{"_id":"@aryasaatvik/deepsec","_rev":"2-d5810fd58551ec6d811ee8d180bd1532","name":"@aryasaatvik/deepsec","dist-tags":{"latest":"2.4.0"},"versions":{"2.3.9":{"name":"@aryasaatvik/deepsec","version":"2.3.9","author":{"name":"Saatvik Arya"},"license":"Apache-2.0","_id":"@aryasaatvik/deepsec@2.3.9","maintainers":[{"name":"aryasaatvik","email":"aryasaatvik@gmail.com"}],"homepage":"https://github.com/aryasaatvik/deepsec#readme","bugs":{"url":"https://github.com/aryasaatvik/deepsec/issues"},"bin":{"deepsec":"dist/cli.mjs"},"dist":{"shasum":"af7b34b8b3b3b8faa4f963f2987f9cda198cc6b6","tarball":"https://registry.npmjs.org/@aryasaatvik/deepsec/-/deepsec-2.3.9.tgz","fileCount":30,"integrity":"sha512-gsb5jUx3RCcsdzx4hPliJvIJ2GVPkBKF93Xtk9oW7ScJNHmp1a5GrlaW6+Wb+eGv92MH8jltrsZhCO5m+GFpTA==","signatures":[{"sig":"MEUCIH4uSUsLQlz+inZxzgv4iWgK5NBgI/7a0Tpo1WPF9bBcAiEAjWBP1l1zP22CpPin32vtmoZOQTDR85V1FsUqvXPkmiA=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":4961171},"type":"module","exports":{".":"./dist/cli.mjs","./config":{"types":"./dist/config.d.ts","import":"./dist/config.mjs"}},"gitHead":"00b895e9233712a4124faf7ab7cea9ed6f677413","scripts":{"build":"tsc --noEmit","bundle":"pnpm --filter @deepsec/core --filter @deepsec/scanner build && node build.mjs","prepack":"pnpm bundle","prepublishOnly":"pnpm -w validate && node -e \"const fs=require('node:fs');for(const f of ['dist/cli.mjs','dist/config.mjs','dist/config.d.ts','dist/sandbox/request-proxy.mjs','dist/docs/getting-started.md','dist/samples/webapp/deepsec.config.ts','SKILL.md','README.md','LICENSE','NOTICE']){if(!fs.existsSync(f)){console.error('Missing: '+f);process.exit(1)}}console.log('Pre-publish checks passed.')\""},"_npmUser":{"name":"aryasaatvik","email":"aryasaatvik@gmail.com"},"repository":{"url":"git+https://github.com/aryasaatvik/deepsec.git","type":"git"},"_npmVersion":"11.16.0","description":"AI-powered vulnerability scanner for any codebase","directories":{},"_nodeVersion":"24.18.0","dependencies":{"ink":"^7.1.1","tar":"^7.5.20","zod":"^3.24.0","jiti":"^2.4.0","react":"^19.2.8","minimatch":"^10.0.0","@vercel/oidc":"^3.4.0","@openai/codex":"^0.153.2","@vercel/sandbox":"^1.9.0","@openai/codex-sdk":"^0.153.2","@anthropic-ai/claude-agent-sdk":"^0.3.260","@earendil-works/pi-coding-agent":"0.85.1"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"dotenv":"^16.4.0","esbuild":"^0.25.12","commander":"^13.0.0","@types/react":"^19.2.18","@deepsec/core":"workspace:*","@deepsec/scanner":"workspace:*","@deepsec/processor":"workspace:*","dts-bundle-generator":"^9.5.1"},"_npmOperationalInternal":{"tmp":"tmp/deepsec_2.3.9_1789134252503_0.629144808152966","host":"s3://npm-registry-packages-npm-production"}},"2.4.0":{"_id":"@aryasaatvik/deepsec@2.4.0","bin":{"deepsec":"./dist/cli.mjs"},"bugs":{"url":"https://github.com/aryasaatvik/deepsec/issues"},"dist":{"shasum":"2a4f3ec6a45f223fa7451931f0f9c4e72d67f042","tarball":"https://registry.npmjs.org/@aryasaatvik/deepsec/-/deepsec-2.4.0.tgz","fileCount":30,"integrity":"sha512-RBiFkVRLQakJcgXh4eFDdl/L5TUmzY4TRddUVOcft34uJPVYtSUicNg3F4WLP6L72mJJk1rYIgS3vxYvDlxn+w==","signatures":[{"sig":"MEUCIFNDnqpLJdMTDEXdVN5rcl6lRIN7fSO4iiEI2DeJvhLkAiEAwHJwU5fSTPn16suvF5G9hQDfyU/t8Br7Ic0NgBB7FFI=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIQC/MTRhHUrp5voyFbxlPI+4mIDxc+e2W8XaV1D+6cJbJwIfE8W1f9yoY1+G4asTnf1I0V2bARvw6kcqZL0raIsGEw=="}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@aryasaatvik%2fdeepsec@2.4.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":4912142},"name":"@aryasaatvik/deepsec","type":"module","author":"Saatvik Arya","exports":{".":"./dist/cli.mjs","./config":{"types":"./dist/config.d.ts","import":"./dist/config.mjs"}},"license":"Apache-2.0","scripts":{"build":"tsc --noEmit","bundle":"pnpm --filter @deepsec/core --filter @deepsec/scanner build && node build.mjs"},"version":"2.4.0","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:e0e4d7ed-18a6-4039-8c9c-40938e1e50fe"}},"homepage":"https://github.com/aryasaatvik/deepsec#readme","repository":{"url":"git+https://github.com/aryasaatvik/deepsec.git","type":"git"},"description":"AI-powered vulnerability scanner for any