Agent skill

Oma Deepsec

by first-fluke in first-fluke/oh-my-agent

Set up and run Deepsec vulnerability scans, triage, and CI gates.

MITAuto-check: notesSecurity

Install Oma Deepsec

skills CLI
$ npx skills add first-fluke/oh-my-agent --skill oma-deepsec -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install first-fluke/oh-my-agent oma-deepsec --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/first-fluke/oh-my-agent.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/oma-deepsec .claude/skills/oma-deepsec && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
oma-deepsec
GitHub stars
1.3k
Token cost
~4.9k tokens
SKILL.md length
2,302 words
Files
8
Skills in repo
57
Repo updated
First seen
Licence
MIT

At a glance

Set up and run Deepsec vulnerability scans, triage, and CI gates.

  • Works in 5 steps: Confirm whether .deepsec/ already… → Resolve intent from the user prompt; if… → Estimate scale: count source files… → …
  • An explicitly requested agent-powered vulnerability scan
  • SKILL.md covers Scheduling, Structural Flow, Logical Operations and References
  • Calls bunx, vercel and bun; needs AI_GATEWAY_API_KEY and VERCEL_OIDC_TOKEN

What it does

Oma Deepsec is an agent skill from first-fluke/oh-my-agent. Set up and run Deepsec vulnerability scans, triage, and CI gates. Use for Deepsec work or an explicitly requested agent-powered vulnerability scan.

Its SKILL.md is about 4.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files (for example `resources/config.md`, `resources/decision-records.md` and `resources/matchers.md`).

It sits in Security, covering Vulnerability scanning. It works with Vercel. The repository describes itself as: Mechanical verification for AI coding agents — skills pack or full harness (stop-hook gates, artifact checks, independent judges). The licence is MIT.

When your agent uses it

  • An explicitly requested agent-powered vulnerability scan
  • Tasks that involve Vulnerability scanning

Example prompts

  • “/oma-deepsec”

Requirements

  • Node.js
  • A credential in AI_GATEWAY_API_KEY
  • A credential in VERCEL_OIDC_TOKEN

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Confirm whether .deepsec/ already exists; if yes, treat the run as incremental, never re-init.
  2. Resolve intent from the user prompt; if ambiguous (e.g. "scan this repo"), default to setup then scan (calibration mode).
  3. Estimate scale: count source files (rough rg --files | wc -l excluding node_modules, .git, dist) to forecast cost before any AI pass.
  4. Resolve the selected credential mode and backend. Check its required environment configuration or an existing claude / codex subscription…
  5. Resolve backend, scope, and spend from existing instructions and configuration under ../_shared/core/execution-policy.md. Before paid or…

What it can do on your machine

Read from SKILL.md and the folder at commit f65bbc0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • bunx
    • vercel
    • bun
    • pnpm
    • npx
    • rg
    • claude
    • codex

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • AI_GATEWAY_API_KEY
    • VERCEL_OIDC_TOKEN
    • ANTHROPIC_AUTH_TOKEN
    • VERCEL_TOKEN
    • OPENAI_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Oma Deepsec loads about 4.9k tokens when it runs. Until then it costs about 40 tokens; SKILL.md has 2,302 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~40
When it runs · the whole SKILL.md, loaded when a task matches
~4.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:92
    n for subscription mode. Do not require `.env.local` credentials for a valid subscription session. |
  • NoteMentions a .env fileSKILL.md:93
    h expiry). API key: regenerate. Confirm `.env.local` is in the cwd deepsec runs from. |
  • NoteMentions a .env fileSKILL.md:124
    # Edit .env.local: set AI_GATEWAY_API_KEY=vck_… (or VERCEL_OIDC_TOKEN via `vercel env pull`)
  • NoteMentions a .env fileSKILL.md:166
    `.deepsec/deepsec.config.ts`, `.deepsec/.env.local`, `.deepsec/matchers/`, `.deepsec/data/<id>/{project.json,INFO.md,co
  • NoteMentions a .env fileSKILL.md:182
    - Writes `.env.local` (never commit) and may run `vercel link` / `vercel env pull` (writes `.vercel/project.json` + toke
  • NoteMentions a .env fileSKILL.md:201
    `sk-ant-…`, `sk-…`, OIDC tokens). Treat `.env.local` as secret. Treat `data/` as gitignored by default.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from first-fluke/oh-my-agent at commit f65bbc0, republished under its MIT licence (© first-fluke). 2,302 words, ~4,860 tokens.

