Official agent skill

Deepsec Documentation Guide

by vercel-labs in vercel-labs/deepsec

Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.

OfficialApache-2.0Auto-check passedSecurity

Install Deepsec Documentation Guide

skills CLI
$ npx skills add vercel-labs/deepsec --skill deepsec-docs -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install vercel-labs/deepsec deepsec-docs --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/vercel-labs/deepsec.git skills-src && mkdir -p .claude/skills && cp -r skills-src/packages/deepsec .claude/skills/deepsec-docs && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
deepsec-docs
GitHub stars
8.1k
Token cost
~956 tokens
SKILL.md length
405 words
Files
115
Skills in repo
2
Repo updated
First seen
Licence
Apache-2.0

At a glance

Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.

  • Initializing deepsec in a repository for the first time
  • SKILL.md covers Where the docs are, How to answer common questions and Agent-native initialization
  • Runs TypeScript and JavaScript scripts from its folder; calls npx
  • Resuming a deepsec setup that stopped part way

What it does

deepsec is an AI-powered vulnerability scanner, and this skill is installed by its one-shot initializer. Instead of answering from training data, the agent reads the relevant doc first: getting started, configuration, plugins, writing matchers, models, Vercel setup, architecture, data layout or the FAQ. Locations differ for the target repository, the isolated workspace and a source clone.

A question-to-doc map covers the common cases. Install or init questions go to getting started and default to npx deepsec init; resuming a stopped setup uses getting started plus data layout and rerunning init or deepsec setup; config questions use the configuration reference and a sample config; matcher and plugin questions use their guides and samples; model choice, project linking, Sandbox and credentials each have their own doc. The agent quotes the docs because flags, defaults and plugin field names change.

When your agent uses it

  • Initializing deepsec in a repository for the first time
  • Resuming a deepsec setup that stopped part way
  • Writing a custom matcher or plugin
  • Choosing a model or setting up credentials and Sandbox access

Example prompts

  • “How do I initialize deepsec in this repo?”
  • “Setup stopped halfway, so how do I resume it?”
  • “Show me how to write a hand-authored matcher for hardcoded API keys.”

Requirements

  • npx, to run deepsec init

What it can do on your machine

Read from SKILL.md and the folder at commit 4fa6722. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (TypeScript and JavaScript, from the files we listed), which the agent can run.

    Shell commands in SKILL.md call:

    • npx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npx, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Deepsec Documentation Guide loads about 956 tokens when it runs. Until then it costs about 71 tokens; SKILL.md has 405 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~71
When it runs · the whole SKILL.md, loaded when a task matches
~956

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from vercel-labs/deepsec at commit 4fa6722, republished under its Apache-2.0 licence (© vercel-labs). 405 words, ~956 tokens.

Download SKILL.mdSave it as .claude/skills/deepsec-docs/SKILL.md (or your agent's skills folder). This skill also uses 114 other files; get the full folder from GitHub.
name
deepsec-docs
description
Use deepsec (an AI-powered vulnerability scanner) — one-shot initialization, resumable setup, project/model credentials, scans, generated or hand-authored matchers, and plugins. Activates when the user asks how to initialize, scan, configure, resume, or extend deepsec.

deepsec

deepsec is an AI-powered vulnerability scanner. The one-shot initializer installs this skill at .deepsec/node_modules/deepsec/SKILL.md. From inside the isolated workspace the same path is node_modules/deepsec/SKILL.md. In a Deepsec source clone, use the repository's docs/ directory instead.

When the user asks how to use, configure, or extend deepsec, read the relevant doc before answering — the docs are the source of truth, not your training data.

Where the docs are

From the target repository, .deepsec/node_modules/deepsec/dist/docs/; from inside .deepsec, node_modules/deepsec/dist/docs/; or from a Deepsec source clone, <deepsec-clone>/docs/:

  • getting-started.md — one-shot initialization and resume walkthrough
  • configuration.md — full deepsec.config.ts reference
  • plugins.md — plugin slots (matchers, notifiers, ownership, people, executor)
  • writing-matchers.md — generated declarative vs hand-authored matchers
  • models.md — model selection, defaults, refusals, future models
  • vercel-setup.md — exact project link, Sandbox scope, Gateway/BYOK/custom routes
  • architecture.md — pipeline internals
  • data-layout.md — data/ schemas (FileRecord, RunMeta, …)
  • faq.md — cost, model choice, sandbox mode, FP rate

