Security Audit Scanner
ruvnet/ruflo
Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.
Runs deepsec's AI-powered security scan over a repository's uncommitted changes, its diff to main, or the whole codebase, using a regex pass followed by agent investigation.
$ npx skills add vercel-labs/deepsec --skill deepsec -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install vercel-labs/deepsec deepsec --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
Claude Code skills documentation · loads skills from .claude/skills/
Install the "deepsec" agent skill from https://github.com/vercel-labs/deepsec/tree/main into .claude/skills/deepsec/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "deepsec", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add vercel-labs/deepsec --skill deepsec -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install vercel-labs/deepsec deepsec --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "deepsec" agent skill from https://github.com/vercel-labs/deepsec/tree/main into .agents/skills/deepsec/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "deepsec", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add vercel-labs/deepsec --skill deepsec -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install vercel-labs/deepsec deepsec --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "deepsec" agent skill from https://github.com/vercel-labs/deepsec/tree/main into .cursor/skills/deepsec/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "deepsec", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add vercel-labs/deepsec --skill deepsec -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install vercel-labs/deepsec deepsec --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "deepsec" agent skill from https://github.com/vercel-labs/deepsec/tree/main into .gemini/skills/deepsec/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "deepsec", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install vercel-labs/deepsec deepsecInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add vercel-labs/deepsec --skill deepsec -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "deepsec" agent skill from https://github.com/vercel-labs/deepsec/tree/main into .github/skills/deepsec/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "deepsec", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add vercel-labs/deepsec --skill deepsec -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install vercel-labs/deepsec deepsec --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "deepsec" agent skill from https://github.com/vercel-labs/deepsec/tree/main into .opencode/skills/deepsec/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "deepsec", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
deepsecRuns deepsec's AI-powered security scan over a repository's uncommitted changes, its diff to main, or the whole codebase, using a regex pass followed by agent investigation.
deepsec first asks which scope to process: uncommitted changes plus untracked files, the diff against origin/main (or main with no remote), or the entire codebase, warned as the expensive option since AI investigation of every candidate file can cost real money on a large repository. It asks before doing anything else so the rest of the run can proceed unattended.
Onboarding state is detected from the repository root: no .deepsec/deepsec.config.ts means a full first-time setup, a partial or interrupted .deepsec/ means re-running the init command to resume from checkpoints and repair the install, and anything else means the project is already onboarded. First-time onboarding normally ends with an AI pass over the whole repo, but since the user already chose a scope, setup stops after the coverage phase (install, login, threat model, matcher generation, the regex scan) and the scoped AI processing runs afterward instead.
A fast regex scan flags candidate files, then AI agents investigate each one and record findings with severity ratings that can later be revalidated, triaged and exported, with everything deepsec adds to the repo living inside a single .deepsec/ workspace.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 4fa6722. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
npxFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npx, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Deepsec Vulnerability Scanner loads about 1.2k tokens when it runs. Until then it costs about 54 tokens; SKILL.md has 661 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from vercel-labs/deepsec at commit 4fa6722, republished under its Apache-2.0 licence (© vercel-labs). 661 words, ~1,238 tokens.
.claude/skills/deepsec/SKILL.md (or your agent's skills folder). This skill also uses 702 other files; get the full folder from GitHub.deepsec is an AI-powered vulnerability scanner.
A fast regex scan flags candidate files, then AI agents investigate each
candidate in depth and record findings with severity ratings; findings can
later be revalidated, triaged, and exported. Everything it adds to a repository
lives in a single .deepsec/ workspace (config, installed package, per-project
data). Because processing runs real AI agents, it costs money in proportion
to how much code it investigates.
Follow this runbook when the user invokes /deepsec or asks for a scan.
Ask the user which scope to process, using a structured question tool if you have one (AskUserQuestion in Claude Code), otherwise plain text:
origin/main (use main if there is no
origin remote)Ask before doing anything else so the rest of the flow can run unattended.
From the repository root:
.deepsec/deepsec.config.ts → not onboarded. Do step 3 in full..deepsec/ exists but .deepsec/node_modules/deepsec is missing, or a
previous setup was interrupted → re-run the init command from step 3; it
resumes from checkpoints and repairs the install rather than starting over.Onboarding normally ends with an AI processing pass over the whole
repository. Since the user already chose a scope, stop setup after the
coverage phase — that still includes install, login, threat model, matcher
generation, and the final regex scan, but skips the full-repo AI process
phase. The scoped processing happens in step 4 instead.
From the repository root, inspect the read-only plan, then run setup:
npx -y deepsec init --plan --output json
npx -y deepsec init --yes --through coverage --output jsonlParse every output line as JSON. On a needs_input event, show the supplied
message and actions to the user rather than inventing remediation. In
particular, VERCEL_AUTH_REQUIRED normally asks the user to run
npx vercel login; after they do, follow the returned link action from
inside .deepsec (use npx vercel link when the user needs to choose a
project), then re-run the same init command. Exit code 2 means input is
needed; exit code 3 means a cost/duration boundary stopped the resumable
run — re-running the same command resumes it. Never expose credential
values, bypass --yes prompts on the user's behalf beyond the flag itself,
or launch an interactive login yourself.