Download SKILL.mdSave it as .claude/skills/oma-deepsec/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
oma-deepsec
description
Set up and run Deepsec vulnerability scans, triage, and CI gates. Use for Deepsec work or an explicitly requested agent-powered vulnerability scan.

Deepsec: Agent-Powered Vulnerability Scanner Driver

Scheduling

Goal

Operate Vercel's deepsec security scanner inside a target repository safely and cost-consciously: bootstrap the .deepsec/ workspace, write a tight INFO.md, run the right scan/process/triage/revalidate/export sequence, gate PRs in CI via process --diff, and grow project-specific matchers, surfacing real, revalidated findings without runaway spend.

Intent signature
  • User mentions deepsec, "deep security scan", bunx deepsec, pnpm deepsec, npx deepsec.
  • User asks an agent to scan a repository for vulnerabilities, security issues, or CVEs and the project has (or should have) a .deepsec/ directory.
  • User asks how to add a deepsec PR / CI security gate, or about process --diff, --diff-staged, --diff-working, --files-from, --comment-out.
  • User mentions deepsec artefacts: INFO.md, SETUP.md, data/<id>/files/, FileRecord, RunMeta, revalidation, triage, custom matchers, MatcherPlugin, noiseTier, priorityPaths.
  • User asks about deepsec configuration: deepsec.config.ts, defaultAgent, AI_GATEWAY_API_KEY, VERCEL_OIDC_TOKEN, AI Gateway, Vercel Sandbox, --agent codex, --agent claude.
  • User asks how to lower deepsec cost, cut false-positive rate, or interpret severity / triage / revalidation verdicts.
When to use
  • First-time deepsec install in a repo (init, INFO.md write, first calibration scan).
  • Running a full or scoped scan and processing findings.
  • Setting up a per-PR CI gate with process --diff and --comment-out.
  • Writing a project-specific matcher to cover entry points the default set misses.
  • Triaging a backlog of findings (severity bucketing, FP cuts via revalidate, exporting to issue tracker).
  • Diagnosing deepsec failures: missing credentials, AI Gateway quota stops, refusals, sandbox auth.
When NOT to use
  • Generic OWASP / lint-style review without deepsec → use oma-qa.
  • Generic CVE / dependency advisories → use oma-qa or oma-search.
  • Architecting a brand-new SAST pipeline that is not deepsec → use oma-architecture.
  • Writing or auditing application code itself → route to oma-backend / oma-frontend / oma-mobile.
  • Cloud / IAM / Terraform hardening → use oma-tf-infra (deepsec only scans the IaC; remediation lives there).
  • Pure reasoning about a finding's fix in product code → use oma-debug once deepsec has produced the finding.
Expected inputs
  • target_repo_root: absolute path of the codebase to scan (parent of .deepsec/).
  • intent: one of setup | scan | pr-review | matchers | triage | config | troubleshoot.
  • credential_mode: ai-gateway-key | vercel-oidc | direct-anthropic | direct-openai | subscription.
  • agent_choice: use the user-named backend, configured defaultAgent, or a choice within delegated scope; ask only when a material choice remains unresolved.
  • severity_floor: lowest severity worth surfacing (typically HIGH).
  • Optional: existing .deepsec/data/<id>/, deepsec.config.ts, custom matchers, CI provider.
Expected outputs
  • A working .deepsec/ workspace registered against the target repo.
  • A populated data/<id>/INFO.md (50-100 lines, project-specific, no line numbers).
  • One or more completed scan → process (→ triage/revalidate) runs with reproducible cost notes.
  • For PR mode: a CI workflow file using process --diff <base> with two-job split (no PR-write in PR-code job).
  • For matchers: new .deepsec/matchers/<slug>.ts files wired through the inline plugin in deepsec.config.ts.
  • A findings export (md-dir and/or json) plus a short summary of top severities and FP-rate notes.
  • Explicit, dollar-and-time-bounded plan before any pass that may cost more than ~$25.
Dependencies
  • Node.js 22+, plus a package manager: bun / bunx (preferred in this monorepo), pnpm, npm, or yarn.
  • A working AI credential: AI_GATEWAY_API_KEY=vck_…, or VERCEL_OIDC_TOKEN, or direct ANTHROPIC_AUTH_TOKEN + ANTHROPIC_BASE_URL, or a logged-in claude / codex CLI subscription.
  • Git (history is consulted by revalidate and --diff modes).
  • Optional: Vercel Sandbox auth for deepsec sandbox … distributed runs.
  • Reference resources under resources/ (loaded only when the scenario requires them).
Control-flow features
  • Branches by intent (setup vs scan vs pr-review vs matchers vs triage vs config vs troubleshoot).
  • Branches by repo size (calibrate with --limit 50 before any large pass).
  • Branches by credential source (gateway key, OIDC, direct, subscription).
  • Stops on quota / credit exhaustion and resumes the same command after top-up.
  • Refuses to launch an unbounded process when no calibration has been done and the repo is large.
  • Reads codebase, writes .deepsec/ files and CI configs, runs long-lived AI processes.

