Deepsec Documentation Guide
vercel-labs/deepsec
Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.
Set up and run Deepsec vulnerability scans, triage, and CI gates.
$ npx skills add first-fluke/oh-my-agent --skill oma-deepsec -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install first-fluke/oh-my-agent oma-deepsec --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/first-fluke/oh-my-agent.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/oma-deepsec .claude/skills/oma-deepsec && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "oma-deepsec" agent skill from https://github.com/first-fluke/oh-my-agent/tree/main/skills/oma-deepsec into .claude/skills/oma-deepsec/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "oma-deepsec", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/first-fluke/oh-my-agent/tree/main/skills/oma-deepsecType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add first-fluke/oh-my-agent --skill oma-deepsec -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install first-fluke/oh-my-agent oma-deepsec --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/first-fluke/oh-my-agent.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/oma-deepsec .agents/skills/oma-deepsec && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "oma-deepsec" agent skill from https://github.com/first-fluke/oh-my-agent/tree/main/skills/oma-deepsec into .agents/skills/oma-deepsec/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "oma-deepsec", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add first-fluke/oh-my-agent --skill oma-deepsec -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install first-fluke/oh-my-agent oma-deepsec --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/first-fluke/oh-my-agent.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/oma-deepsec .cursor/skills/oma-deepsec && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "oma-deepsec" agent skill from https://github.com/first-fluke/oh-my-agent/tree/main/skills/oma-deepsec into .cursor/skills/oma-deepsec/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "oma-deepsec", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/first-fluke/oh-my-agent.git --path skills/oma-deepsec--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add first-fluke/oh-my-agent --skill oma-deepsec -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install first-fluke/oh-my-agent oma-deepsec --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/first-fluke/oh-my-agent.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/oma-deepsec .gemini/skills/oma-deepsec && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "oma-deepsec" agent skill from https://github.com/first-fluke/oh-my-agent/tree/main/skills/oma-deepsec into .gemini/skills/oma-deepsec/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "oma-deepsec", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install first-fluke/oh-my-agent oma-deepsecInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add first-fluke/oh-my-agent --skill oma-deepsec -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/first-fluke/oh-my-agent.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/oma-deepsec .github/skills/oma-deepsec && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "oma-deepsec" agent skill from https://github.com/first-fluke/oh-my-agent/tree/main/skills/oma-deepsec into .github/skills/oma-deepsec/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "oma-deepsec", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add first-fluke/oh-my-agent --skill oma-deepsec -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install first-fluke/oh-my-agent oma-deepsec --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/first-fluke/oh-my-agent.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/oma-deepsec .opencode/skills/oma-deepsec && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "oma-deepsec" agent skill from https://github.com/first-fluke/oh-my-agent/tree/main/skills/oma-deepsec into .opencode/skills/oma-deepsec/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "oma-deepsec", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
oma-deepsecSet up and run Deepsec vulnerability scans, triage, and CI gates.
Oma Deepsec is an agent skill from first-fluke/oh-my-agent. Set up and run Deepsec vulnerability scans, triage, and CI gates. Use for Deepsec work or an explicitly requested agent-powered vulnerability scan.
Its SKILL.md is about 4.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files (for example `resources/config.md`, `resources/decision-records.md` and `resources/matchers.md`).
It sits in Security, covering Vulnerability scanning. It works with Vercel. The repository describes itself as: Mechanical verification for AI coding agents — skills pack or full harness (stop-hook gates, artifact checks, independent judges). The licence is MIT.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit f65bbc0. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
bunxvercelbunpnpmnpxrgclaudecodexFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
github.comFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
AI_GATEWAY_API_KEYVERCEL_OIDC_TOKENANTHROPIC_AUTH_TOKENVERCEL_TOKENOPENAI_API_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Oma Deepsec loads about 4.9k tokens when it runs. Until then it costs about 40 tokens; SKILL.md has 2,302 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
n for subscription mode. Do not require `.env.local` credentials for a valid subscription session. |h expiry). API key: regenerate. Confirm `.env.local` is in the cwd deepsec runs from. |# Edit .env.local: set AI_GATEWAY_API_KEY=vck_… (or VERCEL_OIDC_TOKEN via `vercel env pull`)`.deepsec/deepsec.config.ts`, `.deepsec/.env.local`, `.deepsec/matchers/`, `.deepsec/data/<id>/{project.json,INFO.md,co- Writes `.env.local` (never commit) and may run `vercel link` / `vercel env pull` (writes `.vercel/project.json` + toke`sk-ant-…`, `sk-…`, OIDC tokens). Treat `.env.local` as secret. Treat `data/` as gitignored by default.Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from first-fluke/oh-my-agent at commit f65bbc0, republished under its MIT licence (© first-fluke). 2,302 words, ~4,860 tokens.
