Agent-powered vulnerability scanning for large-scale codebases — on your own infrastructure.
Quick start · Documentation · Models & agents · Configuration
Daniel Bannert's open source work is supported by the community on GitHub Sponsors
deepsec is an agent-powered vulnerability scanner that you run on your own infrastructure, optimized for on-demand review of all code in existing large-scale repos. It is designed to surface hard-to-find issues that have been lurking in applications for a long time.
It is configured to use the best models at maximum thinking levels (tunable via --thinking-level, see models), meaning scans can cost thousands or even tens-of-thousands of dollars for large codebases. Our customers have found the cost worth it for how quickly they were able to patch vulnerabilities that would have otherwise gone unfixed.
For large codebases, work fans out across worker machines in parallel. If a run is interrupted or errors out partway through, just re-run the same command — deepsec picks up where it left off, skipping files it already analyzed and only investigating the rest.
This fork builds on vercel-labs/deepsec and adds:
- OpenCode as an agent backend (
--agent opencode). Both OpenCode runtime generations work — v1 (npmopencode-ai1.x, bundled for sandbox workers) and the new OpenCode v2 (2.0.x), detected automatically at startup. The v2 runtime cannot be driven by the published SDK (a different API surface under/api/…, mandatory basic auth, an async prompt/wait inbox), so the backend speaks both protocols itself. Every batch runs in a private, password-secured OpenCode server with a read-only agent — onlyread,glob,grep, andlist; shell, edits, network tools, subagents, external directories, LSP, and skills are denied. Works forprocess,revalidate, and the one-shotinitrepository analysis. - Vercel AI Gateway on the OpenCode backend. On the v2 runtime, the native
vercel/provider takes oneAI_GATEWAY_API_KEYfor every model behind the gateway (--model vercel/anthropic/claude-opus-4-8). The standard gateway credential expansion also keeps working — it is translated into v2 providerbaseURLoverlays, with the bearer token bridged to thex-api-keyform the v2 anthropic provider reads. - No Vercel account needed for your own key.
init --model-auth directno longer prompts for a Vercel login (upstream issue #164): the platform link — which only enables the optional Vercel Sandbox distribution — is reused silently when Vercel credentials exist and skipped otherwise, while your provider key is still resolved and verified. - Config matcher filtering works.
matchers: { only, exclude }indeepsec.config.tsis honored byscan(upstream issue #36); unknown slugs in the config fail loud instead of being silently ignored. - Your Codex subscription is respected. A
codex loginsubscription wins over a strayOPENAI_API_KEYin the environment — matching the codex CLI's own precedence — unless explicit gateway/base-URL routing is configured (upstream issue #32). - Nine upstream fix MRs merged that repair open issues left sitting upstream: severity ordering (#48/#61), unknown
--matchersslugs (#34/#75), triage data in exports (#64/#71), triage verdict matching (#118/#119), unparseable triage output (#120/#121), token-metrics table layout (#135/#149), non-coherent host mounts (#159/#160), provider policy refusals parsed as findings (#92/#137), and macOS test flakiness (#51/#50). Upstream issues #30, #29, #33, and #91 were verified as already fixed in current main. - Published as
@anolilab/deepsecwith the samedeepsecCLI and release automation via npm trusted publishing — no tokens in CI.
From the root of the repository you want to scan:
npx @anolilab/deepsec initThe command guides you through everything. It asks you to pick an AI model
(with benchmark scores and prices to compare) and how to pay for model
usage — your own OpenAI/Anthropic API key, or Vercel AI Gateway — and then
works unattended: it studies your codebase, scans it, and runs the AI
review. The only thing it adds to your repository is a .deepsec/ folder
where all of its state and findings live.
If the run is interrupted for any reason — Ctrl-C, lost connection, a
spending limit — run npx @anolilab/deepsec init again and it continues
where it left off. To cap what a run may spend or how long it may take:
npx @anolilab/deepsec init --max-cost-usd 100 --max-duration 2hWhen the scan finishes, get a readable report:
cd .deepsec
pnpm deepsec export --format md-dir --out ./findingsFor later scans, work from inside .deepsec/:
pnpm deepsec scan # fast pattern scan, free
pnpm deepsec process # AI review of new candidates
pnpm deepsec revalidate # optional, cuts false-positive rate
pnpm deepsec export --format md-dir --out ./findingsThe getting started guide covers all of this in more detail, including using your own OpenAI or Anthropic API key and running from CI or a coding agent.
After initialization, agents can read the exact documentation matching the
installed CLI at .deepsec/node_modules/@anolilab/deepsec/SKILL.md and
.deepsec/node_modules/@anolilab/deepsec/dist/docs/. Setup errors expose
these as absolute machine-readable paths.
