Official agent skill

Deepsec Vulnerability Scanner

by vercel-labs in vercel-labs/deepsec

Runs deepsec's AI-powered security scan over a repository's uncommitted changes, its diff to main, or the whole codebase, using a regex pass followed by agent investigation.

OfficialApache-2.0Auto-check passedSecurity

Install Deepsec Vulnerability Scanner

skills CLI
$ npx skills add vercel-labs/deepsec --skill deepsec -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install vercel-labs/deepsec deepsec --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
deepsec
GitHub stars
8.1k
Token cost
~1.2k tokens
SKILL.md length
661 words
Files
703
Skills in repo
2
Repo updated
First seen
Licence
Apache-2.0

At a glance

Runs deepsec's AI-powered security scan over a repository's uncommitted changes, its diff to main, or the whole codebase, using a regex pass followed by agent investigation.

  • Works in 5 steps: Ask for scope first → Detect onboarding state → Onboard without full processing → …
  • Scanning uncommitted changes for security vulnerabilities before a commit
  • SKILL.md covers 1. Ask for scope first, 2. Detect onboarding state, 3. Onboard without full… and 4. Run the scoped processing, plus 2 more sections
  • Calls npx

What it does

deepsec first asks which scope to process: uncommitted changes plus untracked files, the diff against origin/main (or main with no remote), or the entire codebase, warned as the expensive option since AI investigation of every candidate file can cost real money on a large repository. It asks before doing anything else so the rest of the run can proceed unattended.

Onboarding state is detected from the repository root: no .deepsec/deepsec.config.ts means a full first-time setup, a partial or interrupted .deepsec/ means re-running the init command to resume from checkpoints and repair the install, and anything else means the project is already onboarded. First-time onboarding normally ends with an AI pass over the whole repo, but since the user already chose a scope, setup stops after the coverage phase (install, login, threat model, matcher generation, the regex scan) and the scoped AI processing runs afterward instead.

A fast regex scan flags candidate files, then AI agents investigate each one and record findings with severity ratings that can later be revalidated, triaged and exported, with everything deepsec adds to the repo living inside a single .deepsec/ workspace.

When your agent uses it

  • Scanning uncommitted changes for security vulnerabilities before a commit
  • Checking a branch's diff to main for newly introduced vulnerabilities
  • Running a full-codebase AI security review of legacy code
  • Setting deepsec up for the first time in a repository

Example prompts

  • “/deepsec scan my uncommitted changes”
  • “Run deepsec on the diff between this branch and main.”
  • “Scan the entire codebase with deepsec, I know it will take a while.”

Requirements

  • Node.js to run npx deepsec
  • An AI agent sandboxed enough to run security investigations

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Ask for scope first
  2. Detect onboarding state
  3. Onboard without full processing
  4. Run the scoped processing
  5. Interpret results

What it can do on your machine

Read from SKILL.md and the folder at commit 4fa6722. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npx, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Deepsec Vulnerability Scanner loads about 1.2k tokens when it runs. Until then it costs about 54 tokens; SKILL.md has 661 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~54
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from vercel-labs/deepsec at commit 4fa6722, republished under its Apache-2.0 licence (© vercel-labs). 661 words, ~1,238 tokens.

Download SKILL.mdSave it as .claude/skills/deepsec/SKILL.md (or your agent's skills folder). This skill also uses 702 other files; get the full folder from GitHub.
name
deepsec
description
Run deepsec, an AI-powered cyber-security vulnerability scanner. Activates when the user invokes /deepsec, asks to run deepsec, or wants to scan their repo, branch, or uncommitted changes for vulnerabilities.

/deepsec — scan this repository with deepsec

deepsec is an AI-powered vulnerability scanner.

  • Modern AI models are great at security code review.
  • Most review solutions only run on pull requests.
  • That means most legacy code was never reviewed, and your code from 6 months ago was reviewed by older models.
  • Instead deepsec does security review on ALL of your existing code using scaled VM fanout.
  • Vercel's deepsec is open source, runs in your own infrastructure, and supports strong agent sandboxing.

A fast regex scan flags candidate files, then AI agents investigate each candidate in depth and record findings with severity ratings; findings can later be revalidated, triaged, and exported. Everything it adds to a repository lives in a single .deepsec/ workspace (config, installed package, per-project data). Because processing runs real AI agents, it costs money in proportion to how much code it investigates.

Follow this runbook when the user invokes /deepsec or asks for a scan.