codebase","directories":{},"maintainers":[{"name":"aryasaatvik","email":"aryasaatvik@gmail.com"}],"dependencies":{"ink":"^7.1.1","tar":"^7.5.20","zod":"^3.24.0","jiti":"^2.4.0","react":"^19.2.8","minimatch":"^10.0.0","@vercel/oidc":"^3.4.0","@openai/codex":"^0.153.2","@vercel/sandbox":"^1.9.0","@openai/codex-sdk":"^0.153.2","@anthropic-ai/claude-agent-sdk":"^0.3.260","@earendil-works/pi-coding-agent":"0.85.1"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"dotenv":"^16.4.0","esbuild":"^0.25.12","commander":"^13.0.0","@types/react":"^19.2.18","@deepsec/core":"0.1.0","@deepsec/scanner":"0.1.0","@deepsec/processor":"0.1.0","dts-bundle-generator":"^9.5.1"},"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/deepsec_2.4.0_1789135170219_0.48336897253771727"}}},"time":{"created":"2026-09-11T13:44:12.359Z","modified":"2026-09-11T13:59:30.705Z","2.3.9":"2026-09-11T13:44:12.685Z","2.4.0":"2026-09-11T13:59:30.358Z"},"bugs":{"url":"https://github.com/aryasaatvik/deepsec/issues"},"author":"Saatvik Arya","license":"Apache-2.0","homepage":"https://github.com/aryasaatvik/deepsec#readme","repository":{"url":"git+https://github.com/aryasaatvik/deepsec.git","type":"git"},"description":"AI-powered vulnerability scanner for any codebase","maintainers":[{"name":"aryasaatvik","email":"aryasaatvik@gmail.com"}],"readme":"# deepsec\n\n> Fork of [vercel-labs/deepsec](https://github.com/vercel-labs/deepsec), published as\n> `@aryasaatvik/deepsec`.\n\n[`deepsec`](https://github.com/aryasaatvik/deepsec) is an agent-powered vulnerability scanner that you can run in your own infrastructure, optimized to perform on-demand review of all code in existing \nlarge-scale repos.\n\n`deepsec` is designed to surface hard-to-find issues that have been lurking in applications for a long time. It is configured to use the best models at maximum thinking levels (tunable via `--thinking-level`, see [models](https://github.com/aryasaatvik/deepsec/blob/main/docs/models.md)), meaning scans can cost thousands or even tens-of-thousands of dollars for large codebases. Our customers have found the cost worth it for how quickly they were able to patch vulnerabilities that would have otherwise gone unfixed.\n\nFor large codebases, work fans out across worker machines in parallel.\nIf a run is interrupted or errors out partway through, just re-run the same\ncommand — deepsec picks up where it left off, skipping files it already\nanalyzed and only investigating the rest.\n\n## Get started\n\nFrom the root of the repository you want to scan:\n\n```bash\nnpx @aryasaatvik/deepsec init\n```\n\nThe command guides you through everything. It asks you to pick an AI model\n(with benchmark scores and prices to compare) and how to pay for model\nusage — your own OpenAI/Anthropic API key, or Vercel AI Gateway — and then\nworks unattended: it studies your codebase, scans it, and runs the AI\nreview. The only thing it adds to your repository is a `.deepsec/` folder\nwhere all of its state and findings live.\n\nIf the run is interrupted for any reason — Ctrl-C, lost connection, a\nspending limit — run `npx @aryasaatvik/deepsec init` again and it continues where it\nleft off. To cap what a run may spend or how long it may take:\n\n```bash\nnpx @aryasaatvik/deepsec init --max-cost-usd 100 --max-duration 2h\n```\n\nWhen the scan finishes, get a readable report:\n\n```bash\ncd .deepsec\npnpm deepsec export --format md-dir --out ./findings\n```\n\nFor later scans, work from inside `.deepsec/`:\n\n```bash\npnpm deepsec scan        # fast pattern scan, free\npnpm deepsec process     # AI review of new candidates\npnpm deepsec revalidate  # optional, cuts false-positive rate\npnpm deepsec export --format md-dir --out ./findings\n```\n\nThe [getting started guide](https://github.com/aryasaatvik/deepsec/blob/main/docs/getting-started.md)\ncovers all of this in more detail, including using your own OpenAI or\nAnthropic API key and running from CI or a coding agent.\n\n## Docs\n\nAfter initialization, agents can read the exact documentation matching the\ninstalled CLI at `.deepsec/node_modules/@aryasaatvik/deepsec/SKILL.md` and\n`.deepsec/node_modules/@aryasaatvik/deepsec/dist/docs/`. Setup errors expose these as\nabsolute machine-readable paths.