.claude/skills/oma-deepsec/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.Operate Vercel's deepsec security scanner inside a target repository safely and cost-consciously: bootstrap the .deepsec/ workspace, write a tight INFO.md, run the right scan/process/triage/revalidate/export sequence, gate PRs in CI via process --diff, and grow project-specific matchers, surfacing real, revalidated findings without runaway spend.
deepsec, "deep security scan", bunx deepsec, pnpm deepsec, npx deepsec..deepsec/ directory.process --diff, --diff-staged, --diff-working, --files-from, --comment-out.INFO.md, SETUP.md, data/<id>/files/, FileRecord, RunMeta, revalidation, triage, custom matchers, MatcherPlugin, noiseTier, priorityPaths.deepsec.config.ts, defaultAgent, AI_GATEWAY_API_KEY, VERCEL_OIDC_TOKEN, AI Gateway, Vercel Sandbox, --agent codex, --agent claude.init, INFO.md write, first calibration scan).process --diff and --comment-out.revalidate, exporting to issue tracker).oma-qa.oma-qa or oma-search.oma-architecture.oma-backend / oma-frontend / oma-mobile.oma-tf-infra (deepsec only scans the IaC; remediation lives there).oma-debug once deepsec has produced the finding.target_repo_root: absolute path of the codebase to scan (parent of .deepsec/).intent: one of setup | scan | pr-review | matchers | triage | config | troubleshoot.credential_mode: ai-gateway-key | vercel-oidc | direct-anthropic | direct-openai | subscription.agent_choice: use the user-named backend, configured defaultAgent, or a choice within delegated scope; ask only when a material choice remains unresolved.severity_floor: lowest severity worth surfacing (typically HIGH)..deepsec/data/<id>/, deepsec.config.ts, custom matchers, CI provider..deepsec/ workspace registered against the target repo.data/<id>/INFO.md (50-100 lines, project-specific, no line numbers).scan → process (→ triage/revalidate) runs with reproducible cost notes.process --diff <base> with two-job split (no PR-write in PR-code job)..deepsec/matchers/<slug>.ts files wired through the inline plugin in deepsec.config.ts.md-dir and/or json) plus a short summary of top severities and FP-rate notes.bun / bunx (preferred in this monorepo), pnpm, npm, or yarn.AI_GATEWAY_API_KEY=vck_…, or VERCEL_OIDC_TOKEN, or direct ANTHROPIC_AUTH_TOKEN + ANTHROPIC_BASE_URL, or a logged-in claude / codex CLI subscription.revalidate and --diff modes).deepsec sandbox … distributed runs.resources/ (loaded only when the scenario requires them).intent (setup vs scan vs pr-review vs matchers vs triage vs config vs troubleshoot).--limit 50 before any large pass).process when no calibration has been done and the repo is large..deepsec/ files and CI configs, runs long-lived AI processes..deepsec/ already exists; if yes, treat the run as incremental, never re-init.intent from the user prompt; if ambiguous (e.g. "scan this repo"), default to setup then scan (calibration mode).rg --files | wc -l excluding node_modules, .git, dist) to forecast cost before any AI pass.claude / codex subscription login, without echoing secrets. A valid subscription session does not require an API-key environment variable. Resolve only missing configuration before AI calls.../_shared/core/execution-policy.md. Before paid or custom-scope work, record the actual approved, limited, or declined action using resources/decision-records.md. A configured backend does not authorize additional spend; ask only for a material missing choice or new authorization..deepsec/ is missing and intent involves scanning → run bunx deepsec init (or npx deepsec init) and follow the printed prompt to populate INFO.md before any AI pass.INFO.md is empty or template-shaped → write it (50-100 lines, project-specific, 3-5 examples per section, no line numbers, no generic CWE enumeration).--limit 50 --concurrency 5) and report cost extrapolation before the full pass.process / revalidate run halts on quota → leave file locks intact, surface the exact remediation URL, re-run the same command after top-up.refused: true) → never silently drop; document the affected files and either retry with the other backend or add the path to config.json:ignorePaths only if reproducible.pull-requests: write, comment job has no PR code).data/<id>/files/ and the parent repo's entry points.| Failure | Recovery |
