What happened
Vercel Labs (vercel-labs/deepsec) released deepsec, an open-source, agent-powered vulnerability scanner that runs in your own infrastructure and performs on-demand AI review of existing large-scale repositories using top reasoning models, with fast regex matcher + LLM investigation pipeline, resume-on-interrupt, CI/PR gating (process --diff), cross-project metrics, and parallel execution across Vercel Sandbox microVMs with egress-limited, host-side credential injection.
Why it matters
It is a notable OSS contribution to agentic AppSec: LLM-based deep-code review for hard-to-find vulnerabilities that regex static analyzers miss, designed for self-hosting with security mitigations (credentials held host-side, sandboxed worker egress) baked into the harness. It shows the coding-agent-sandbox pattern being reused for offensive security analysis.
Applicability
AppSec and engineering teams with large legacy codebases should trial deepsec for on-demand deep scans and PR gating; security teams should note the sandbox + credential-isolation design as a reference pattern for running LLM security agents safely.