How to answer common questions

  • "How do I install/init deepsec?" → getting-started.md; default to npx deepsec init, not a manual install/scan recipe.
  • "Setup stopped; how do I resume?" → getting-started.md + data-layout.md; re-run init or deepsec setup.
  • "How do I run another scan?" → getting-started.md after noting the first scan/process already ran during setup.
  • "What goes in deepsec.config.ts?" → configuration.md + samples/webapp/deepsec.config.ts.
  • "Why did setup generate a matcher?" → writing-matchers.md + the project's generated-matchers.ts.
  • "How do I add a richer matcher?" → writing-matchers.md + samples/webapp/matchers/*.ts.
  • "How do I write a plugin?" → plugins.md + samples/webapp/deepsec.config.ts (inline plugin pattern).
  • "What does deepsec actually do?" → architecture.md.
  • "What's in data/<id>/files/foo.json?" → data-layout.md.
  • "Which model / agent should I use?" → models.md.
  • "How do project linking, Sandbox, or my own credentials work?" → vercel-setup.md.

Read the doc before paraphrasing. The CLI flag set, defaults, and plugin-contract field names change — quote the doc, don't recall.

Show full SKILL.md (132 more words)Show less

Agent-native initialization

When you are asked to initialize Deepsec from a non-TTY agent session, first inspect the read-only plan:

bash
npx deepsec init --plan --output json

Then run the requested policy, normally:

bash
npx deepsec init --yes --model-profile value --output jsonl

Parse every output line as JSON. On needs_input, show the supplied message and actions to the user rather than inventing remediation. In particular, VERCEL_AUTH_REQUIRED normally asks the user to run npx vercel login; after they do, follow the returned link action from inside .deepsec. Use npx vercel link when the user needs to choose, or the returned parameterized --yes --team <team-slug> --project <project-name> form for a known existing project. Then rerun the same Deepsec command. Exit code 2 means input is needed and exit code 3 means a requested cost/duration boundary stopped the resumable run. Never expose credential values, bypass --yes, or launch an interactive login yourself.

© vercel-labs, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 114 other files in packages/deepsec of vercel-labs/deepsec.

  • SKILL.md
  • .gitignore
  • build.mjs
  • package.json
  • src/__tests__/agent-config.test.ts
  • src/__tests__/agent-defaults.test.ts
  • src/__tests__/credential-brokering.test.ts
  • src/__tests__/ensure-connected-workspace.test.ts
  • src/__tests__/env-file.test.ts
  • src/__tests__/file-sources.test.ts
  • src/__tests__/formatters.test.ts
  • src/__tests__/merge-records.test.ts
  • src/__tests__/metrics.test.ts
  • src/__tests__/model-picker.test.ts
  • src/__tests__/model-route.test.ts
  • src/__tests__/network-policy.test.ts
  • src/__tests__/output-cap.test.ts
  • src/__tests__/pr-comment.test.ts
  • src/__tests__/preflight.test.ts
  • … and 96 more

Open the folder on GitHubat commit 4fa6722

Compare with similar skills

Deepsec Documentation Guide next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Deepsec Documentation Guide compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Deepsec Documentation Guide this skillvercel-labs/deepsec8.1k—~956Automated safety check: PassApache-2.0
Native Dependency Updatemono/SkiaSharp5.6k—~4.1kAutomated safety check: PassMIT
Security AuditTheDecipherist/claude-code-mastery550—~1.3kAutomated safety check: NotesMIT
Cyberowlaikarimhabush/cyberowl263—~2.5kAutomated safety check: PassMIT
Pre-Commit Security Scanzereight/gitlab-mcp2k1 repos~859Automated safety check: NotesMIT
CodeCrucible Security Scansblock/codecrucible117—~1.2kAutomated safety check: PassApache-2.0

Similar skills

  • Update native dependencies (libpng, libexpat, zlib, libwebp, harfbuzz, freetype, libjpeg-turbo, etc.) in SkiaSharp's Skia fork.

    5.6k GitHub stars~4.1k tokensUpdated today
    SecurityAuto-check passed
  • Security Audit

    TheDecipherist/claude-code-mastery

    Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.