|---|---|
Missing AI credentials for --agent claude / codex | Check the selected mode per resources/config.md: environment configuration for key/OIDC/direct modes, or CLI login for subscription mode. Do not require .env.local credentials for a valid subscription session. |
401 Unauthorized from gateway | OIDC: re-run vercel env pull (12 h expiry). API key: regenerate. Confirm .env.local is in the cwd deepsec runs from. |
Stopped: AI Gateway credits exhausted | Top up via the printed URL; re-run the same command, files already done are skipped. |
Stopped: Claude Pro/Max subscription exhausted | Switch to AI Gateway; subscriptions don't carry full scans. |
| Persistent refusal on a single file (>5% of batches) | Add the path to data/<id>/config.json:ignorePaths, or run that file alone with --batch-size 1. |
FP rate too high on HIGH+ | Run revalidate --min-severity HIGH; tighten INFO.md's threat model and FP notes; bias matchers to precise. |
noisy matcher wedges scanner on a 100k-file repo | Tighten filePatterns to language- or directory-anchored globs. |
| Sandbox auth fails | OIDC: re-run vercel env pull. Access-token mode: verify VERCEL_TOKEN + VERCEL_TEAM_ID + VERCEL_PROJECT_ID. |
| Full pass exceeds existing scope or spend authorization | Report the calibrated estimate and preserve completed free/limited work. Resolve only the missing authorization; record the actual approved, limited, or declined pass before executing it. |
bun / bunx (preferred), pnpm, npm, yarn are interchangeable.deepsec init, init-project, scan, process, process --diff, triage, revalidate, enrich, report, export, metrics, status, sandbox <cmd>.--diff <ref|range>, --diff-staged, --diff-working, --files <csv>, --files-from <path> (or - for stdin).jq over data/<id>/files/**/*.json for ad-hoc severity / TP queries.AI_GATEWAY_API_KEY, VERCEL_OIDC_TOKEN, ANTHROPIC_AUTH_TOKEN / ANTHROPIC_BASE_URL, OPENAI_API_KEY / OPENAI_BASE_URL, claude login, codex login.resources/ for setup, scanning, PR review, matchers, triage, config, load on demand.cd <target-repo>
bunx deepsec init
cd .deepsec
bun install
# Edit .env.local: set AI_GATEWAY_API_KEY=vck_… (or VERCEL_OIDC_TOKEN via `vercel env pull`).deepsec/node_modules/deepsec/SKILL.md and .deepsec/data/<id>/SETUP.md,
skim README / AGENTS.md / CLAUDE.md and a handful of representative
files, and replace each section of data/<id>/INFO.md (50-100 lines,
3-5 examples per section, no line numbers, no generic CWE rehash).resources/decision-records.md; --limit bounds files, not dollar spend. The deepsec docs (getting-started.md, vercel-setup.md, faq.md) recommend --limit 50 --concurrency 5 as the calibration starting point.bunx deepsec scan
bunx deepsec status
bunx deepsec process --limit 50 --concurrency 5resources/scanning.md. Reuse existing authorization covering the backend, scope, and estimated spend. Record the actual scope decision before calibration and again before an expanded pass; resolve only missing authorization. If the user names different --limit / --concurrency values, use theirs.bunx deepsec process --concurrency 5
bunx deepsec triage --severity HIGH
bunx deepsec revalidate --min-severity HIGHresources/decision-records.md before filtering or suppression, including findings that will not be surfaced. Then export:bunx deepsec export --format md-dir --out ./findings
bunx deepsec metricsbunx deepsec process \
--diff origin/${BASE_REF} \
--comment-out comment.mdresources/pr-review.md. Never grant pull-requests: write to the job that runs PR-controlled code..deepsec/node_modules/deepsec/dist/config.d.ts and the samples/webapp/matchers/* examples..deepsec/matchers/<slug>.ts, wire it through the inline plugin in .deepsec/deepsec.config.ts.bunx deepsec scan --matchers <slug> should land in 1-20 hits / 1k files (precise), 5-100 (normal), or roughly the framework entry-point count (noisy)..deepsec/data/<id>/.| Scope | Resource target |
