AI product Open source

deepsec

deepsec is an open-source, agent-powered vulnerability scanner and security harness from Vercel Labs for on-demand review of large codebases within the user's own infrastructure. It identifies candidate vulnerabilities, uses AI models to investigate them, supports triage and optional revalidation to reduce false positives, and can run work across parallel worker machines.

View repository Visit site Mentioned in 1 video ↓

Overview

The CLI initializes a repository with `npx deepsec init`, stores state and findings in a `.deepsec/` directory, and resumes interrupted runs while skipping files already analyzed. Subsequent commands separate fast pattern scanning from AI processing and revalidation, and findings can be exported as Markdown directories or JSON. Model access can use Vercel AI Gateway, direct OpenAI or Anthropic credentials, or a custom HTTPS provider; scan cost and duration can be capped with command-line options.

What deepsec is used for

1 use taken from transcripts — each links to the moment in the video.

  • An open-source, agent-powered vulnerability scanner for large codebases that runs inside the user's infrastructure. It identifies candidate issues, performs AI investigations, supports triage and Git-history revalidation, and exports findings as Markdown or JSON.

Videos mentioning deepsec

1 in the library.