Structural Flow

Entry
  1. Confirm whether .deepsec/ already exists; if yes, treat the run as incremental, never re-init.
  2. Resolve intent from the user prompt; if ambiguous (e.g. "scan this repo"), default to setup then scan (calibration mode).
  3. Estimate scale: count source files (rough rg --files | wc -l excluding node_modules, .git, dist) to forecast cost before any AI pass.
  4. Resolve the selected credential mode and backend. Check its required environment configuration or an existing claude / codex subscription login, without echoing secrets. A valid subscription session does not require an API-key environment variable. Resolve only missing configuration before AI calls.
  5. Resolve backend, scope, and spend from existing instructions and configuration under ../_shared/core/execution-policy.md. Before paid or custom-scope work, record the actual approved, limited, or declined action using resources/decision-records.md. A configured backend does not authorize additional spend; ask only for a material missing choice or new authorization.
Transitions
  • If .deepsec/ is missing and intent involves scanning → run bunx deepsec init (or npx deepsec init) and follow the printed prompt to populate INFO.md before any AI pass.
  • If INFO.md is empty or template-shaped → write it (50-100 lines, project-specific, 3-5 examples per section, no line numbers, no generic CWE enumeration).
  • If repo is > 500 files and no calibration has run → run a calibration pass first (deepsec docs recommend --limit 50 --concurrency 5) and report cost extrapolation before the full pass.
  • If a process / revalidate run halts on quota → leave file locks intact, surface the exact remediation URL, re-run the same command after top-up.
  • If the agent reports a refusal (refused: true) → never silently drop; document the affected files and either retry with the other backend or add the path to config.json:ignorePaths only if reproducible.
  • If the user wants a CI gate → emit the two-job pattern (PR-code job has no pull-requests: write, comment job has no PR code).
  • If the user wants more matcher coverage → run the matcher-authoring workflow against data/<id>/files/ and the parent repo's entry points.
Failure and recovery
FailureRecovery
Missing AI credentials for --agent claude / codexCheck the selected mode per resources/config.md: environment configuration for key/OIDC/direct modes, or CLI login for subscription mode. Do not require .env.local credentials for a valid subscription session.
401 Unauthorized from gatewayOIDC: re-run vercel env pull (12 h expiry). API key: regenerate. Confirm .env.local is in the cwd deepsec runs from.
Stopped: AI Gateway credits exhaustedTop up via the printed URL; re-run the same command, files already done are skipped.
Stopped: Claude Pro/Max subscription exhaustedSwitch to AI Gateway; subscriptions don't carry full scans.
Persistent refusal on a single file (>5% of batches)Add the path to data/<id>/config.json:ignorePaths, or run that file alone with --batch-size 1.
FP rate too high on HIGH+Run revalidate --min-severity HIGH; tighten INFO.md's threat model and FP notes; bias matchers to precise.
noisy matcher wedges scanner on a 100k-file repoTighten filePatterns to language- or directory-anchored globs.
Sandbox auth failsOIDC: re-run vercel env pull. Access-token mode: verify VERCEL_TOKEN + VERCEL_TEAM_ID + VERCEL_PROJECT_ID.
Full pass exceeds existing scope or spend authorizationReport the calibrated estimate and preserve completed free/limited work. Resolve only the missing authorization; record the actual approved, limited, or declined pass before executing it.
Exit
  • Success: planned passes ran, findings exist with verdicts (or no findings produced), files written are listed, residual cost / followups are explicit.
  • Partial success: some passes blocked on credentials/quota/refusal; the blocker, the safe-resume command, and the recommended next step are reported.
  • Failure: nothing destructive happened, the user has the exact next command to unblock the work.