|---|---|
CODEBASE | Target repo source files, framework configs, route directories, README / AGENTS.md / CLAUDE.md. |
LOCAL_FS | .deepsec/deepsec.config.ts, .deepsec/.env.local, .deepsec/matchers/, .deepsec/data/<id>/{project.json,INFO.md,config.json,files/,runs/,reports/}, generated findings/, comment.md, CI workflow files. |
PROCESS | `bunx deepsec scan |
NETWORK | Anthropic / OpenAI via Vercel AI Gateway (default) or direct provider endpoints; optional Vercel Sandbox microVM control plane. |
CREDENTIALS | AI_GATEWAY_API_KEY, VERCEL_OIDC_TOKEN, ANTHROPIC_AUTH_TOKEN, OPENAI_API_KEY, VERCEL_TOKEN / VERCEL_TEAM_ID / VERCEL_PROJECT_ID, claude / codex subscription tokens. Consume read-only; never echo secrets back to the user or commit them. |
MEMORY | User-stated budget cap, severity floor, and stop conditions for the current session. |
revalidate and --diff).sandbox mode: Vercel auth is wired; otherwise stay local.process: measured file scope and calibrated cost must fit existing authorization; otherwise use an authorized limited pass or resolve the missing spend/scope decision..deepsec/ (config, lockfile, scaffolding) and .deepsec/data/<id>/ (gitignored) inside the target repo.<!-- oma-docs:ignore-start -->
.env.local (never commit) and may run vercel link / vercel env pull (writes .vercel/project.json + token).<!-- oma-docs:ignore-end -->
sandbox mode.<!-- oma-docs:ignore-start -->
.github/workflows/deepsec.yml (or analogue) when the user asks for a CI gate.<!-- oma-docs:ignore-end -->
deepsec.config.ts and adds .deepsec/matchers/*.ts when authoring matchers.oma-scm).process on a repo whose size you have not measured. Always run a calibration pass first when file count is unknown or > 500 (deepsec docs recommend --limit 50 --concurrency 5; defer to a user-named value if given).data/<id>/ to "start clean" without explicit user instruction.INFO.md stays short and project-specific. 50-100 lines, 3-5 examples per section. Name primitives but no line numbers. Skip generic CWE categories; built-in matchers cover those.pull-requests: write to a job that executes PR-controlled pnpm install / config-loading. Use the two-job pattern in resources/pr-review.md.refused: true, log it, retry with the other backend, or add the file to ignorePaths only when reproducible.precise when the bug shape is exact. Reserve noisy for entry-point coverage and tight globs.vck_…, sk-ant-…, sk-…, OIDC tokens). Treat .env.local as secret. Treat data/ as gitignored by default.sandbox for prompt-injection-prone repos (vendored code, untrusted deps).revalidate-tagged verdicts (true-positive / false-positive / fixed / uncertain) over raw process output.resources/scanning.md's flag list must be checked against --help first. Likewise, when the CLI's printed model names, defaults, or per-batch costs disagree with the values written in this skill, the CLI is right — upstream moves faster than these resources.resources/decision-records.md; do not add another confirmation when existing authorization covers the action.resources/decision-records.md (before paid/custom-scope work or filtering triaged findings).INFO.md bootstrap: resources/setup.mdresources/scanning.mdprocess --diff (two-job pattern, exit-code semantics): resources/pr-review.mdresources/matchers.mdresources/triage.mddeepsec.config.ts reference, env vars, plugin order, AI Gateway / Vercel Sandbox auth: resources/config.mdgetting-started, reviewing-changes, writing-matchers, configuration, models, plugins, architecture, data-layout, vercel-setup, supported-tech, faq)../_shared/core/context-loading.md../_shared/core/quality-principles.md© first-fluke, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 7 other files in skills/oma-deepsec of first-fluke/oh-my-agent.
Open the folder on GitHubat commit f65bbc0
We found 2 copies of this SKILL.md (exact, near-identical or edited) in other folders. This page covers the copy in first-fluke/oh-my-agent, which our catalogue first saw on October 7, 2026.