\n\n- [Getting started](https://github.com/aryasaatvik/deepsec/blob/main/docs/getting-started.md) — set up and run your first scan\n- [Reviewing changes](https://github.com/aryasaatvik/deepsec/blob/main/docs/reviewing-changes.md) — `process --diff` and CI gating\n- [Supported technology](https://github.com/aryasaatvik/deepsec/blob/main/docs/supported-tech.md) — built-in coverage\n- [Generated and hand-authored matchers](https://github.com/aryasaatvik/deepsec/blob/main/docs/writing-matchers.md)\n- [Configuration](https://github.com/aryasaatvik/deepsec/blob/main/docs/configuration.md)\n- [Plugins](https://github.com/aryasaatvik/deepsec/blob/main/docs/plugins.md)\n- [Models](https://github.com/aryasaatvik/deepsec/blob/main/docs/models.md)\n- [Project link and credentials](https://github.com/aryasaatvik/deepsec/blob/main/docs/vercel-setup.md)\n- [Architecture](https://github.com/aryasaatvik/deepsec/blob/main/docs/architecture.md)\n- [Data layout](https://github.com/aryasaatvik/deepsec/blob/main/docs/data-layout.md)\n- [FAQ](https://github.com/aryasaatvik/deepsec/blob/main/docs/faq.md)\n- [Samples](https://github.com/aryasaatvik/deepsec/tree/main/samples)\n- [Contributing](https://github.com/aryasaatvik/deepsec/blob/main/CONTRIBUTING.md)\n\n## AI provider\n\nBy default, deepsec routes model calls through Vercel AI Gateway, which\ngives access to every major model without provider-specific keys. You can\ninstead bring your own key — OpenAI, Anthropic, or a custom HTTPS\nprovider — by passing `--model-auth direct` with `--ai-provider` and\n`--ai-api-key-env` to `init`; no Vercel account is needed in that mode.\nDeepsec only ever stores the *name* of the environment variable holding\nyour key, never the key itself. See\n[project link and credentials](https://github.com/aryasaatvik/deepsec/blob/main/docs/vercel-setup.md)\nfor the full reference.\n\nIf a `process` or `revalidate` run halts because the upstream credential\nran out of quota or credits, deepsec stops gracefully and tells you\nwhere to top up. Re-run the same command afterward and it picks up\nwhere it left off.\n\n## Distributed execution (optional)\n\nLarge monorepos can fan work across [Vercel Sandbox](https://vercel.com/docs/vercel-sandbox) microVMs:\n\n```bash\npnpm deepsec sandbox process --project-id my-app --sandboxes 10 --concurrency 4\n```\n\nSetup already verified the Vercel connection, so this needs no extra\nonboarding. The local working tree is tarballed and uploaded; `.git` is\nexcluded. Model credentials remain host-side and are injected only at the\nselected egress host.\n\n## Security model of deepsec itself\n\nTreat `deepsec` like a coding agent with full shell access on the enviroment that it is\nrunning on. It is designed to run on trusted inputs (your source code) but you may still\nbe concerned about prompt injection due to external dependencies or vendored code.\n\nRunning on a sandbox (see above) does limit the potential exposure substantially:\n\n- The API keys for the coding agents are injected outside of the sandbox and hence cannot be exfiltrated\n- For the worker sandboxes, network egress from the sandbox is limited to coding agent hosts (Egress is allowed during the bootstrap process, but this does not run the coding agent)\n\n## Workflow reference\n\n| Command         | What it does                                             |\n|-----------------|----------------------------------------------------------|\n| `scan`          | Find candidate sites with regex matchers (fast, no AI)   |\n| `process`       | AI investigation; emits findings + recommendation        |\n| `process --diff`| PR-mode: scan + investigate only files changed in a diff |\n| `triage`        | Lightweight P0/P1/P2 classification (cheaper model)      |\n| `revalidate`    | Re-check existing findings; checks git history for fixes |\n| `enrich`        | Add git committer info + (with a plugin) ownership data  |\n| `report`        | Markdown + JSON summary for one project                  |\n| `export`        | Per-finding JSON or directory of markdown files          |\n| `metrics`       | Cross-project counts: severities, vulns by type, TPs     |\n| `status`        | Snapshot of the project mirror                           |\n| `sandbox <cmd>` | Run any of the above on Vercel Sandbox microVMs          |\n\n## License\n\nApache 2.0. See [LICENSE](LICENSE) and [NOTICE](NOTICE).\n","readmeFilename":""}