Native Dependency Update
mono/SkiaSharp
Update native dependencies (libpng, libexpat, zlib, libwebp, harfbuzz, freetype, libjpeg-turbo, etc.) in SkiaSharp's Skia fork.
Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.
$ npx skills add vercel-labs/deepsec --skill deepsec-docs -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install vercel-labs/deepsec deepsec-docs --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/vercel-labs/deepsec.git skills-src && mkdir -p .claude/skills && cp -r skills-src/packages/deepsec .claude/skills/deepsec-docs && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "deepsec-docs" agent skill from https://github.com/vercel-labs/deepsec/tree/main/packages/deepsec into .claude/skills/deepsec-docs/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "deepsec-docs", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/vercel-labs/deepsec/tree/main/packages/deepsecType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add vercel-labs/deepsec --skill deepsec-docs -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install vercel-labs/deepsec deepsec-docs --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/vercel-labs/deepsec.git skills-src && mkdir -p .agents/skills && cp -r skills-src/packages/deepsec .agents/skills/deepsec-docs && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "deepsec-docs" agent skill from https://github.com/vercel-labs/deepsec/tree/main/packages/deepsec into .agents/skills/deepsec-docs/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "deepsec-docs", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add vercel-labs/deepsec --skill deepsec-docs -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install vercel-labs/deepsec deepsec-docs --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/vercel-labs/deepsec.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/packages/deepsec .cursor/skills/deepsec-docs && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "deepsec-docs" agent skill from https://github.com/vercel-labs/deepsec/tree/main/packages/deepsec into .cursor/skills/deepsec-docs/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "deepsec-docs", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/vercel-labs/deepsec.git --path packages/deepsec--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add vercel-labs/deepsec --skill deepsec-docs -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install vercel-labs/deepsec deepsec-docs --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/vercel-labs/deepsec.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/packages/deepsec .gemini/skills/deepsec-docs && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "deepsec-docs" agent skill from https://github.com/vercel-labs/deepsec/tree/main/packages/deepsec into .gemini/skills/deepsec-docs/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "deepsec-docs", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install vercel-labs/deepsec deepsec-docsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add vercel-labs/deepsec --skill deepsec-docs -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/vercel-labs/deepsec.git skills-src && mkdir -p .github/skills && cp -r skills-src/packages/deepsec .github/skills/deepsec-docs && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "deepsec-docs" agent skill from https://github.com/vercel-labs/deepsec/tree/main/packages/deepsec into .github/skills/deepsec-docs/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "deepsec-docs", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add vercel-labs/deepsec --skill deepsec-docs -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install vercel-labs/deepsec deepsec-docs --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/vercel-labs/deepsec.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/packages/deepsec .opencode/skills/deepsec-docs && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "deepsec-docs" agent skill from https://github.com/vercel-labs/deepsec/tree/main/packages/deepsec into .opencode/skills/deepsec-docs/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "deepsec-docs", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
deepsec-docsPoints the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.
deepsec is an AI-powered vulnerability scanner, and this skill is installed by its one-shot initializer. Instead of answering from training data, the agent reads the relevant doc first: getting started, configuration, plugins, writing matchers, models, Vercel setup, architecture, data layout or the FAQ. Locations differ for the target repository, the isolated workspace and a source clone.
A question-to-doc map covers the common cases. Install or init questions go to getting started and default to npx deepsec init; resuming a stopped setup uses getting started plus data layout and rerunning init or deepsec setup; config questions use the configuration reference and a sample config; matcher and plugin questions use their guides and samples; model choice, project linking, Sandbox and credentials each have their own doc. The agent quotes the docs because flags, defaults and plugin field names change.
Read from SKILL.md and the folder at commit 4fa6722. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships script files (TypeScript and JavaScript, from the files we listed), which the agent can run.
Shell commands in SKILL.md call:
npxFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npx, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Deepsec Documentation Guide loads about 956 tokens when it runs. Until then it costs about 71 tokens; SKILL.md has 405 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from vercel-labs/deepsec at commit 4fa6722, republished under its Apache-2.0 licence (© vercel-labs). 405 words, ~956 tokens.
.claude/skills/deepsec-docs/SKILL.md (or your agent's skills folder). This skill also uses 114 other files; get the full folder from GitHub.deepsec is an AI-powered vulnerability scanner. The one-shot initializer
installs this skill at .deepsec/node_modules/deepsec/SKILL.md. From inside
the isolated workspace the same path is node_modules/deepsec/SKILL.md. In a
Deepsec source clone, use the repository's docs/ directory instead.
When the user asks how to use, configure, or extend deepsec, read the relevant doc before answering — the docs are the source of truth, not your training data.
From the target repository, .deepsec/node_modules/deepsec/dist/docs/; from
inside .deepsec, node_modules/deepsec/dist/docs/; or from a Deepsec source
clone, <deepsec-clone>/docs/:
getting-started.md — one-shot initialization and resume walkthroughconfiguration.md — full deepsec.config.ts referenceplugins.md — plugin slots (matchers, notifiers, ownership, people, executor)writing-matchers.md — generated declarative vs hand-authored matchersmodels.md — model selection, defaults, refusals, future modelsvercel-setup.md — exact project link, Sandbox scope, Gateway/BYOK/custom routesarchitecture.md — pipeline internalsdata-layout.md — data/ schemas (FileRecord, RunMeta, …)faq.md — cost, model choice, sandbox mode, FP rategetting-started.md; default to npx deepsec init, not a manual install/scan recipe.getting-started.md + data-layout.md; re-run init or deepsec setup.getting-started.md after noting the first scan/process already ran during setup.deepsec.config.ts?" → configuration.md + samples/webapp/deepsec.config.ts.writing-matchers.md + the project's generated-matchers.ts.writing-matchers.md + samples/webapp/matchers/*.ts.plugins.md + samples/webapp/deepsec.config.ts (inline plugin pattern).architecture.md.data/<id>/files/foo.json?" → data-layout.md.models.md.vercel-setup.md.Read the doc before paraphrasing. The CLI flag set, defaults, and plugin-contract field names change — quote the doc, don't recall.