Logical Operations

Tools and instruments
  • Package manager: bun / bunx (preferred), pnpm, npm, yarn are interchangeable.
  • CLI commands: deepsec init, init-project, scan, process, process --diff, triage, revalidate, enrich, report, export, metrics, status, sandbox <cmd>.
  • Diff sources for PR mode: --diff <ref|range>, --diff-staged, --diff-working, --files <csv>, --files-from <path> (or - for stdin).
  • Inspection: jq over data/<id>/files/**/*.json for ad-hoc severity / TP queries.
  • Credentials: AI_GATEWAY_API_KEY, VERCEL_OIDC_TOKEN, ANTHROPIC_AUTH_TOKEN / ANTHROPIC_BASE_URL, OPENAI_API_KEY / OPENAI_BASE_URL, claude login, codex login.
  • Resource files under resources/ for setup, scanning, PR review, matchers, triage, config, load on demand.
Show full SKILL.md (1,106 more words)Show less
Canonical workflow path
  1. Bootstrap (one time per repo):
    bash
    cd <target-repo>
    bunx deepsec init
    cd .deepsec
    bun install
    # Edit .env.local: set AI_GATEWAY_API_KEY=vck_… (or VERCEL_OIDC_TOKEN via `vercel env pull`)
    Then prompt the coding agent (this skill) to read .deepsec/node_modules/deepsec/SKILL.md and .deepsec/data/<id>/SETUP.md, skim README / AGENTS.md / CLAUDE.md and a handful of representative files, and replace each section of data/<id>/INFO.md (50-100 lines, 3-5 examples per section, no line numbers, no generic CWE rehash).
  2. Calibrate before any full pass. First record the selected authorized calibration scope using resources/decision-records.md; --limit bounds files, not dollar spend. The deepsec docs (getting-started.md, vercel-setup.md, faq.md) recommend --limit 50 --concurrency 5 as the calibration starting point.
    bash
    bunx deepsec scan
    bunx deepsec status
    bunx deepsec process --limit 50 --concurrency 5
    Read the run cost and extrapolate to the full repo using resources/scanning.md. Reuse existing authorization covering the backend, scope, and estimated spend. Record the actual scope decision before calibration and again before an expanded pass; resolve only missing authorization. If the user names different --limit / --concurrency values, use theirs.
  3. Full investigation, triage, revalidate, export:
    bash
    bunx deepsec process --concurrency 5
    bunx deepsec triage --severity HIGH
    bunx deepsec revalidate --min-severity HIGH
    Record and verify every triaged finding's actual verdict using resources/decision-records.md before filtering or suppression, including findings that will not be surfaced. Then export:
    bash
    bunx deepsec export --format md-dir --out ./findings
    bunx deepsec metrics
  4. PR mode (CI gate, scoped to changed files, exit code = 0/1):
    bash
    bunx deepsec process \
      --diff origin/${BASE_REF} \
      --comment-out comment.md
    Wire the two-job CI pattern from resources/pr-review.md. Never grant pull-requests: write to the job that runs PR-controlled code.
  5. Custom matchers (close entry-point gaps surfaced in step 3):
    • Read the contract in .deepsec/node_modules/deepsec/dist/config.d.ts and the samples/webapp/matchers/* examples.
    • Write .deepsec/matchers/<slug>.ts, wire it through the inline plugin in .deepsec/deepsec.config.ts.
    • Verify hit rate: bunx deepsec scan --matchers <slug> should land in 1-20 hits / 1k files (precise), 5-100 (normal), or roughly the framework entry-point count (noisy).
  6. Resume after any quota stop, network blip, or Ctrl-C: re-run the same command. State is on disk under .deepsec/data/<id>/.
Resource scope
ScopeResource target
CODEBASETarget repo source files, framework configs, route directories, README / AGENTS.md / CLAUDE.md.
LOCAL_FS.deepsec/deepsec.config.ts, .deepsec/.env.local, .deepsec/matchers/, .deepsec/data/<id>/{project.json,INFO.md,config.json,files/,runs/,reports/}, generated findings/, comment.md, CI workflow files.
PROCESS`bunx deepsec scan
NETWORKAnthropic / OpenAI via Vercel AI Gateway (default) or direct provider endpoints; optional Vercel Sandbox microVM control plane.
CREDENTIALSAI_GATEWAY_API_KEY, VERCEL_OIDC_TOKEN, ANTHROPIC_AUTH_TOKEN, OPENAI_API_KEY, VERCEL_TOKEN / VERCEL_TEAM_ID / VERCEL_PROJECT_ID, claude / codex subscription tokens. Consume read-only; never echo secrets back to the user or commit them.
