Official agent skill

Deepsec

by vercel-labs in vercel-labs/dev3000

Run DeepSec against a Vercel project checkout from dev3000. An agent skill from vercel-labs/dev3000.

OfficialMITAuto-check: notesDocuments & Office

Install Deepsec

skills CLI
$ npx skills add vercel-labs/dev3000 --skill deepsec -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install vercel-labs/dev3000 deepsec --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/vercel-labs/dev3000.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/deepsec .claude/skills/deepsec && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
deepsec
GitHub stars
1.6k
Token cost
~985 tokens
SKILL.md length
507 words
Files
1
Skills in repo
3
Repo updated
First seen
Licence
MIT

At a glance

Run DeepSec against a Vercel project checkout from dev3000. An agent skill from vercel-labs/dev3000.

  • Works in 8 steps: Inspect the project shape → Initialize DeepSec if needed → Install DeepSec workspace dependencies → …
  • One-click DeepSec setup
  • SKILL.md covers Operating Policy, Default Flow and Validation
  • Calls npx, pnpm and git

What it does

Deepsec is an agent skill from vercel-labs/dev3000, published by the product's own GitHub organization. Run DeepSec against a Vercel project checkout from dev3000. Use for one-click DeepSec setup, project context bootstrapping, bounded first-pass processing, and report generation.

Its SKILL.md is about 990 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Documents & Office. It works with Vercel and pnpm. The repository describes itself as: Captures your web app's complete development timeline - server logs, browser events, console messages, network requests, and automatic screenshots - in a unified, timestamped… The licence is MIT.

When your agent uses it

  • One-click DeepSec setup
  • Project context bootstrapping
  • Bounded first-pass processing
  • Report generation

Example prompts

  • “/deepsec”

Requirements

  • Node.js

Workflow steps

8 steps, taken from the first numbered list in SKILL.md.

  1. Inspect the project shape
  2. Initialize DeepSec if needed
  3. Install DeepSec workspace dependencies
  4. Fill the generated project context
  5. Run the scan
  6. Run bounded AI processing
  7. Generate the findings report
  8. Summarize the run

What it can do on your machine

Read from SKILL.md and the folder at commit 3b945d7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npx
    • pnpm
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npx, pnpm and git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Deepsec loads about 985 tokens when it runs. Until then it costs about 46 tokens; SKILL.md has 507 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~46
When it runs · the whole SKILL.md, loaded when a task matches
~985

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:13
    not write AI credentials into `.deepsec/.env.local` or any tracked file. The dev3000 runtime passes AI Gateway credenti
  • NoteMentions a .env fileSKILL.md:57
    d make sure no secrets, `node_modules`, `.env.local`, or raw scan state are staged by accident.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from vercel-labs/dev3000 at commit 3b945d7, republished under its MIT licence (© vercel-labs). 507 words, ~985 tokens.

Download SKILL.mdSave it as .claude/skills/deepsec/SKILL.md (or your agent's skills folder).
name
deepsec
description
Run DeepSec against a Vercel project checkout from dev3000. Use for one-click DeepSec setup, project context bootstrapping, bounded first-pass processing, and report generation.

DeepSec Dev3000 Runbook

Use this skill to turn the manual DeepSec workflow into a repeatable dev3000 run against the current Vercel project checkout.

Operating Policy

  • Work from the real project checkout at /workspace/repo.
  • Do not write AI credentials into .deepsec/.env.local or any tracked file. The dev3000 runtime passes AI Gateway credentials through the process environment.
  • Default dev3000 runs are a bounded first pass. Do not run an unbounded process or revalidate command unless the user explicitly asks for a full DeepSec scan in run-specific instructions.
  • Keep generated scan state in the locations DeepSec already gitignores. Commit only the durable setup/context files and human-readable findings report.
  • Treat DeepSec as a coding agent with shell access. Do not run it on untrusted source inputs.

