vercel-labs/dev3000-deepsec
Run DeepSec against a Vercel project checkout from dev3000. Use for one-click DeepSec setup, project context bootstrapping, bounded first-pass processing, and report generation.
npx skills add https://github.com/vercel-labs/dev3000 --skill deepsec
Use this skill to turn the manual DeepSec workflow into a repeatable dev3000 run against the current Vercel project checkout.
/workspace/repo..deepsec/.env.local or any tracked file. The dev3000 runtime passes AI Gateway credentials through the process environment.process or revalidate command unless the user explicitly asks for a full DeepSec scan in run-specific instructions.README.md if present.AGENTS.md or CLAUDE.md if present..deepsec/ is absent, run npx --yes deepsec@latest init..deepsec/ already exists, do not force overwrite it.corepack pnpm install from .deepsec/.@anthropic-ai/claude-agent-sdk.corepack pnpm is unavailable, run pnpm install only after confirming pnpm exists..deepsec/node_modules/deepsec/SKILL.md..deepsec/data/<id>/SETUP.md..deepsec/data/<id>/INFO.md with concise project-specific context.INFO.md to roughly 50-100 lines.corepack pnpm deepsec scan from .deepsec/.corepack pnpm deepsec process --limit 25 --concurrency 2 --batch-size 3.--limit.corepack pnpm deepsec export --format md-dir --out ./findings..deepsec/findings/README.md summarizing that this bounded pass found no findings and include the exact commands that were run.corepack pnpm deepsec status, and generated finding files as validation.git diff --stat and make sure no secrets, node_modules, .env.local, or raw scan state are staged by accident.Take vercel-labs/dev3000-deepsec from the repository into ~/.claude/skills for personal
use, or into .claude/skills inside a project.
The agent identifies a skill by the name field in its header. Two skills with the
same name cannot sit side by side — one of them will be ignored.
The instructions reference npm, npx.
Without those the skill loads but fails at the first command.