MEMORYUser-stated budget cap, severity floor, and stop conditions for the current session.
Preconditions
  • Node.js 22+ is available.
  • Repo is a git checkout (deepsec uses git history for revalidate and --diff).
  • For any AI command: at least one credential mode is configured before the call, or the call is held until one is.
  • For sandbox mode: Vercel auth is wired; otherwise stay local.
  • For unbounded process: measured file scope and calibrated cost must fit existing authorization; otherwise use an authorized limited pass or resolve the missing spend/scope decision.
Effects and side effects
  • Creates .deepsec/ (config, lockfile, scaffolding) and .deepsec/data/<id>/ (gitignored) inside the target repo.
<!-- oma-docs:ignore-start -->
  • Writes .env.local (never commit) and may run vercel link / vercel env pull (writes .vercel/project.json + token).
<!-- oma-docs:ignore-end -->
  • Spawns long-running AI processes that cost real money. Single full scans range from $25 to over $1,200 per the official cost guide and can climb to tens of thousands on very large repos.
  • Reads source code; sends snippets to the configured LLM (gateway = zero retention; direct provider = subject to that provider's policy). Never exfiltrates secrets; the gateway key stays outside the worker sandbox in sandbox mode.
<!-- oma-docs:ignore-start -->
  • May write .github/workflows/deepsec.yml (or analogue) when the user asks for a CI gate.
<!-- oma-docs:ignore-end -->
  • Edits deepsec.config.ts and adds .deepsec/matchers/*.ts when authoring matchers.
  • Does not commit, push, or open PRs unless the user explicitly authorizes a separate commit step (route via oma-scm).
Guardrails
  1. Never launch an unbounded process on a repo whose size you have not measured. Always run a calibration pass first when file count is unknown or > 500 (deepsec docs recommend --limit 50 --concurrency 5; defer to a user-named value if given).
  2. State cost and stopping condition before any AI pass. Use the published bands (100 files ≈ $25-60, 500 ≈ $130-300, 2,000 ≈ $500-1,200; ×2-3 swing).
  3. Resume, do not reset. After any network / quota / Ctrl-C interruption, re-run the same command. Never delete data/<id>/ to "start clean" without explicit user instruction.
  4. INFO.md stays short and project-specific. 50-100 lines, 3-5 examples per section. Name primitives but no line numbers. Skip generic CWE categories; built-in matchers cover those.
  5. For PR/CI gates, keep PR-controlled code in a no-write job. Never grant pull-requests: write to a job that executes PR-controlled pnpm install / config-loading. Use the two-job pattern in resources/pr-review.md.
  6. Pin actions to full SHAs in production CI; major-version tags are for examples only.
  7. Never silently drop refusals. If the agent reports refused: true, log it, retry with the other backend, or add the file to ignorePaths only when reproducible.
  8. Bias matchers toward precise when the bug shape is exact. Reserve noisy for entry-point coverage and tight globs.
  9. Never echo or commit credentials (vck_…, sk-ant-…, sk-…, OIDC tokens). Treat .env.local as secret. Treat data/ as gitignored by default.
  10. Treat deepsec like an agent with shell access. Recommend sandbox for prompt-injection-prone repos (vendored code, untrusted deps).
  11. Findings need verdicts. For any HIGH+ surfaced to the user, prefer revalidate-tagged verdicts (true-positive / false-positive / fixed / uncertain) over raw process output.
  12. Do not invent CLI flags, and trust the CLI over these notes. Anything beyond resources/scanning.md's flag list must be checked against --help first. Likewise, when the CLI's printed model names, defaults, or per-batch costs disagree with the values written in this skill, the CLI is right — upstream moves faster than these resources.
  13. Reuse existing backend, scope, and spend decisions. Record consequential execution choices and per-finding verdicts through resources/decision-records.md; do not add another confirmation when existing authorization covers the action.