Default Flow

  1. Inspect the project shape:
    • Read README.md if present.
    • Read AGENTS.md or CLAUDE.md if present.
    • Skim representative files for auth, middleware, request handlers, data access, billing, webhooks, and security-sensitive boundaries.
  2. Initialize DeepSec if needed:
    • If .deepsec/ is absent, run npx --yes deepsec@latest init.
    • If .deepsec/ already exists, do not force overwrite it.
  3. Install DeepSec workspace dependencies:
    • Run corepack pnpm install from .deepsec/.
    • Ensure the Claude Agent SDK native binary that DeepSec actually uses is available. Do not run a Claude Code postinstall; DeepSec uses @anthropic-ai/claude-agent-sdk.
    • If corepack pnpm is unavailable, run pnpm install only after confirming pnpm exists.
  4. Fill the generated project context:
    • Read .deepsec/node_modules/deepsec/SKILL.md.
    • Read .deepsec/data/<id>/SETUP.md.
    • Replace .deepsec/data/<id>/INFO.md with concise project-specific context.
    • Keep INFO.md to roughly 50-100 lines.
    • Use 3-5 examples per section. Name local primitives such as auth helpers, middleware, database clients, webhook handlers, and privileged APIs.
    • Do not include line numbers, generic CWE lists, or broad framework summaries.
  5. Run the scan:
    • Run corepack pnpm deepsec scan from .deepsec/.
  6. Run bounded AI processing:
    • Default command: corepack pnpm deepsec process --limit 25 --concurrency 2 --batch-size 3.
    • If the candidate set is below the limit, state that all discovered candidates were processed.
    • If the user explicitly requested a full run, use the requested limit/concurrency or omit --limit.
    • If the process command fails, stop and report the failure. Do not generate a manual fallback report from regex candidates.
  7. Generate the findings report:
    • Run corepack pnpm deepsec export --format md-dir --out ./findings.
    • If there are no findings, create .deepsec/findings/README.md summarizing that this bounded pass found no findings and include the exact commands that were run.
  8. Summarize the run:
    • Include commands run, project id, limit/concurrency, and whether the report contains findings.
    • Do not include a "Next Steps - Full Scan" section by default.
    • Only include a follow-up scan section if DeepSec reports unprocessed candidates or the user explicitly asked about deeper coverage. Label it "Optional Deeper Follow-Up" and explain exactly how it differs from the completed run.
Show full SKILL.md (53 more words)Show less

Validation

  • Prefer DeepSec's own command output, corepack pnpm deepsec status, and generated finding files as validation.
  • Do not start a dev server or browser unless the user explicitly asks for visual/runtime verification.
  • Before finishing, check git diff --stat and make sure no secrets, node_modules, .env.local, or raw scan state are staged by accident.

© vercel-labs, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/deepsec of vercel-labs/dev3000.

Open the folder on GitHubat commit 3b945d7

Compare with similar skills

Deepsec next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Deepsec compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Deepsec this skillvercel-labs/dev30001.6k—~985Automated safety check: NotesMIT
Check Deps SyncHyk260/PureChat546—~594Automated safety check: PassMIT
Deploy Release Testvercel/next.js143k—~1.2kAutomated safety check: PassMIT
Pwa ReleaseAHS12/thoth-blueprint626—~505Automated safety check: PassGPL-3.0
Devops SpecialistCaoMeiYouRen/caomei-auth220—~446Automated safety check: NotesMIT
Upstream Syncevloghq/evlog1.9k—~856Automated safety check: PassMIT

Similar skills

  • Check Deps Sync

    Hyk260/PureChat

    Check if package.json files are in sync with pnpm-lock.yaml.

    546 GitHub stars~594 tokensUpdated 21 days ago
    DevOps & CloudAuto-check passed
  • Deploy Release Test

    vercel/next.js

    Official

    Validate a commit-specific Next.js preview package and manually trigger the entire Next.js deployment test suite through the teste2edeployrelease.yml GitHub Actions workflow.

