mrkeyoor.com_
Mon 28 Sept 19:23 UTC
Dev Toolsevaluationupdated 26 Aug 2026

deepsec review

Deepsec is a self-hosted code-security scanner that combines fast pattern matching with coding agents that investigate suspected vulnerabilities. It is aimed at deep, on-demand reviews of existing large repositories, with resumable runs and optional distributed workers.

+21stars / 7d
Verdict

Our Deepsec run built in 58 seconds and passed 2,379 of 2,411 tests, but one assertion failed, so the codebase is close to green rather than clean at commit a008d3e. Use it for a funded, human-reviewed security sweep where deep agent investigation may uncover flaws cheaper tools miss. Keep Semgrep, CodeQL, or focused scanners in routine CI, because Deepsec's stated cost and shell access make it a deliberate audit tool.

We ran it

Lab card: what happened when we ran deepsecScreenshot of deepsec (deepsec.sh)
Install✓ · 94s1211 packages · 2333 MB
Build✓ · 58s
Tests✗ · 40s2379 passed · 1 failed · 31 skipped of 2411 (vitest)
Repo751 files~52,801 lines of source · 4.5 MB · 4 CI workflows

Answers from our run

Does deepsec build from source?

Dependencies installed in 94 seconds (1211 packages), and the build succeeded in 58 seconds. We cloned commit a008d3e into a clean Debian container with 3 CPUs and no project-specific setup.

Do deepsec's tests pass?

Not all of them: 2379 of 2411 passed and 1 failed when we ran the project's own test command (vitest). Some failures need services or credentials a bare container does not have.

Who should not use deepsec?

Teams looking for predictable low-cost scanning: the README says large-codebase runs can cost thousands or tens of thousands of dollars at high thinking levels.

What are the alternatives to deepsec?

Semgrep, CodeQL, Gitleaks. Our Deepsec run built in 58 seconds and passed 2,379 of 2,411 tests, but one assertion failed, so the codebase is close to green rather than clean at commit a008d3e.

Setup2/52,333 MB install and provider setup precede a real scan
Docs5/5Cost, credentials, workflow, state, and shell risk are explicit
Community4/57,826 stars with active August issue and pull request work
Maturity3/5Build passes, but one test failed and no GitHub release exists

Discussed on

  1. hnDeepsec58 points

Who it’s for

Security teams hunting old vulnerabilities across large codebases where a costly deep review is justified.
Organizations that need findings and scan state stored inside their own repository workspace.
Teams willing to pair pattern matchers with AI investigation, human triage, and revalidation.
Vercel users who can fan large scans across Sandbox workers, or teams bringing direct provider keys.

Who it’s NOT for

Teams looking for predictable low-cost scanning: the README says large-codebase runs can cost thousands or tens of thousands of dollars at high thinking levels.
Anyone unwilling to grant an AI security tool broad machine access: Deepsec's own security section says to treat it like a coding agent with full shell access.
Organizations that cannot send source-derived context to an external model provider: local state does not make the AI review local, and the documented providers are remote HTTPS services.
Buyers who require a clean test run at the measured commit: our suite reported 2,379 passed, 1 failed, and 31 skipped out of 2,411.
Teams expecting a passive dependency scanner: Deepsec investigates source with agents and needs model credentials, spending controls, and review of generated findings.

Setup reality

Our sandbox installed 1,211 pnpm packages in 94 seconds and used 2,333 MB on disk. The build succeeded in 58 seconds. Tests failed after 40 seconds: 2,379 passed, 1 failed, and 31 skipped out of 2,411.

Initialization needs Node.js, a repository to scan, and either Vercel AI Gateway access or a direct OpenAI, Anthropic, or custom provider key. Deepsec stores the environment-variable name for a key, not the key value. Large scans need explicit cost and duration limits.

Deepsec has full shell access on its host. Vercel Sandbox is optional for isolation and distributed work; it uploads a tarball of the working tree without .git. Interrupted scans resume from .deepsec/, which also stores findings and state.

Pattern scanning narrows the work before agents investigate

Deepsec starts with regex matchers that identify candidate code, then asks coding agents to investigate and produce findings with recommendations. Separate commands scan, process, triage, revalidate, enrich, report, and export results. Diff mode limits work to changed files for pull requests. This split makes sense for security review: cheap matching reduces the material sent to an expensive model, while later revalidation can revisit a finding against current code and Git history.

The tool is designed for large repositories, and its README is candid about money. High-thinking models can push a large scan into thousands or tens of thousands of dollars. Initialization therefore accepts a dollar ceiling and a duration cap. Runs write progress under .deepsec/ and resume after interruption, lost credentials, or a spending stop. Resumability is essential when a single review can exceed a normal CI window and budget.