1. Ask for scope first

Ask the user which scope to process, using a structured question tool if you have one (AskUserQuestion in Claude Code), otherwise plain text:

  • Uncommitted changes — working tree + untracked files
  • Diff to main — changes vs origin/main (use main if there is no origin remote)
  • Entire codebase — warn that this is the expensive option: AI processing investigates every candidate file and can cost real money on a large repository

Ask before doing anything else so the rest of the flow can run unattended.

2. Detect onboarding state

From the repository root:

  • No .deepsec/deepsec.config.ts → not onboarded. Do step 3 in full.
  • .deepsec/ exists but .deepsec/node_modules/deepsec is missing, or a previous setup was interrupted → re-run the init command from step 3; it resumes from checkpoints and repairs the install rather than starting over.
  • Otherwise → onboarded; skip to step 4.

3. Onboard without full processing

Onboarding normally ends with an AI processing pass over the whole repository. Since the user already chose a scope, stop setup after the coverage phase — that still includes install, login, threat model, matcher generation, and the final regex scan, but skips the full-repo AI process phase. The scoped processing happens in step 4 instead.

From the repository root, inspect the read-only plan, then run setup:

bash
npx -y deepsec init --plan --output json
npx -y deepsec init --yes --through coverage --output jsonl

Parse every output line as JSON. On a needs_input event, show the supplied message and actions to the user rather than inventing remediation. In particular, VERCEL_AUTH_REQUIRED normally asks the user to run npx vercel login; after they do, follow the returned link action from inside .deepsec (use npx vercel link when the user needs to choose a project), then re-run the same init command. Exit code 2 means input is needed; exit code 3 means a cost/duration boundary stopped the resumable run — re-running the same command resumes it. Never expose credential values, bypass --yes prompts on the user's behalf beyond the flag itself, or launch an interactive login yourself.

Show full SKILL.md (187 more words)Show less

4. Run the scoped processing

Run from inside .deepsec/ (the config loader only finds deepsec.config.ts in the current directory or its ancestors; after step 3, npx deepsec resolves to the copy installed there):

ScopeCommand
Uncommitted changescd .deepsec && npx deepsec process --diff-working
Diff to maincd .deepsec && npx deepsec process --diff origin/main
Entire codebase, right after step 3cd .deepsec && npx deepsec process (the final scan from setup already produced the candidate set)
Entire codebase, previously onboardedcd .deepsec && npx deepsec scan && npx deepsec process

5. Interpret results

  • Direct-mode (--diff*) exit codes: 0 = no net-new findings, 1 = at least one net-new finding (not an error), anything else = runtime error. Pre-existing findings on touched files are excluded from the gate.
  • Summarize any findings for the user, then offer follow-ups (all from inside .deepsec/): npx deepsec report, npx deepsec revalidate, and npx deepsec export --format md-dir --out ./findings.

Going deeper

After onboarding, full documentation ships with the installed package at .deepsec/node_modules/deepsec/dist/docs/ — getting-started.md, reviewing-changes.md (direct mode, exit codes, CI gating), configuration.md, models.md, and more. Read the relevant doc before varying the commands above; flags and defaults change between releases.

© vercel-labs, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 702 other files in the repository root of vercel-labs/deepsec.

  • SKILL.md
  • .agents/skills
  • .deepsec/.gitignore
  • .deepsec/AGENTS.md
  • .deepsec/README.md
  • .deepsec/data/deepsec/INFO.md
  • .deepsec/data/deepsec/SETUP.md
  • .deepsec/data/deepsec/files/.env.local.json
  • .deepsec/data/deepsec/files/.github/workflows/ci.yml.json
  • .deepsec/data/deepsec/files/.github/workflows/deepsec.yml.json
  • .deepsec/data/deepsec/files/.github/workflows/e2e-live-sandbox.yml.json
  • .deepsec/data/deepsec/files/.github/workflows/release.yml.json
  • .deepsec/data/deepsec/files/e2e/vitest.config.ts.json
  • … and 690 more

Open the folder on GitHubat commit 4fa6722

Compare with similar skills

Deepsec Vulnerability Scanner next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Deepsec Vulnerability Scanner compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Deepsec Vulnerability Scanner this skillvercel-labs/deepsec8.1k—~1.2kAutomated safety check: PassApache-2.0
Security Audit Scannerruvnet/ruflo74k2 repos~823Automated safety check: PassMIT
Native Dependency Updatemono/SkiaSharp5.6k—~4.1kAutomated safety check: PassMIT
Security AuditTheDecipherist/claude-code-mastery550—~1.3kAutomated safety check: NotesMIT
Fix Scan Findingmalloydata/publisher116—~5.1kAutomated safety check: PassMIT
Claude Securityanthropics/claude-plugins-official37k—~1.4kAutomated safety check: PassApache-2.0

Similar skills

  • Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.