When you are asked to initialize Deepsec from a non-TTY agent session, first inspect the read-only plan:
npx deepsec init --plan --output jsonThen run the requested policy, normally:
npx deepsec init --yes --model-profile value --output jsonlParse every output line as JSON. On needs_input, show the supplied message
and actions to the user rather than inventing remediation. In particular,
VERCEL_AUTH_REQUIRED normally asks the user to run npx vercel login; after
they do, follow the returned link action from inside .deepsec. Use
npx vercel link when the user needs to choose, or the returned parameterized
--yes --team <team-slug> --project <project-name> form for a known existing
project. Then rerun the same Deepsec command. Exit code 2 means input is needed
and exit code 3 means a requested cost/duration boundary stopped the resumable
run. Never expose credential values, bypass --yes, or launch an interactive
login yourself.
© vercel-labs, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 114 other files in packages/deepsec of vercel-labs/deepsec.
Open the folder on GitHubat commit 4fa6722
Deepsec Documentation Guide next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Deepsec Documentation Guide this skillvercel-labs/deepsec | 8.1k | — | ~956 | Automated safety check: Pass | Apache-2.0 | |
| Native Dependency Updatemono/SkiaSharp | 5.6k | — | ~4.1k | Automated safety check: Pass | MIT | |
| Security AuditTheDecipherist/claude-code-mastery | 550 | — | ~1.3k | Automated safety check: Notes | MIT | |
| Cyberowlaikarimhabush/cyberowl | 263 | — | ~2.5k | Automated safety check: Pass | MIT | |
| Pre-Commit Security Scanzereight/gitlab-mcp | 2k | 1 repos | ~859 | Automated safety check: Notes | MIT | |
| CodeCrucible Security Scansblock/codecrucible | 117 | — | ~1.2k | Automated safety check: Pass | Apache-2.0 |
mono/SkiaSharp
Update native dependencies (libpng, libexpat, zlib, libwebp, harfbuzz, freetype, libjpeg-turbo, etc.) in SkiaSharp's Skia fork.
TheDecipherist/claude-code-mastery
Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.
karimhabush/cyberowl
Check if recent cybersecurity alerts from 10 international CERTs affect your current project.
zereight/gitlab-mcp
Runs a fast security sweep of recent code changes before a commit or PR, checking for leaked secrets, vulnerable dependencies, unsafe input handling and auth gaps.
block/codecrucible
Runs the codecrucible CLI for LLM-backed security scans of a repository, checks scope and cost first with a dry run, and reads the SARIF results.
sickn33/agentic-awesome-skills
Harden Docker/container images and runtime deployments with secure base images, non-root users, CVE scanning, SBOM/signing, seccomp/AppArmor, and Kubernetes pod security controls.
vercel-labs/deepsec
Runs deepsec's AI-powered security scan over a repository's uncommitted changes, its diff to main, or the whole codebase, using a regex pass followed by agent investigation.
Works with
Categories
Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner. deepsec is an AI-powered vulnerability scanner, and this skill is installed by its one-shot initializer. Instead of answering from training data, the agent reads the relevant doc first: getting started, configuration, plugins, writing matchers, models, Vercel setup, architecture, data layout or the FAQ.
Deepsec Documentation Guide fits situations like: initializing deepsec in a repository for the first time; resuming a deepsec setup that stopped part way; writing a custom matcher or plugin; choosing a model or setting up credentials and Sandbox access.
Run `npx skills add vercel-labs/deepsec --skill deepsec-docs -a claude-code`. Or copy the skill folder (packages/deepsec in vercel-labs/deepsec) into .claude/skills/deepsec-docs in your project. Claude Code loads it when a task matches its description.
Run `npx skills add vercel-labs/deepsec --skill deepsec-docs -a codex`. Or copy the skill folder (packages/deepsec in vercel-labs/deepsec) into .agents/skills/deepsec-docs in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vercel-labs/deepsec --skill deepsec-docs -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/deepsec-docs, .gemini/skills/deepsec-docs, .github/skills/deepsec-docs and .opencode/skills/deepsec-docs in your project.
Going by SKILL.md and its folder, Deepsec Documentation Guide needs TypeScript and JavaScript for the scripts in its folder and the command-line tools its instructions call (npx). Our summary lists: npx, to run deepsec init.
SKILL.md contains no URLs. Its commands use npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Deepsec Documentation Guide is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 956 tokens (SKILL.md is roughly 3.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Deepsec Documentation Guide: Native Dependency Update (mono/SkiaSharp, 5.6k stars), Security Audit (TheDecipherist/claude-code-mastery, 550 stars), Cyberowlai (karimhabush/cyberowl, 263 stars) and Pre-Commit Security Scan (zereight/gitlab-mcp, 2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
vercel-labs (a GitHub organization, an official publisher) maintains it in vercel-labs/deepsec, which has 8,115 GitHub stars. The repository holds 2 skills in this directory. The repository was last updated on September 29, 2026.
Source: vercel-labs/deepsec on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.