Use deepsec (an AI-powered vulnerability scanner) — one-shot initialization, resumable setup, project/model credentials, scans, generated or hand-authored matchers, and plugins. Activates when the user asks how to initialize, scan, configure, resume, or extend deepsec.
73
90%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Passed
No findings from the security scan
deepsec is an AI-powered vulnerability scanner. The one-shot initializer
installs this skill at .deepsec/node_modules/deepsec/SKILL.md. From inside
the isolated workspace the same path is node_modules/deepsec/SKILL.md. In a
Deepsec source clone, use the repository's docs/ directory instead.
When the user asks how to use, configure, or extend deepsec, read the relevant doc before answering — the docs are the source of truth, not your training data.
From the target repository, .deepsec/node_modules/deepsec/dist/docs/; from
inside .deepsec, node_modules/deepsec/dist/docs/; or from a Deepsec source
clone, <deepsec-clone>/docs/:
getting-started.md — one-shot initialization and resume walkthroughconfiguration.md — full deepsec.config.ts referenceplugins.md — plugin slots (matchers, notifiers, ownership, people, executor)writing-matchers.md — generated declarative vs hand-authored matchersmodels.md — model selection, defaults, refusals, future modelsvercel-setup.md — exact project link, Sandbox scope, Gateway/BYOK/custom routesarchitecture.md — pipeline internalsdata-layout.md — data/ schemas (FileRecord, RunMeta, …)faq.md — cost, model choice, sandbox mode, FP rategetting-started.md; default to npx deepsec init, not a manual install/scan recipe.getting-started.md + data-layout.md; re-run init or deepsec setup.getting-started.md after noting the first scan/process already ran during setup.deepsec.config.ts?" → configuration.md + samples/webapp/deepsec.config.ts.writing-matchers.md + the project's generated-matchers.ts.writing-matchers.md + samples/webapp/matchers/*.ts.plugins.md + samples/webapp/deepsec.config.ts (inline plugin pattern).architecture.md.data/<id>/files/foo.json?" → data-layout.md.models.md.vercel-setup.md.Read the doc before paraphrasing. The CLI flag set, defaults, and plugin-contract field names change — quote the doc, don't recall.
When you are asked to initialize Deepsec from a non-TTY agent session, first inspect the read-only plan:
npx deepsec init --plan --output jsonThen run the requested policy, normally:
npx deepsec init --yes --model-profile value --output jsonlParse every output line as JSON. On needs_input, show the supplied message
and actions to the user rather than inventing remediation. In particular,
VERCEL_AUTH_REQUIRED normally asks the user to run npx vercel login; after
they do, follow the returned link action from inside .deepsec. Use
npx vercel link when the user needs to choose, or the returned parameterized
--yes --team <team-slug> --project <project-name> form for a known existing
project. Then rerun the same Deepsec command. Exit code 2 means input is needed
and exit code 3 means a requested cost/duration boundary stopped the resumable
run. Never expose credential values, bypass --yes, or launch an interactive
login yourself.
ce64674
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.