    74k GitHub starsUsed in 2 repos~823 tokens
    SecurityAuto-check passed
  • Update native dependencies (libpng, libexpat, zlib, libwebp, harfbuzz, freetype, libjpeg-turbo, etc.) in SkiaSharp's Skia fork.

    5.6k GitHub stars~4.1k tokensUpdated today
    SecurityAuto-check passed
  • Security Audit

    TheDecipherist/claude-code-mastery

    Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.

    550 GitHub stars~1.3k tokensUpdated 5 mo ago
    SecurityAuto-check: notes
  • Fix Scan Finding

    malloydata/publisher

    Fix a CRITICAL Trivy finding that is failing CI in this repo (a vulnerability, misconfiguration, or secret from security-scan.yml or image-scan.yml), or add, review, or retire an entry in…

    116 GitHub stars~5.1k tokensUpdated today
    SecurityAuto-check passed
  • Claude Security

    anthropics/claude-plugins-official

    Official

    Scans a whole codebase or a set of changes for security issues, and turns findings into verified patch files that you apply yourself.

    37k GitHub stars~1.4k tokensUpdated today
    SecurityAuto-check passed
  • Security Analysis

    microsoft/haste

    Official

    Dependabot and security analysis skill for HASTE. An agent skill from microsoft/haste.

    106 GitHub stars~1k tokensUpdated 5 days ago
    SecurityAuto-check passed

More from vercel-labs/deepsec

  • Deepsec Documentation Guide

    vercel-labs/deepsec

    Official

    Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.

    8.1k GitHub stars~956 tokensUpdated 8 days ago
    Auto-check passed

Works with

Questions about Deepsec Vulnerability Scanner

What does Deepsec Vulnerability Scanner do?

Runs deepsec's AI-powered security scan over a repository's uncommitted changes, its diff to main, or the whole codebase, using a regex pass followed by agent investigation. deepsec first asks which scope to process: uncommitted changes plus untracked files, the diff against origin/main (or main with no remote), or the entire codebase, warned as the expensive option since AI investigation of every candidate file can cost real money on a large repository. It asks before doing anything else so the rest of the run can proceed unattended.

When should I use Deepsec Vulnerability Scanner?

Deepsec Vulnerability Scanner fits situations like: scanning uncommitted changes for security vulnerabilities before a commit; checking a branch's diff to main for newly introduced vulnerabilities; running a full-codebase AI security review of legacy code; setting deepsec up for the first time in a repository.

How do I install Deepsec Vulnerability Scanner in Claude Code?

Run `npx skills add vercel-labs/deepsec --skill deepsec -a claude-code`. Or copy the skill folder (the vercel-labs/deepsec repository) into .claude/skills/deepsec in your project. Claude Code loads it when a task matches its description.

How do I install Deepsec Vulnerability Scanner in Codex?

Run `npx skills add vercel-labs/deepsec --skill deepsec -a codex`. Or copy the skill folder (the vercel-labs/deepsec repository) into .agents/skills/deepsec in your project. Codex loads it when a task matches its description.

Can I use Deepsec Vulnerability Scanner in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vercel-labs/deepsec --skill deepsec -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/deepsec, .gemini/skills/deepsec, .github/skills/deepsec and .opencode/skills/deepsec in your project.

What does Deepsec Vulnerability Scanner need to run?

Going by SKILL.md and its folder, Deepsec Vulnerability Scanner needs the command-line tools its instructions call (npx). Our summary lists: Node.js to run npx deepsec; An AI agent sandboxed enough to run security investigations.

Does Deepsec Vulnerability Scanner access the network?

SKILL.md contains no URLs. Its commands use npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Deepsec Vulnerability Scanner safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Deepsec Vulnerability Scanner use?

Deepsec Vulnerability Scanner is published under the Apache-2.0 licence (from the LICENSE file in the skill folder). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Deepsec Vulnerability Scanner use?

About 1.2k tokens (SKILL.md is roughly 5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Deepsec Vulnerability Scanner?

Skills that share tags, products or a category with Deepsec Vulnerability Scanner: Security Audit Scanner (ruvnet/ruflo, 74k stars), Native Dependency Update (mono/SkiaSharp, 5.6k stars), Security Audit (TheDecipherist/claude-code-mastery, 550 stars) and Fix Scan Finding (malloydata/publisher, 116 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Deepsec Vulnerability Scanner?

vercel-labs (a GitHub organization, an official publisher) maintains it in vercel-labs/deepsec, which has 8,115 GitHub stars. The repository holds 2 skills in this directory. The repository was last updated on September 29, 2026.

Source: vercel-labs/deepsec on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.