RepoDaily · 2026-08-15 · Security tool

deepsec: Vercel Labs' agent-powered vulnerability scanner that runs on your own infrastructure

#6 Security tool TypeScript +783 vercel-labs/deepsec Open repository

deepsec from Vercel Labs aims AI agents at whole codebases to surface long-hidden bugs, with a free pattern scan, resumable runs, and hard cost caps. What the docs show before you spend model tokens.

Repo typeSecurity tool
Best forSecurity and platform engineers auditing large existing repositories who can budget model spend and want findings as reviewable markdown files
Risk levelMedium: free to set up, but full-repo AI review can cost thousands to tens of thousands of dollars
Time to evaluateHalf a day to a day: run `npx deepsec init` with `--max-cost-usd` and `--max-duration` caps, inspect the free scan stage, then authorize one capped paid pass

Primary question: Do the findings from a capped first run justify the model spend for your repo, and does `revalidate` keep the false-positive rate low enough to act on?

91/100

RepoDaily adoption score

RepoDaily rates this as 91/100 (strong) for adoption: evidence, installation path, production risk, differentiation, license clarity, and AI/agent fit are scored from the article sources and adoption notes.

Directional score from RepoDaily sources and adoption notes, not a benchmark.Risk: Medium
100Evidence quality

6 source(s) across 4 source category/categories, plus a RepoDaily-specific evidence module when available.

100Installability

6 workflow step(s), 5 next-action step(s), and 5 command/install signal(s) were detected.

66Maintenance confidence

Trending momentum is +783 stars, with maintenance/release/issue signals counted when present.

96Production readiness

Risk is marked medium, with 6 security note(s) and 5 explicit skip condition(s).

100Differentiation

3 opportunity lens item(s), 5 alternative(s), and 2 type-specific section(s) support differentiation.

82License clarity

License source or license wording is present.

78Agent / AI fit

5 AI/agent-related signal(s) were detected in the article text and metadata.

Project overview

deepsec is an agent-powered vulnerability scanner from Vercel Labs that you run inside your own infrastructure. Written in TypeScript and shipped under Apache-2.0, it is built for one specific job: on-demand review of all code in existing large-scale repositories, with a stated focus on surfacing hard-to-find issues that have been lurking in applications for a long time. The tool earned 783 stars during this trending period at rank 6, and its entire footprint in your repository is a single `.deepsec/` folder that holds state, configuration, and findings.

The design splits work into a cheap stage and an expensive one. A fast pattern scan runs locally and costs nothing, producing candidate files; the `process` stage then hands those candidates to an AI review running the best models at maximum thinking levels, tunable through the `--thinking-level` flag documented in the models guide. Setup asks exactly two questions: which model, shown with its DeepSecBench benchmark score and cost relative to the cheapest option, and how to pay — the default Vercel AI Gateway, your own OpenAI or Anthropic key, or an already-logged-in claude or codex CLI via `--model-auth local`.

The README is unusually blunt about money: scans can cost thousands or even tens of thousands of dollars for large codebases, and the project says customers found that worth it for how quickly long-standing vulnerabilities got patched. Every runaway risk has a control — `npx deepsec init --max-cost-usd 100 --max-duration 2h` stops at a safe point, and re-running the same command resumes exactly where the run stopped, skipping files already analyzed. For large repositories, work fans out across worker machines in parallel.

Internals are visible rather than hidden. CONTRIBUTING.md documents a four-package monorepo — core types and plugin contracts, a regex-matcher scanner engine, a processor wired to the Claude and Codex SDKs, and the publishable CLI with a `@vercel/sandbox` executor — plus end-to-end tests against an intentionally vulnerable fixture app. New matchers and plugins are called out as the most useful contributions, and vulnerabilities in the tool itself have a published disclosure address at [email protected].