Oma Deepsec next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Oma Deepsec this skillfirst-fluke/oh-my-agent | 1.3k | — | ~4.9k | Automated safety check: Notes | MIT | |
| Deepsec Documentation Guidevercel-labs/deepsec | 8.1k | — | ~956 | Automated safety check: Pass | Apache-2.0 | |
| Deepsec Vulnerability Scannervercel-labs/deepsec | 8.1k | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | |
| Shiro Attack CLISummerSec/ShiroAttack2 | 2.6k | — | ~945 | Automated safety check: Pass | MIT | |
| Cve Remediationrundeck/rundeck | 6.3k | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | |
| Native Dependency Updatemono/SkiaSharp | 5.6k | — | ~4.1k | Automated safety check: Pass | MIT |
vercel-labs/deepsec
Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.
vercel-labs/deepsec
Runs deepsec's AI-powered security scan over a repository's uncommitted changes, its diff to main, or the whole codebase, using a regex pass followed by agent investigation.
SummerSec/ShiroAttack2
当用户要求利用、检测或测试 Apache Shiro rememberMe 反序列化漏洞 (Shiro-550, CVE-2016-4437) 时使用。触发词包括 "Shiro"、"rememberMe"、"shiro attack"、"CVE-2016-4437"、"Shiro-550"、"爆破 Shiro key"、"利用 Shiro"、"Shiro…
rundeck/rundeck
Verify if a CVE affects the project and remediate it. An agent skill from rundeck/rundeck.
mono/SkiaSharp
Update native dependencies (libpng, libexpat, zlib, libwebp, harfbuzz, freetype, libjpeg-turbo, etc.) in SkiaSharp's Skia fork.
alexgreensh/repo-forensics
Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.
first-fluke/oh-my-agent
Decomposes a complex feature into tasks, dispatches parallel specialist agents with durable state, and supervises verification, QA review and retries.
first-fluke/oh-my-agent
Create short, explainer, or recorded-demo videos through the OMA video CLI.
first-fluke/oh-my-agent
Splits a complex feature into prioritized tasks, spawns specialist CLI subagents in parallel, tracks them through shared memory and verifies each result.
first-fluke/oh-my-agent
Evaluates system boundaries and tradeoffs and writes architecture recommendations, option comparisons or ADRs, with a Mermaid diagram when structure changes.
first-fluke/oh-my-agent
Backend specialist for APIs, database work, authentication and migrations that follows clean architecture with router, service and repository layers.
first-fluke/oh-my-agent
Installs or checks the oma CLI and its runtimes (bun, uv, serena) in a fresh workspace so that oma-* skills can run their commands.
Works with
Categories
Set up and run Deepsec vulnerability scans, triage, and CI gates. Oma Deepsec is an agent skill from first-fluke/oh-my-agent. Set up and run Deepsec vulnerability scans, triage, and CI gates.
Oma Deepsec fits situations like: an explicitly requested agent-powered vulnerability scan; tasks that involve Vulnerability scanning.
Run `npx skills add first-fluke/oh-my-agent --skill oma-deepsec -a claude-code`. Or copy the skill folder (skills/oma-deepsec in first-fluke/oh-my-agent) into .claude/skills/oma-deepsec in your project. Claude Code loads it when a task matches its description.
Run `npx skills add first-fluke/oh-my-agent --skill oma-deepsec -a codex`. Or copy the skill folder (skills/oma-deepsec in first-fluke/oh-my-agent) into .agents/skills/oma-deepsec in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add first-fluke/oh-my-agent --skill oma-deepsec -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/oma-deepsec, .gemini/skills/oma-deepsec, .github/skills/oma-deepsec and .opencode/skills/oma-deepsec in your project.
Going by SKILL.md and its folder, Oma Deepsec needs the command-line tools its instructions call (bunx, vercel, bun, pnpm, npx and rg) and credentials named AI_GATEWAY_API_KEY, VERCEL_OIDC_TOKEN, ANTHROPIC_AUTH_TOKEN and VERCEL_TOKEN. Our summary lists: Node.js; A credential in AI_GATEWAY_API_KEY; A credential in VERCEL_OIDC_TOKEN.
SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Oma Deepsec is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.9k tokens (SKILL.md is roughly 19k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Oma Deepsec: Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars), Deepsec Vulnerability Scanner (vercel-labs/deepsec, 8.1k stars), Shiro Attack CLI (SummerSec/ShiroAttack2, 2.6k stars) and Cve Remediation (rundeck/rundeck, 6.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
first-fluke (a GitHub organization) maintains it in first-fluke/oh-my-agent, which has 1,338 GitHub stars. The repository holds 57 skills in this directory. The repository was last updated on October 8, 2026.
Source: first-fluke/oh-my-agent on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.