    143k GitHub stars~1.2k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Pwa Release

    AHS12/thoth-blueprint

    Safely change Vite, service-worker, offline fallback, cache, Docker, Vercel, or release-distribution behavior.

    626 GitHub stars~505 tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Devops Specialist

    CaoMeiYouRen/caomei-auth

    修改 Docker、CI/CD、部署配置、环境变量、运行时参数、构建脚本和发布流程时使用。优先覆盖 Docker、Vercel、Cloudflare 与 GitHub Actions 场景。用户提到 deploy、Dockerfile、workflow、CI、CD、environment variables、build pipeline、release config 时都应触发。

    220 GitHub stars~446 tokensUpdated 7 days ago
    DevOps & CloudAuto-check: notes
  • Upstream Sync

    evloghq/evlog

    Check the eve and Vercel Connect ecosystem for updates and new features, keep the app current with them, and replace workarounds with the real improvements.

    1.9k GitHub stars~856 tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Slidev Migrate

    leochiu-a/slidev-workspace

    Migrate a single Slidev project into a Slidev workspace structure.

    171 GitHub stars~954 tokensUpdated 3 days ago
    Documents & OfficeAuto-check passed

More from vercel-labs/dev3000

  • Analyze Bundle

    vercel-labs/dev3000

    Official

    Convert Next.js bundle analyzer data to NDJSON and explore it

    1.6k GitHub stars~617 tokensUpdated today
    Auto-check passed
  • D3k

    vercel-labs/dev3000

    Official

    A skill your agent uses when the user asks to use d3k, run/dev/test/debug a web project with d3k, or reproduce a browser issue.

    1.6k GitHub stars~1.5k tokensUpdated today
    Auto-check: warnings

Works with

Questions about Deepsec

What does Deepsec do?

Run DeepSec against a Vercel project checkout from dev3000. An agent skill from vercel-labs/dev3000. Deepsec is an agent skill from vercel-labs/dev3000, published by the product's own GitHub organization. Run DeepSec against a Vercel project checkout from dev3000.

When should I use Deepsec?

Deepsec fits situations like: one-click DeepSec setup; project context bootstrapping; bounded first-pass processing; report generation.

How do I install Deepsec in Claude Code?

Run `npx skills add vercel-labs/dev3000 --skill deepsec -a claude-code`. Or copy the skill folder (.agents/skills/deepsec in vercel-labs/dev3000) into .claude/skills/deepsec in your project. Claude Code loads it when a task matches its description.

How do I install Deepsec in Codex?

Run `npx skills add vercel-labs/dev3000 --skill deepsec -a codex`. Or copy the skill folder (.agents/skills/deepsec in vercel-labs/dev3000) into .agents/skills/deepsec in your project. Codex loads it when a task matches its description.

Can I use Deepsec in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vercel-labs/dev3000 --skill deepsec -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/deepsec, .gemini/skills/deepsec, .github/skills/deepsec and .opencode/skills/deepsec in your project.

What does Deepsec need to run?

Going by SKILL.md and its folder, Deepsec needs the command-line tools its instructions call (npx, pnpm and git). Our summary lists: Node.js.

Does Deepsec access the network?

SKILL.md contains no URLs. Its commands use npx and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Deepsec safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Deepsec use?

Deepsec is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Deepsec use?

About 985 tokens (SKILL.md is roughly 3.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Deepsec?

Skills that share tags, products or a category with Deepsec: Check Deps Sync (Hyk260/PureChat, 546 stars), Deploy Release Test (vercel/next.js, 143k stars), Pwa Release (AHS12/thoth-blueprint, 626 stars) and Devops Specialist (CaoMeiYouRen/caomei-auth, 220 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Deepsec?

vercel-labs (a GitHub organization, an official publisher) maintains it in vercel-labs/dev3000, which has 1,582 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on October 7, 2026.

Source: vercel-labs/dev3000 on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.