Problem it solves

  • Large, long-lived codebases carry vulnerabilities nobody has re-reviewed, because manual line-by-line audits do not scale to whole repositories
  • Rule-based SAST floods reviewers with candidates; deepsec ships a `revalidate` stage precisely because raw findings carry false positives
  • Whole-repo AI review is expensive and slow — minutes to many hours per the getting-started guide — so runs need cost caps, duration caps, and resumption
  • Sending an entire codebase out for review raises trust questions: where the code goes, which credentials get stored, and what gets committed to the repo
  • Organizations have internal risk patterns — specific helper names, internal package imports — that generic scanners never flag

How it works

  1. `npx deepsec init` from the repository root asks two questions: which model (each option shown with its DeepSecBench score and cost relative to the cheapest), and how to pay for calls
  2. The tool creates a `.deepsec/` folder — the only thing it adds to your repository — studies the codebase for risky areas, runs the free pattern scan, then starts the AI review of flagged files
  3. The `process` stage runs AI review at high thinking levels, tunable via `--thinking-level`; for large codebases, work fans out across worker machines in parallel
  4. If a run stops — Ctrl-C, a lost connection, a spending limit, or provider credits running out — re-running the same command resumes where it stopped, skipping files already analyzed
  5. `pnpm deepsec revalidate` re-checks findings to cut the false-positive rate before anyone acts on them
  6. `pnpm deepsec export --format md-dir --out ./findings` writes one markdown file per finding; `pnpm deepsec report` gives a quick overview

Command surface: every flag the docs expose

  • `npx deepsec init` — guided setup and first full run; safe to re-run, resumes interrupted work
  • `npx deepsec init --max-cost-usd 100 --max-duration 2h` — cap spend and wall-clock time; duration units must be `ms`, `s`, `m`, or `h`
  • `pnpm deepsec scan` — free local pattern scan with no AI calls; `pnpm deepsec process` — the expensive AI review of new or changed candidates
  • `pnpm deepsec status` and `pnpm deepsec report` — progress and overview; `pnpm deepsec export --format md-dir --out ./findings` — one markdown file per finding
  • Model access flags: `--agent codex` or `--agent claude`, `--ai-provider openai|anthropic`, `--model-auth direct` with `--ai-api-key-env MY_OPENAI_KEY`, or `--model-auth local` for an already-logged-in CLI
  • `--thinking-level` tunes reasoning depth, per the models doc linked from the README
  • Matcher testing: `pnpm deepsec scan --project-id <id> --root <path> --matchers <slug>` to check candidate counts for a new matcher
  • On-disk docs for coding agents: `.deepsec/node_modules/deepsec/SKILL.md` and `.deepsec/node_modules/deepsec/dist/docs/`, exposed as absolute machine-readable paths on setup errors

Architecture read: a four-package TypeScript monorepo

  • `packages/core` — types, schemas, plugin contracts, and the config loader
  • `packages/scanner` — regex matchers plus the scanning engine; matchers are `MatcherPlugin` exports registered in `matchers/index.ts`
  • `packages/processor` — AI agent integration via the Claude SDK and Codex SDK, plus enrich, triage, and revalidate stages
  • `packages/deepsec` — the publishable package: bundled CLI, the `deepsec/config` sub-export, and the `@vercel/sandbox` executor
  • `e2e/` runs against a fixture project; `fixtures/vulnerable-app` holds intentionally vulnerable test data excluded from lint and knip
  • Distribution bundles via esbuild into `packages/deepsec/dist/{cli,config}.mjs`; PRs touching the publish surface must also pass `pnpm test:bundle`
  • `e2e/pipeline-sandbox.test.ts` exercises bootstrap, worker spawn, file upload/download, and result merge against a real Vercel Sandbox using a stub agent — no model tokens spent, gated on `DEEPSEC_E2E_LIVE_SANDBOX=1`

The cost model is the real interface

deepsec treats price as a first-class design constraint rather than fine print. The README warns that large-codebase scans can reach thousands or tens of thousands of dollars; the init model picker therefore shows each option's DeepSecBench score next to its cost relative to the cheapest choice, and `--max-cost-usd` with `--max-duration` stops a run at a safe point that resumes later. The free `scan` stage doubles as a sizing tool: it reveals how many candidates the paid `process` stage would review before a single token is spent. Even the project's own CI economizes — its live-sandbox end-to-end test runs the full pipeline with a stub agent specifically so no model tokens are consumed.

