Pattern scanning narrows the work before agents investigate
Deepsec starts with regex matchers that identify candidate code, then asks coding agents to investigate and produce findings with recommendations. Separate commands scan, process, triage, revalidate, enrich, report, and export results. Diff mode limits work to changed files for pull requests. This split makes sense for security review: cheap matching reduces the material sent to an expensive model, while later revalidation can revisit a finding against current code and Git history.
The tool is designed for large repositories, and its README is candid about money. High-thinking models can push a large scan into thousands or tens of thousands of dollars. Initialization therefore accepts a dollar ceiling and a duration cap. Runs write progress under .deepsec/ and resume after interruption, lost credentials, or a spending stop. Resumability is essential when a single review can exceed a normal CI window and budget.
The local install occupies 2,333 MB before model calls
Our sandbox installed 1,211 pnpm packages in 94 seconds and consumed 2,333 MB. The checkout itself had 751 files, about 52,801 source lines, and used 4.5 MB. The build passed in 58 seconds. That contrast shows where the local cost sits: the repository is compact, while its monorepo dependency graph is large before any code analysis or model request begins.
The repo had 4 CI workflow files, no Dockerfile, no top-level tests directory, and pnpm workspaces. A normal user starts with npx deepsec init inside the target repository instead of cloning this source tree. That command creates .deepsec/, installs the matching CLI and documentation there, asks for a model and payment route, and starts unattended work. Source contributors face the larger workspace we measured.
What happened when we ran it
We ran commit a008d3e in an unprivileged Node.js 22 container with 3 CPUs, 8 GB of RAM, and no secrets. Installation took 94 seconds, the build took 58 seconds, and tests ended with exit code 1 after 40 seconds. Vitest reported 2,379 passed, 1 failed, and 31 skipped out of 2,411 tests.
The failing assertion expected a child process exit code of 42 in a test concerned with signal listeners and error handling. The summary listed 3 failed test files, 60 passed files, and 1 skipped file even though the test count contained one failure. The log does not show why the observed exit code differed, so it would be wrong to blame container permissions, timing, or Node.js. The useful finding is that the full supplied command was not green in our sandbox.
Full shell access makes isolation part of setup
Deepsec tells operators to treat it like a coding agent with full shell access to its environment. Source code is trusted input in the intended model, yet vendored code or external dependencies can contain prompt injection. A local run therefore places the scanner, its agent, model credential path, and repository on the same trust boundary. A disposable clone with limited credentials is a sensible minimum for a first run.
Vercel Sandbox can move workers into microVMs and fan a project across several machines. The README's example uses 10 sandboxes with concurrency 4. The local working tree is packed and uploaded without .git; model credentials remain outside workers and are injected at the selected egress host. Bootstrap permits broader egress than the agent phase, a distinction security teams should include in their review.
Direct keys avoid Gateway billing but still call remote models
Vercel AI Gateway is the default provider route. Direct mode supports OpenAI, Anthropic, or a custom HTTPS provider and does not require a Vercel account according to the README. Deepsec saves only the name of the environment variable holding the credential. If quota runs out, processing stops and can continue after the account is funded.
Open issue 164 reports that a direct OpenAI setup still entered a Vercel authentication flow in the reporter's WSL2 environment. That report does not prove every direct configuration is broken, but it is specific enough to test before a scheduled review. Run initialization in a disposable repository, confirm the selected endpoint and account, then set both --max-cost-usd and --max-duration before scanning valuable code.
Revalidation reduces false positives at additional cost
The free matcher scan finds candidate sites. AI processing investigates them, lightweight triage assigns P0, P1, or P2 classes, and optional revalidation checks findings again. Export can write Markdown or JSON, while metrics summarize projects. This pipeline gives reviewers several points to reject weak findings instead of dumping one model response into a security queue.
It also creates multiple definitions of completion. Pull request 165 describes a case where quota stopped a 532-finding revalidation after only 326 findings, yet the saved run was marked done. That fix was still open when fetched, and its author notes the process path has a similar shape. Until the behavior lands and is verified in your version, compare requested, completed, and unresolved work instead of trusting a success-shaped status alone.
August activity is strong despite the missing release tag
GitHub showed 7,826 stars, 68 combined issues and pull requests, and a last push on August 26, 2026. The latest-release endpoint returned no release, so there is no current GitHub tag to cite. That absence does not imply abandonment: issue and pull request activity was current, including work on provider authentication, interrupted-run reporting, severity validation, and dependency security.
Deepsec is best treated as a periodic audit engagement in software form. Budget the model bill, isolate the host, preserve the .deepsec/ state, and have a security engineer review both findings and coverage. Our 2,379 passing tests show substantial exercised code, while the single failure and open completion semantics argue against unattended trust. Routine CI still benefits from deterministic scanners whose cost and coverage are easier to predict.

