intelligent Processing (The Brain):
    Inside the Worker:

    • Injection Defense: Your prompt passes through a 1µs regex filter to block malicious inputs.
    • MoE Routing: The request is routed to the best expert model (Python, React, Rust, etc.) using cosine similarity.
    • Fallback Chain: If Groq’s primary model (gpt-oss-120b) fails, it automatically retries with gpt-oss-20b, then qwen3. You never see an error.
    • Constitutional Safety: The response is checked against a 200ms budget for truthfulness and harmlessness. If it violates principles, it self-corrects before sending back.
  4. Execution (The Hands):
    The Worker returns a structured response containing:

    • The explanation text.
    • A special code block marked with path=filename.js.

    Back in VS Code, the extension parses this marker. It opens VS Code’s native diff editor (vscode.diff), showing you exactly what will change.

    You click Apply. The extension uses vscode.workspace.applyEdit to update your file instantly. Done.

🛡️ SECURITY FIRST: HARDENING THE AGENT

Giving AI write access to your filesystem is dangerous. So I hardened it like a bank vault.

  • Strict CSP: The webview runs with a nonce-based Content Security Policy. No inline scripts unless nonced. No external requests except highlight.js.
  • XSS Protection: Every user-sourced string goes through escapeHtml(). File paths, message content, mention labels—all sanitized.
  • Sandboxed Access: The extension reads files only through vscode.workspace.openTextDocument, respecting workspace boundaries. It cannot touch files outside your project.
  • Confirmation Gates: Selection edits apply immediately (low risk). Full-file edits always show a diff first and require explicit confirmation.

📊 THE BENCHMARKS: STILL TRUE

Don’t let the UI distract you. The engine underneath hasn’t changed. According to my Master Performance Document, KODA still holds:

  • Prompt Injection Defense: ~1 microsecond execution. Four-layer regex. Faster than your blink.
  • Constitutional AI Safety: Hardcoded 200ms budget. No infinite loops. No resource drain.
  • Telemetry Processing: 1,000 packets in <50ms using six-sigma anomaly detection.

Claude (Anthropic) reviewed this architecture last month and said: "This is genuinely impressive. Not impressive for a thirteen-year-old. Just impressive, period."

He respected the engineering because the engineering was real.

👑 TRY IT YOURSELF

Download v0.1.0 from GitHub: github.com/harun-sket/Koda-cursor

(Note: Microsoft Marketplace requires users to be 13+. We distribute via GitHub Releases for now.)

  1. Download the .vsix file.
  2. Open VS Code / Cursor.
  3. Press Ctrl+Shift+P → "Extensions: Install from VSIX...".
  4. Choose the downloaded file. Restart.
  5. Click the Tiger Icon 🐯 in the Activity Bar.
  6. Highlight some messy code. Press Ctrl+Alt+I. Type: "Refactor this for readability and explain why."

Watch KODA rewrite it. Watch it teach you.

Age doesn’t matter. Device doesn’t matter. Location doesn’t matter.

Execution matters. 🐯

Top comments (0)