Payment routing has three paths. The default sends model calls through Vercel AI Gateway, which logs you into Vercel and creates a small dedicated project to hold credentials, with nothing billable created during setup. Alternatively, you bring your own OpenAI or Anthropic key with `--model-auth direct`; deepsec persists only the environment variable name, never the key itself, reading the value from the environment or `.deepsec/.env.local`. The third path, `--model-auth local`, leans on an already-logged-in claude or codex CLI and configures no API key, gateway token, or environment variables at all.

Extensibility: matchers and plugins are the contribution path

  • CONTRIBUTING.md names new matchers and new plugins as the most useful contributions, with dedicated guides at `docs/writing-matchers.md` and `docs/plugins.md`
  • Adding a matcher: create `packages/scanner/src/matchers/<slug>.ts` exporting a `MatcherPlugin`, register it in `matchers/index.ts`, then verify candidate counts via `pnpm deepsec scan --matchers <slug>`
  • Matchers that only make sense for one organization — specific helper names, internal package imports — belong in a plugin rather than upstream
  • `samples/` ships copy-paste starting points; `docs/configuration.md` covers configuration and `docs/plugins.md` is the plugin authoring reference
  • Build, test, lint, and knip must all pass before a PR is mergeable, keeping matcher and plugin contributions cheap to review

Trust boundaries: license, disclosure, and data placement

  • Apache-2.0, including the explicit patent grant, per the LICENSE file
  • Vulnerabilities in deepsec itself are reported to [email protected] per SECURITY.md, with a commitment to investigate legitimate reports
  • The only artifact added to a scanned repository is the `.deepsec/` folder, which holds state and findings
  • With direct API keys, deepsec stores the environment variable name only — never the key — and reads values from the environment or `.deepsec/.env.local`
  • Default Vercel AI Gateway routing creates a small dedicated credentials project at setup; the docs state nothing billable is created during that step

Who should pay attention?

Good fit if

  • Existing large repositories with years of un-reviewed code, where surfacing long-lurking issues is the actual goal
  • Organizations that already hold OpenAI or Anthropic API keys, or have claude/codex CLIs logged in, and want no new vendor accounts
  • Security teams that need resumable audits — cost-capped slices that continue across Ctrl-C, disconnects, and provider credit exhaustion
  • Codebases with internal risk patterns worth encoding as plugins, such as helper names or internal package imports
  • CI gating on changed code via `process --diff`, as documented in `docs/reviewing-changes.md`

Skip for now if

  • Small repositories where a full AI review would cost more than the bugs it could find
  • Environments that cannot send source to external model providers — the harness self-hosts, but the models do not
  • Anyone needing a compliance-grade SAST report format rather than markdown finding files exported from `.deepsec/`
  • Budgets that cannot absorb four-figure model spend; the free `scan` stage alone never runs AI review
  • Shops requiring vendor SLAs — this is a vercel-labs project with no release notes or SLA in the source pack

Risks and cautions

Medium

The harness is Apache-2.0, resumable, and cost-capped, but the AI review stage can bill thousands to tens of thousands of dollars on large repos, and per-finding quality depends on model choice and an unquantified false-positive rate after revalidate.

