Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
vercel-labs avatar

Deepsec

  • 99 installs
  • 1.6k repo stars
  • Updated July 9, 2026
  • vercel-labs/dev3000

dev3000 skill running DeepSec scans on Vercel project checkouts with report generation.

About

dev3000 DeepSec integration skill for running security scans against Vercel project checkouts. Provides one-click DeepSec setup, project context bootstrapping from dev3000 workspace, bounded first-pass processing to control scan scope, and report generation for findings review. Distinct from the standalone deepsec skill by focusing on dev3000 project checkout integration rather than general deepsec node_modules configuration.

  • DeepSec scan against Vercel project checkout from dev3000
  • One-click DeepSec setup and project context bootstrapping
  • Bounded first-pass processing for controlled scan scope
  • Report generation for security findings review
  • dev3000-specific integration not general deepsec config

Deepsec by the numbers

  • 99 all-time installs (skills.sh)
  • Ranked #1,003 of 2,209 Security skills by installs in the Skillselion catalog
  • Security screen: LOW risk (skills.sh audit)
  • Data as of Jul 28, 2026 (Skillselion catalog sync)
At a glance

deepsec capabilities & compatibility

Capabilities
setup deepsec · bootstrap project context · generate security report
Works with
vercel
Use cases
security audit · testing
Runs
Runs locally
From the docs

What deepsec says it does

Run DeepSec against a Vercel project checkout from dev3000.
SKILL.md
npx skills add https://github.com/vercel-labs/dev3000 --skill deepsec

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs99
repo stars1.6k
Security audit3 / 3 scanners passed
Last updatedJuly 9, 2026
Repositoryvercel-labs/dev3000

How do I run DeepSec on my dev3000 Vercel project checkout?

Run DeepSec against a Vercel project checkout from dev3000 with one-click setup, bounded first-pass processing, and report generation.

Who is it for?

dev3000 users running security scans on Vercel project workspaces.

Skip if: Standalone deepsec node_modules configuration outside dev3000.

When should I use this skill?

User wants DeepSec setup or scan from dev3000 project context.

What you get

DeepSec scan completed with bounded processing and security report generated.

Files

SKILL.mdMarkdownGitHub ↗

DeepSec Dev3000 Runbook

Use this skill to turn the manual DeepSec workflow into a repeatable dev3000 run against the current Vercel project checkout.

Operating Policy

  • Work from the real project checkout at /workspace/repo.
  • Do not write AI credentials into .deepsec/.env.local or any tracked file. The dev3000 runtime passes AI Gateway credentials through the process environment.
  • Default dev3000 runs are a bounded first pass. Do not run an unbounded process or revalidate command unless the user explicitly asks for a full DeepSec scan in run-specific instructions.
  • Keep generated scan state in the locations DeepSec already gitignores. Commit only the durable setup/context files and human-readable findings report.
  • Treat DeepSec as a coding agent with shell access. Do not run it on untrusted source inputs.

Default Flow

1. Inspect the project shape:

  • Read README.md if present.
  • Read AGENTS.md or CLAUDE.md if present.
  • Skim representative files for auth, middleware, request handlers, data access, billing, webhooks, and security-sensitive boundaries.

2. Initialize DeepSec if needed:

  • If .deepsec/ is absent, run npx --yes deepsec@latest init.
  • If .deepsec/ already exists, do not force overwrite it.

3. Install DeepSec workspace dependencies:

  • Run corepack pnpm install from .deepsec/.
  • Ensure the Claude Agent SDK native binary that DeepSec actually uses is available. Do not run a Claude Code postinstall; DeepSec uses @anthropic-ai/claude-agent-sdk.
  • If corepack pnpm is unavailable, run pnpm install only after confirming pnpm exists.

4. Fill the generated project context:

  • Read .deepsec/node_modules/deepsec/SKILL.md.
  • Read .deepsec/data/<id>/SETUP.md.
  • Replace .deepsec/data/<id>/INFO.md with concise project-specific context.
  • Keep INFO.md to roughly 50-100 lines.
  • Use 3-5 examples per section. Name local primitives such as auth helpers, middleware, database clients, webhook handlers, and privileged APIs.
  • Do not include line numbers, generic CWE lists, or broad framework summaries.

5. Run the scan:

  • Run corepack pnpm deepsec scan from .deepsec/.

6. Run bounded AI processing:

  • Default command: corepack pnpm deepsec process --limit 25 --concurrency 2 --batch-size 3.
  • If the candidate set is below the limit, state that all discovered candidates were processed.
  • If the user explicitly requested a full run, use the requested limit/concurrency or omit --limit.
  • If the process command fails, stop and report the failure. Do not generate a manual fallback report from regex candidates.

7. Generate the findings report:

  • Run corepack pnpm deepsec export --format md-dir --out ./findings.
  • If there are no findings, create .deepsec/findings/README.md summarizing that this bounded pass found no findings and include the exact commands that were run.

8. Summarize the run:

  • Include commands run, project id, limit/concurrency, and whether the report contains findings.
  • Do not include a "Next Steps - Full Scan" section by default.
  • Only include a follow-up scan section if DeepSec reports unprocessed candidates or the user explicitly asked about deeper coverage. Label it "Optional Deeper Follow-Up" and explain exactly how it differs from the completed run.

Validation

  • Prefer DeepSec's own command output, corepack pnpm deepsec status, and generated finding files as validation.
  • Do not start a dev server or browser unless the user explicitly asks for visual/runtime verification.
  • Before finishing, check git diff --stat and make sure no secrets, node_modules, .env.local, or raw scan state are staged by accident.

Related skills

FAQ

How is this different from deepsec skill?

This integrates DeepSec with dev3000 Vercel project checkouts; deepsec skill covers general configuration.

What is bounded first-pass?

Controlled scan scope for initial processing before full repository analysis.

What output is produced?

Security report generation from DeepSec scan results.

Is Deepsec safe to install?

skills.sh reports 3 of 3 security scanners passed. Review the Security Audits panel on this page before installing in production.

Securityauditappsec

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.