- Getting started — set up and run your first scan
- Reviewing changes —
process --diffand CI gating - Supported technology — built-in coverage
- Generated and hand-authored matchers
- Configuration
- Plugins
- Models — agent backends, thinking levels, credentials, recommended models & ensemble strategy
- Project link and credentials
- Architecture
- Data layout
- FAQ
- Samples
- Contributing
The AI review runs through an interchangeable agent backend, selected with
--agent (or defaultAgent in deepsec.config.ts). Same prompt, same JSON
output contract — you can mix backends within a repo and compare models
under the same workload.
| Backend | SDK | Default model |
|---|---|---|
codex (default) |
@openai/codex-sdk |
gpt-5.5 |
claude |
@anthropic-ai/claude-agent-sdk |
claude-opus-4-8 |
opencode |
@opencode-ai/sdk/v2 + opencode runtime |
anthropic/claude-opus-4-8 |
pi |
@earendil-works/pi-coding-agent |
zai/glm-5.2 |
pnpm deepsec process --project-id my-app --agent claude
pnpm deepsec process --project-id my-app --agent opencode --model anthropic/claude-opus-4-8The opencode backend speaks both OpenCode runtime generations — the v1
runtime (npm opencode-ai 1.x, also bundled for sandbox workers) and the new
OpenCode v2 (2.0.x) — detected automatically at startup, so it works
with whatever opencode you have installed. Each batch runs in a private,
password-secured OpenCode server with a read-only agent: only read,
glob, grep, and list are allowed; shell, edits, network tools,
subagents, external directories, LSP, and skills are denied.
For a local run without environment credentials, connect a provider first
(run opencode, then use /connect) and use its provider/model id:
pnpm deepsec process --project-id my-app \
--agent opencode \
--model openai/gpt-5.5Through the Vercel AI Gateway, the v2 runtime also accepts the native
vercel/ provider — one AI_GATEWAY_API_KEY covers every model behind the
gateway:
AI_GATEWAY_API_KEY=vck_… pnpm deepsec process --project-id my-app \
--agent opencode \
--model vercel/anthropic/claude-opus-4-8See models for the full backend reference, thinking levels, credential routing, and the recommended models & ensemble strategy for maximum issue discovery.
By default, deepsec routes model calls through Vercel AI Gateway, which
gives access to every major model without provider-specific keys — one
AI_GATEWAY_API_KEY covers every agent backend above. You can instead
bring your own key — OpenAI, Anthropic, or a custom HTTPS provider — by
passing --model-auth direct with --ai-provider and --ai-api-key-env
to init; no Vercel account is needed in that mode. Deepsec only ever
stores the name of the environment variable holding your key, never the
key itself. See
project link and credentials
for the full reference.
When running locally, deepsec can also reuse existing Claude, Codex, Pi,
or OpenCode provider authentication — including a local opencode CLI
login (opencode → /connect) — for evaluation-scale scans.
If a process or revalidate run halts because the upstream credential
ran out of quota or credits, deepsec stops gracefully and tells you
where to top up. Re-run the same command afterward and it picks up
where it left off.
Large monorepos can fan work across Vercel Sandbox microVMs:
pnpm deepsec sandbox process --project-id my-app --sandboxes 10 --concurrency 4Setup already verified the Vercel connection, so this needs no extra
onboarding. The local working tree is tarballed and uploaded; .git is
excluded. Model credentials remain host-side and are injected only at the
selected egress host.
Treat deepsec like a coding agent with full shell access on the enviroment that it is
running on. It is designed to run on trusted inputs (your source code) but you may still
be concerned about prompt injection due to external dependencies or vendored code.
Running on a sandbox (see above) does limit the potential exposure substantially:
- The API keys for the coding agents are injected outside of the sandbox and hence cannot be exfiltrated
- For the worker sandboxes, network egress from the sandbox is limited to coding agent hosts (Egress is allowed during the bootstrap process, but this does not run the coding agent)
| Command | What it does |
|---|---|
scan |
Find candidate sites with regex matchers (fast, no AI) |
process |
AI investigation; emits findings + recommendation |
process --diff |
PR-mode: scan + investigate only files changed in a diff |
triage |
Lightweight P0/P1/P2 classification (cheaper model) |
revalidate |
Re-check existing findings; checks git history for fixes |
enrich |
Add git committer info + (with a plugin) ownership data |
report |
Markdown + JSON summary for one project |
export |
Per-finding JSON or directory of markdown files |
metrics |
Cross-project counts: severities, vulns by type, TPs |
status |
Snapshot of the project mirror |
sandbox <cmd> |
Run any of the above on Vercel Sandbox microVMs |
Start with CONTRIBUTING.md. For security reports, see SECURITY.md. For community guidelines, see CODE_OF_CONDUCT.md.