The local install occupies 2,333 MB before model calls

Our sandbox installed 1,211 pnpm packages in 94 seconds and consumed 2,333 MB. The checkout itself had 751 files, about 52,801 source lines, and used 4.5 MB. The build passed in 58 seconds. That contrast shows where the local cost sits: the repository is compact, while its monorepo dependency graph is large before any code analysis or model request begins.

The repo had 4 CI workflow files, no Dockerfile, no top-level tests directory, and pnpm workspaces. A normal user starts with npx deepsec init inside the target repository instead of cloning this source tree. That command creates .deepsec/, installs the matching CLI and documentation there, asks for a model and payment route, and starts unattended work. Source contributors face the larger workspace we measured.

What happened when we ran it

We ran commit a008d3e in an unprivileged Node.js 22 container with 3 CPUs, 8 GB of RAM, and no secrets. Installation took 94 seconds, the build took 58 seconds, and tests ended with exit code 1 after 40 seconds. Vitest reported 2,379 passed, 1 failed, and 31 skipped out of 2,411 tests.

The failing assertion expected a child process exit code of 42 in a test concerned with signal listeners and error handling. The summary listed 3 failed test files, 60 passed files, and 1 skipped file even though the test count contained one failure. The log does not show why the observed exit code differed, so it would be wrong to blame container permissions, timing, or Node.js. The useful finding is that the full supplied command was not green in our sandbox.

Full shell access makes isolation part of setup

Deepsec tells operators to treat it like a coding agent with full shell access to its environment. Source code is trusted input in the intended model, yet vendored code or external dependencies can contain prompt injection. A local run therefore places the scanner, its agent, model credential path, and repository on the same trust boundary. A disposable clone with limited credentials is a sensible minimum for a first run.

Vercel Sandbox can move workers into microVMs and fan a project across several machines. The README's example uses 10 sandboxes with concurrency 4. The local working tree is packed and uploaded without .git; model credentials remain outside workers and are injected at the selected egress host. Bootstrap permits broader egress than the agent phase, a distinction security teams should include in their review.

Direct keys avoid Gateway billing but still call remote models

Vercel AI Gateway is the default provider route. Direct mode supports OpenAI, Anthropic, or a custom HTTPS provider and does not require a Vercel account according to the README. Deepsec saves only the name of the environment variable holding the credential. If quota runs out, processing stops and can continue after the account is funded.

Open issue 164 reports that a direct OpenAI setup still entered a Vercel authentication flow in the reporter's WSL2 environment. That report does not prove every direct configuration is broken, but it is specific enough to test before a scheduled review. Run initialization in a disposable repository, confirm the selected endpoint and account, then set both --max-cost-usd and --max-duration before scanning valuable code.

Revalidation reduces false positives at additional cost

The free matcher scan finds candidate sites. AI processing investigates them, lightweight triage assigns P0, P1, or P2 classes, and optional revalidation checks findings again. Export can write Markdown or JSON, while metrics summarize projects. This pipeline gives reviewers several points to reject weak findings instead of dumping one model response into a security queue.

It also creates multiple definitions of completion. Pull request 165 describes a case where quota stopped a 532-finding revalidation after only 326 findings, yet the saved run was marked done. That fix was still open when fetched, and its author notes the process path has a similar shape. Until the behavior lands and is verified in your version, compare requested, completed, and unresolved work instead of trusting a success-shaped status alone.

August activity is strong despite the missing release tag

GitHub showed 7,826 stars, 68 combined issues and pull requests, and a last push on August 26, 2026. The latest-release endpoint returned no release, so there is no current GitHub tag to cite. That absence does not imply abandonment: issue and pull request activity was current, including work on provider authentication, interrupted-run reporting, severity validation, and dependency security.

Deepsec is best treated as a periodic audit engagement in software form. Budget the model bill, isolate the host, preserve the .deepsec/ state, and have a security engineer review both findings and coverage. Our 2,379 passing tests show substantial exercised code, while the single failure and open completion semantics argue against unattended trust. Routine CI still benefits from deterministic scanners whose cost and coverage are easier to predict.

Alternatives

ProjectWhat it isPick it when
SemgrepA static-analysis engine built around code patterns and data-flow rules.pick this instead when repeatable rules, fast CI feedback, and bounded compute matter more than agent investigation.
CodeQLGitHub's query language and libraries for semantic code analysis.pick this instead when you need auditable queries and GitHub code-scanning integration.
Gitleaks gh↗A focused scanner for secrets in repositories and history.pick this instead when leaked credentials are the target and a broad AI review would add cost without focus.

What people are saying

  1. [github-trending] vercel-labs/deepsec

Sources

  1. Deepsec README
  2. Deepsec repository
  3. Issue 164: direct key still requests Vercel authentication
  4. Pull request 165: incomplete revalidation records

More dev tools reviews

coursebook · ink · kitter · flea · sonicloud_opensdk · cn · the whole board →