  • The README itself states large-codebase scans can cost thousands or even tens of thousands of dollars
  • Default model routing goes through Vercel AI Gateway; the direct-key and local-subscription modes exist but require opt-in flags
  • No release notes, changelog, or versioning data appear in the source pack, so upgrade behavior cannot be verified from these documents
  • False-positive rates are not quantified anywhere in the pack; `revalidate` reduces them but gives no published numbers
  • The publish surface (`deepsec/config`) carries an extra merge gate (`pnpm test:bundle`), signaling that interface churn is anticipated
  • Runs in your own infrastructure; state and findings stay inside the `.deepsec/` folder in your repository
  • Three credential modes: Vercel AI Gateway, your own OpenAI/Anthropic key, or `--model-auth local` with no credentials configured at all
  • With direct keys, deepsec persists only the environment variable name; the key itself lives in your environment or `.deepsec/.env.local`
  • `revalidate` exists specifically to cut the false-positive rate before findings reach a fix queue
  • Vulnerabilities in the tool itself go to [email protected] per SECURITY.md, with all legitimate reports investigated
  • Apache-2.0 grants copyright and patent licenses covering internal use and derivative works

Alternatives to compare

ApproachWhen to useTrade-off
Semgrep
Fast rule-based scanning across many languages with cheap per-repo runs and zero model spendOpen source engine; the cloud platform is sold separately
CodeQL
Deep semantic queries inside GitHub CI with a large maintained query setFree for public repositories; private-repo use is part of GitHub Advanced Security
Gitleaks
Secret detection only — keys and tokens in git history — at near-zero costOpen source
TruffleHog
Secret scanning with verified-credential checks across git historyOpen source core with a paid enterprise tier
Commercial AI-assisted SAST (Checkmarx, Veracode)
Vendor-managed compliance reporting and SLAs matter more than model choice and raw markdown findingsEnterprise contracts

What this trend reveals

Encode house rules as private plugins

CONTRIBUTING.md explicitly routes org-specific matchers — specific helper names, internal package imports — into plugins rather than upstream, so a private plugin package can carry in-house risk knowledge without forking the scanner.

Write one matcher for an internal helper, register it in `matchers/index.ts`, and measure candidate counts with `pnpm deepsec scan --matchers <slug>` — a free, no-AI check.

Gate pull requests instead of whole repos

After one full baseline pass, `docs/reviewing-changes.md` documents `process --diff` and CI gating, so incremental review targets only changed code at a fraction of the full-repo price.

Run `process --diff` on branches containing a seeded flaw and compare the token cost against the full-repo `process` stage.

Buy a big audit in capped slices

`--max-cost-usd` and `--max-duration` stop runs at safe points that resume on re-run, converting a five-figure audit into a sequence of small, individually approved spends.

Chain `npx deepsec init --max-cost-usd 100 --max-duration 2h` invocations and log findings exported per slice with `pnpm deepsec export`.

Best next action

Size the paid stage for free, then cap the first run

The `scan` stage is local pattern matching with no AI cost, so use it to measure how many candidates `process` would review before authorizing any model spend.

  1. At the root of a disposable copy of the target repo, run `npx deepsec init --max-cost-usd 100 --max-duration 2h`
  2. At the model prompt, pick your own OpenAI/Anthropic key or a local claude/codex login to avoid creating a Vercel account
  3. Let the free `scan` stage finish, then stop and inspect candidate volume inside `.deepsec/`
  4. If the candidate set looks sane, run `pnpm deepsec process`, then `pnpm deepsec revalidate`, then `pnpm deepsec export --format md-dir --out ./findings`
  5. Report any harness bug or vulnerability to [email protected] per SECURITY.md rather than opening a public issue

RepoDaily verdict

deepsec is the rare security tool that prices itself honestly: free pattern scanning, capped and resumable AI review, and markdown findings you can read in a terminal. The trade is real money — thousands of dollars on large repos — plus a young codebase with no published releases or false-positive numbers. For an existing repository that has never been deeply reviewed, one cost-capped `npx deepsec init` run is a defensible first spend; for small projects or code that cannot reach external models, it is the wrong instrument.

Sources