Run from inside .deepsec/ (the config loader only finds
deepsec.config.ts in the current directory or its ancestors; after step 3,
npx deepsec resolves to the copy installed there):
| Scope | Command |
|---|---|
| Uncommitted changes | cd .deepsec && npx deepsec process --diff-working |
| Diff to main | cd .deepsec && npx deepsec process --diff origin/main |
| Entire codebase, right after step 3 | cd .deepsec && npx deepsec process (the final scan from setup already produced the candidate set) |
| Entire codebase, previously onboarded | cd .deepsec && npx deepsec scan && npx deepsec process |
--diff*) exit codes: 0 = no net-new findings, 1 = at
least one net-new finding (not an error), anything else = runtime error.
Pre-existing findings on touched files are excluded from the gate..deepsec/): npx deepsec report, npx deepsec revalidate, and
npx deepsec export --format md-dir --out ./findings.After onboarding, full documentation ships with the installed package at
.deepsec/node_modules/deepsec/dist/docs/ — getting-started.md,
reviewing-changes.md (direct mode, exit codes, CI gating),
configuration.md, models.md, and more. Read the relevant doc before
varying the commands above; flags and defaults change between releases.
© vercel-labs, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 702 other files in the repository root of vercel-labs/deepsec.
Open the folder on GitHubat commit 4fa6722
Deepsec Vulnerability Scanner next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Deepsec Vulnerability Scanner this skillvercel-labs/deepsec | 8.1k | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | |
| Security Audit Scannerruvnet/ruflo | 74k | 2 repos | ~823 | Automated safety check: Pass | MIT | |
| Native Dependency Updatemono/SkiaSharp | 5.6k | — | ~4.1k | Automated safety check: Pass | MIT | |
| Security AuditTheDecipherist/claude-code-mastery | 550 | — | ~1.3k | Automated safety check: Notes | MIT | |
| Fix Scan Findingmalloydata/publisher | 116 | — | ~5.1k | Automated safety check: Pass | MIT | |
| Claude Securityanthropics/claude-plugins-official | 37k | — | ~1.4k | Automated safety check: Pass | Apache-2.0 |
ruvnet/ruflo
Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.
mono/SkiaSharp
Update native dependencies (libpng, libexpat, zlib, libwebp, harfbuzz, freetype, libjpeg-turbo, etc.) in SkiaSharp's Skia fork.
TheDecipherist/claude-code-mastery
Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.
malloydata/publisher
Fix a CRITICAL Trivy finding that is failing CI in this repo (a vulnerability, misconfiguration, or secret from security-scan.yml or image-scan.yml), or add, review, or retire an entry in…
anthropics/claude-plugins-official
Scans a whole codebase or a set of changes for security issues, and turns findings into verified patch files that you apply yourself.
microsoft/haste
Dependabot and security analysis skill for HASTE. An agent skill from microsoft/haste.
vercel-labs/deepsec
Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.
Works with
Categories
Runs deepsec's AI-powered security scan over a repository's uncommitted changes, its diff to main, or the whole codebase, using a regex pass followed by agent investigation. deepsec first asks which scope to process: uncommitted changes plus untracked files, the diff against origin/main (or main with no remote), or the entire codebase, warned as the expensive option since AI investigation of every candidate file can cost real money on a large repository. It asks before doing anything else so the rest of the run can proceed unattended.
Deepsec Vulnerability Scanner fits situations like: scanning uncommitted changes for security vulnerabilities before a commit; checking a branch's diff to main for newly introduced vulnerabilities; running a full-codebase AI security review of legacy code; setting deepsec up for the first time in a repository.
Run `npx skills add vercel-labs/deepsec --skill deepsec -a claude-code`. Or copy the skill folder (the vercel-labs/deepsec repository) into .claude/skills/deepsec in your project. Claude Code loads it when a task matches its description.
Run `npx skills add vercel-labs/deepsec --skill deepsec -a codex`. Or copy the skill folder (the vercel-labs/deepsec repository) into .agents/skills/deepsec in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vercel-labs/deepsec --skill deepsec -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/deepsec, .gemini/skills/deepsec, .github/skills/deepsec and .opencode/skills/deepsec in your project.
Going by SKILL.md and its folder, Deepsec Vulnerability Scanner needs the command-line tools its instructions call (npx). Our summary lists: Node.js to run npx deepsec; An AI agent sandboxed enough to run security investigations.
SKILL.md contains no URLs. Its commands use npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Deepsec Vulnerability Scanner is published under the Apache-2.0 licence (from the LICENSE file in the skill folder). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.2k tokens (SKILL.md is roughly 5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Deepsec Vulnerability Scanner: Security Audit Scanner (ruvnet/ruflo, 74k stars), Native Dependency Update (mono/SkiaSharp, 5.6k stars), Security Audit (TheDecipherist/claude-code-mastery, 550 stars) and Fix Scan Finding (malloydata/publisher, 116 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
vercel-labs (a GitHub organization, an official publisher) maintains it in vercel-labs/deepsec, which has 8,115 GitHub stars. The repository holds 2 skills in this directory. The repository was last updated on September 29, 2026.
Source: vercel-labs/deepsec on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.