Solutions  ·  2026-09-27

Vercel Labs ships deepsec — open-source agent-powered vulnerability scanner for large-scale codebases

SolutionsMedium impactGlobal
Vercel Labs (vercel-labs/deepsec) released deepsec, an open-source, agent-powered vulnerability scanner that runs in your own infrastructure and performs on-demand AI review of existing large-scale repositories using top reasoning models, with fast regex matcher + LLM investigation pipeline, resume-on-interrupt, CI/PR gating (process --diff), cross-project metrics, and parallel execution across Vercel Sandbox microVMs with egress-limited, host-side credential injection.
It is a notable OSS contribution to agentic AppSec: LLM-based deep-code review for hard-to-find vulnerabilities that regex static analyzers miss, designed for self-hosting with security mitigations (credentials held host-side, sandboxed worker egress) baked into the harness. It shows the coding-agent-sandbox pattern being reused for offensive security analysis.
AppSec and engineering teams with large legacy codebases should trial deepsec for on-demand deep scans and PR gating; security teams should note the sandbox + credential-isolation design as a reference pattern for running LLM security agents safely.
vercel-labs/deepsec (GitHub)Scanners Box listing (kitploit.com)
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →