Documentation
Install the extension, run your first scan, and understand what you are looking at.
Three things, in order: install the extension, let it fetch the scanning engine, and run a scan. Signing in is optional and comes later.
Install Vulnetix from Open VSX, then follow the installation guide.
If you use something other than VS Code itself, go to your editor first. Cursor, Windsurf, VSCodium and the rest install from a different marketplace, and the steps differ enough to be worth their own page.