    550 GitHub stars~1.3k tokensUpdated 5 mo ago
    SecurityAuto-check: notes
  • Cyberowlai

    karimhabush/cyberowl

    Check if recent cybersecurity alerts from 10 international CERTs affect your current project.

    263 GitHub stars~2.5k tokensUpdated today
    SecurityAuto-check passed
  • Pre-Commit Security Scan

    zereight/gitlab-mcp

    Runs a fast security sweep of recent code changes before a commit or PR, checking for leaked secrets, vulnerable dependencies, unsafe input handling and auth gaps.

    2k GitHub starsUsed in 1 repo~859 tokens
    SecurityAuto-check: notes
  • CodeCrucible Security Scans

    block/codecrucible

    Official

    Runs the codecrucible CLI for LLM-backed security scans of a repository, checks scope and cost first with a dry run, and reads the SARIF results.

    117 GitHub stars~1.2k tokensUpdated today
    SecurityAuto-check passed
  • Container Security Hardening

    sickn33/agentic-awesome-skills

    Harden Docker/container images and runtime deployments with secure base images, non-root users, CVE scanning, SBOM/signing, seccomp/AppArmor, and Kubernetes pod security controls.

    47k GitHub starsUsed in 1 repo~1k tokens
    SecurityAuto-check: notes

More from vercel-labs/deepsec

  • Official

    Runs deepsec's AI-powered security scan over a repository's uncommitted changes, its diff to main, or the whole codebase, using a regex pass followed by agent investigation.

    8.1k GitHub stars~1.2k tokensUpdated 8 days ago
    Auto-check passed

Works with

Categories

Questions about Deepsec Documentation Guide

What does Deepsec Documentation Guide do?

Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner. deepsec is an AI-powered vulnerability scanner, and this skill is installed by its one-shot initializer. Instead of answering from training data, the agent reads the relevant doc first: getting started, configuration, plugins, writing matchers, models, Vercel setup, architecture, data layout or the FAQ.

When should I use Deepsec Documentation Guide?

Deepsec Documentation Guide fits situations like: initializing deepsec in a repository for the first time; resuming a deepsec setup that stopped part way; writing a custom matcher or plugin; choosing a model or setting up credentials and Sandbox access.

How do I install Deepsec Documentation Guide in Claude Code?

Run `npx skills add vercel-labs/deepsec --skill deepsec-docs -a claude-code`. Or copy the skill folder (packages/deepsec in vercel-labs/deepsec) into .claude/skills/deepsec-docs in your project. Claude Code loads it when a task matches its description.

How do I install Deepsec Documentation Guide in Codex?

Run `npx skills add vercel-labs/deepsec --skill deepsec-docs -a codex`. Or copy the skill folder (packages/deepsec in vercel-labs/deepsec) into .agents/skills/deepsec-docs in your project. Codex loads it when a task matches its description.

Can I use Deepsec Documentation Guide in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vercel-labs/deepsec --skill deepsec-docs -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/deepsec-docs, .gemini/skills/deepsec-docs, .github/skills/deepsec-docs and .opencode/skills/deepsec-docs in your project.

What does Deepsec Documentation Guide need to run?

Going by SKILL.md and its folder, Deepsec Documentation Guide needs TypeScript and JavaScript for the scripts in its folder and the command-line tools its instructions call (npx). Our summary lists: npx, to run deepsec init.

Does Deepsec Documentation Guide access the network?

SKILL.md contains no URLs. Its commands use npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Deepsec Documentation Guide safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Deepsec Documentation Guide use?

Deepsec Documentation Guide is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Deepsec Documentation Guide use?

About 956 tokens (SKILL.md is roughly 3.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Deepsec Documentation Guide?

Skills that share tags, products or a category with Deepsec Documentation Guide: Native Dependency Update (mono/SkiaSharp, 5.6k stars), Security Audit (TheDecipherist/claude-code-mastery, 550 stars), Cyberowlai (karimhabush/cyberowl, 263 stars) and Pre-Commit Security Scan (zereight/gitlab-mcp, 2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Deepsec Documentation Guide?

vercel-labs (a GitHub organization, an official publisher) maintains it in vercel-labs/deepsec, which has 8,115 GitHub stars. The repository holds 2 skills in this directory. The repository was last updated on September 29, 2026.

Source: vercel-labs/deepsec on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.