
Deepsec
- 99 installs
- 1.6k repo stars
- Updated July 9, 2026
- vercel-labs/dev3000
dev3000 skill running DeepSec scans on Vercel project checkouts with report generation.
About
dev3000 DeepSec integration skill for running security scans against Vercel project checkouts. Provides one-click DeepSec setup, project context bootstrapping from dev3000 workspace, bounded first-pass processing to control scan scope, and report generation for findings review. Distinct from the standalone deepsec skill by focusing on dev3000 project checkout integration rather than general deepsec node_modules configuration.
- DeepSec scan against Vercel project checkout from dev3000
- One-click DeepSec setup and project context bootstrapping
- Bounded first-pass processing for controlled scan scope
- Report generation for security findings review
- dev3000-specific integration not general deepsec config
Deepsec by the numbers
- 99 all-time installs (skills.sh)
- Ranked #1,003 of 2,209 Security skills by installs in the Skillselion catalog
- Security screen: LOW risk (skills.sh audit)
- Data as of Jul 28, 2026 (Skillselion catalog sync)
deepsec capabilities & compatibility
- Capabilities
- setup deepsec · bootstrap project context · generate security report
- Works with
- vercel
- Use cases
- security audit · testing
- Runs
- Runs locally
What deepsec says it does
Run DeepSec against a Vercel project checkout from dev3000.
npx skills add https://github.com/vercel-labs/dev3000 --skill deepsecAdd your badge
Show developers this skill is listed on Skillselion. Paste this into your README.
| Installs | 99 |
|---|---|
| repo stars | ★ 1.6k |
| Security audit | 3 / 3 scanners passed |
| Last updated | July 9, 2026 |
| Repository | vercel-labs/dev3000 ↗ |
How do I run DeepSec on my dev3000 Vercel project checkout?
Run DeepSec against a Vercel project checkout from dev3000 with one-click setup, bounded first-pass processing, and report generation.
Who is it for?
dev3000 users running security scans on Vercel project workspaces.
Skip if: Standalone deepsec node_modules configuration outside dev3000.
When should I use this skill?
User wants DeepSec setup or scan from dev3000 project context.
What you get
DeepSec scan completed with bounded processing and security report generated.
Files
DeepSec Dev3000 Runbook
Use this skill to turn the manual DeepSec workflow into a repeatable dev3000 run against the current Vercel project checkout.
Operating Policy
- Work from the real project checkout at
/workspace/repo. - Do not write AI credentials into
.deepsec/.env.localor any tracked file. The dev3000 runtime passes AI Gateway credentials through the process environment. - Default dev3000 runs are a bounded first pass. Do not run an unbounded
processorrevalidatecommand unless the user explicitly asks for a full DeepSec scan in run-specific instructions. - Keep generated scan state in the locations DeepSec already gitignores. Commit only the durable setup/context files and human-readable findings report.
- Treat DeepSec as a coding agent with shell access. Do not run it on untrusted source inputs.
Default Flow
1. Inspect the project shape:
- Read
README.mdif present. - Read
AGENTS.mdorCLAUDE.mdif present. - Skim representative files for auth, middleware, request handlers, data access, billing, webhooks, and security-sensitive boundaries.
2. Initialize DeepSec if needed:
- If
.deepsec/is absent, runnpx --yes deepsec@latest init. - If
.deepsec/already exists, do not force overwrite it.
3. Install DeepSec workspace dependencies:
- Run
corepack pnpm installfrom.deepsec/. - Ensure the Claude Agent SDK native binary that DeepSec actually uses is available. Do not run a Claude Code postinstall; DeepSec uses
@anthropic-ai/claude-agent-sdk. - If
corepack pnpmis unavailable, runpnpm installonly after confirmingpnpmexists.
4. Fill the generated project context:
- Read
.deepsec/node_modules/deepsec/SKILL.md. - Read
.deepsec/data/<id>/SETUP.md. - Replace
.deepsec/data/<id>/INFO.mdwith concise project-specific context. - Keep
INFO.mdto roughly 50-100 lines. - Use 3-5 examples per section. Name local primitives such as auth helpers, middleware, database clients, webhook handlers, and privileged APIs.
- Do not include line numbers, generic CWE lists, or broad framework summaries.
5. Run the scan:
- Run
corepack pnpm deepsec scanfrom.deepsec/.
6. Run bounded AI processing:
- Default command:
corepack pnpm deepsec process --limit 25 --concurrency 2 --batch-size 3. - If the candidate set is below the limit, state that all discovered candidates were processed.
- If the user explicitly requested a full run, use the requested limit/concurrency or omit
--limit. - If the process command fails, stop and report the failure. Do not generate a manual fallback report from regex candidates.
7. Generate the findings report:
- Run
corepack pnpm deepsec export --format md-dir --out ./findings. - If there are no findings, create
.deepsec/findings/README.mdsummarizing that this bounded pass found no findings and include the exact commands that were run.
8. Summarize the run:
- Include commands run, project id, limit/concurrency, and whether the report contains findings.
- Do not include a "Next Steps - Full Scan" section by default.
- Only include a follow-up scan section if DeepSec reports unprocessed candidates or the user explicitly asked about deeper coverage. Label it "Optional Deeper Follow-Up" and explain exactly how it differs from the completed run.
Validation
- Prefer DeepSec's own command output,
corepack pnpm deepsec status, and generated finding files as validation. - Do not start a dev server or browser unless the user explicitly asks for visual/runtime verification.
- Before finishing, check
git diff --statand make sure no secrets,node_modules,.env.local, or raw scan state are staged by accident.
Related skills
FAQ
How is this different from deepsec skill?
This integrates DeepSec with dev3000 Vercel project checkouts; deepsec skill covers general configuration.
What is bounded first-pass?
Controlled scan scope for initial processing before full repository analysis.
What output is produced?
Security report generation from DeepSec scan results.
Is Deepsec safe to install?
skills.sh reports 3 of 3 security scanners passed. Review the Security Audits panel on this page before installing in production.