References

  • L1 execution scope and per-finding verdict records: resources/decision-records.md (before paid/custom-scope work or filtering triaged findings).
  • Workspace install + INFO.md bootstrap: resources/setup.md
  • Full scan/process/triage/revalidate/export workflow + cost guide: resources/scanning.md
  • PR / CI gate via process --diff (two-job pattern, exit-code semantics): resources/pr-review.md
  • Authoring custom matchers (slugs, noise tiers, file globs, plugin wiring): resources/matchers.md
  • Reading findings, severities, triage / revalidation verdicts, FP cuts: resources/triage.md
  • deepsec.config.ts reference, env vars, plugin order, AI Gateway / Vercel Sandbox auth: resources/config.md
  • Upstream docs (load only when a resource file points at one):
  • Shared context loading: ../_shared/core/context-loading.md
  • Shared quality principles: ../_shared/core/quality-principles.md

© first-fluke, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files in skills/oma-deepsec of first-fluke/oh-my-agent.

  • SKILL.md
  • resources/config.md
  • resources/decision-records.md
  • resources/matchers.md
  • resources/pr-review.md
  • resources/scanning.md
  • resources/setup.md
  • resources/triage.md

Open the folder on GitHubat commit f65bbc0

Used in 1 other repository

We found 2 copies of this SKILL.md (exact, near-identical or edited) in other folders. This page covers the copy in first-fluke/oh-my-agent, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Oma Deepsec next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Oma Deepsec compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Oma Deepsec this skillfirst-fluke/oh-my-agent1.3k—~4.9kAutomated safety check: NotesMIT
Deepsec Documentation Guidevercel-labs/deepsec8.1k—~956Automated safety check: PassApache-2.0
Deepsec Vulnerability Scannervercel-labs/deepsec8.1k—~1.2kAutomated safety check: PassApache-2.0
Shiro Attack CLISummerSec/ShiroAttack22.6k—~945Automated safety check: PassMIT
Cve Remediationrundeck/rundeck6.3k—~2.9kAutomated safety check: PassApache-2.0
Native Dependency Updatemono/SkiaSharp5.6k—~4.1kAutomated safety check: PassMIT

Similar skills

  • Deepsec Documentation Guide

    vercel-labs/deepsec

    Official

    Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.

    8.1k GitHub stars~956 tokensUpdated 9 days ago
    SecurityAuto-check passed
  • Official

    Runs deepsec's AI-powered security scan over a repository's uncommitted changes, its diff to main, or the whole codebase, using a regex pass followed by agent investigation.

    8.1k GitHub stars~1.2k tokensUpdated 9 days ago
    SecurityAuto-check passed
  • Shiro Attack CLI

    SummerSec/ShiroAttack2

    当用户要求利用、检测或测试 Apache Shiro rememberMe 反序列化漏洞 (Shiro-550, CVE-2016-4437) 时使用。触发词包括 "Shiro"、"rememberMe"、"shiro attack"、"CVE-2016-4437"、"Shiro-550"、"爆破 Shiro key"、"利用 Shiro"、"Shiro…

    2.6k GitHub stars~945 tokensUpdated 4 mo ago
    SecurityAuto-check passed
  • Cve Remediation

    rundeck/rundeck

    Verify if a CVE affects the project and remediate it. An agent skill from rundeck/rundeck.

    6.3k GitHub stars~2.9k tokensUpdated today
    SecurityAuto-check passed
  • Update native dependencies (libpng, libexpat, zlib, libwebp, harfbuzz, freetype, libjpeg-turbo, etc.) in SkiaSharp's Skia fork.

    5.6k GitHub stars~4.1k tokensUpdated today
    SecurityAuto-check passed
  • Forensify

    alexgreensh/repo-forensics

    Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.

    188 GitHub stars~2.5k tokensUpdated 11 days ago
    SecurityAuto-check: notes

More from first-fluke/oh-my-agent

All 57 skills in this repo
  • OMA Multi-Agent Orchestration

    first-fluke/oh-my-agent

    Decomposes a complex feature into tasks, dispatches parallel specialist agents with durable state, and supervises verification, QA review and retries.

    1.3k GitHub stars~4.1k tokensUpdated today
    Auto-check passed
  • Oma Video

    first-fluke/oh-my-agent

    Create short, explainer, or recorded-demo videos through the OMA video CLI.

    1.3k GitHub starsUsed in 1 repo~1.7k tokens
    Auto-check passed
  • OMA Multi-Agent Orchestrator

    first-fluke/oh-my-agent

    Splits a complex feature into prioritized tasks, spawns specialist CLI subagents in parallel, tracks them through shared memory and verifies each result.

    1.3k GitHub stars~3.1k tokensUpdated today
    Auto-check passed
  • Architecture Decisions and ADRs

    first-fluke/oh-my-agent

    Evaluates system boundaries and tradeoffs and writes architecture recommendations, option comparisons or ADRs, with a Mermaid diagram when structure changes.

    1.3k GitHub stars~2.6k tokensUpdated today
    Auto-check passed
  • OMA Backend Agent

    first-fluke/oh-my-agent

    Backend specialist for APIs, database work, authentication and migrations that follows clean architecture with router, service and repository layers.

    1.3k GitHub stars~2.4k tokensUpdated today
    Auto-check passed
  • oma Bootstrap

    first-fluke/oh-my-agent

    Installs or checks the oma CLI and its runtimes (bun, uv, serena) in a fresh workspace so that oma-* skills can run their commands.

    1.3k GitHub stars~719 tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Oma Deepsec

What does Oma Deepsec do?

Set up and run Deepsec vulnerability scans, triage, and CI gates. Oma Deepsec is an agent skill from first-fluke/oh-my-agent. Set up and run Deepsec vulnerability scans, triage, and CI gates.

When should I use Oma Deepsec?

Oma Deepsec fits situations like: an explicitly requested agent-powered vulnerability scan; tasks that involve Vulnerability scanning.

How do I install Oma Deepsec in Claude Code?

Run `npx skills add first-fluke/oh-my-agent --skill oma-deepsec -a claude-code`. Or copy the skill folder (skills/oma-deepsec in first-fluke/oh-my-agent) into .claude/skills/oma-deepsec in your project. Claude Code loads it when a task matches its description.

How do I install Oma Deepsec in Codex?

Run `npx skills add first-fluke/oh-my-agent --skill oma-deepsec -a codex`. Or copy the skill folder (skills/oma-deepsec in first-fluke/oh-my-agent) into .agents/skills/oma-deepsec in your project. Codex loads it when a task matches its description.

Can I use Oma Deepsec in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add first-fluke/oh-my-agent --skill oma-deepsec -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/oma-deepsec, .gemini/skills/oma-deepsec, .github/skills/oma-deepsec and .opencode/skills/oma-deepsec in your project.

What does Oma Deepsec need to run?

Going by SKILL.md and its folder, Oma Deepsec needs the command-line tools its instructions call (bunx, vercel, bun, pnpm, npx and rg) and credentials named AI_GATEWAY_API_KEY, VERCEL_OIDC_TOKEN, ANTHROPIC_AUTH_TOKEN and VERCEL_TOKEN. Our summary lists: Node.js; A credential in AI_GATEWAY_API_KEY; A credential in VERCEL_OIDC_TOKEN.

Does Oma Deepsec access the network?

SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.

Is Oma Deepsec safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Oma Deepsec use?

Oma Deepsec is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Oma Deepsec use?

About 4.9k tokens (SKILL.md is roughly 19k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Oma Deepsec?

Skills that share tags, products or a category with Oma Deepsec: Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars), Deepsec Vulnerability Scanner (vercel-labs/deepsec, 8.1k stars), Shiro Attack CLI (SummerSec/ShiroAttack2, 2.6k stars) and Cve Remediation (rundeck/rundeck, 6.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Oma Deepsec?

first-fluke (a GitHub organization) maintains it in first-fluke/oh-my-agent, which has 1,338 GitHub stars. The repository holds 57 skills in this directory. The repository was last updated on October 8, 2026.

Source: first-fluke/oh-my-agent on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.