🔧 Công cụ lập trình•Mã nguồn mở•Đang hoạt động

deepsec

Vulnerability scanner dùng coding agents để rà soát codebase lớn, tìm lỗ hổng khó thấy và chạy song song trên local hoặc Vercel Sandbox.

#deepsec
Danh mục
🔧 Công cụ lập trình
Giá
Mã nguồn mở
GitHub Stars
⭐ 8,119
Ngôn ngữ
TypeScript
License
Apache-2.0
Ngày thêm
2026-05-07
Tóm tắt từ README GitHub
deepsec is an agent-powered vulnerability scanner that you can run in your own infrastructure, optimized to perform on-demand review of all code in existing large-scale repos. is designed to surface hard-to-find issues that have been lurking in applications for a long time. It is configured to use the best models at maximum thinking levels (tunable via , see models), meaning scans can cost thousands or even tens-of-thousands of dollars for large codebases. Our customers have found the cost worth it for how quickly they were able to patch vulnerabilities that would have otherwise gone unfixed. For large codebases, work fans out across worker machines in parallel. If a run is interrupted or errors out partway through, just re-run the same command — deepsec picks up where it left off, skipping files it already analyzed and only investigating the rest. Get started From the root of the repository you want to scan: The command guides you through everything. It asks you to pick an AI model (with benchmark scores and prices to compare) and how to pay for model usage — your own OpenAI/Anthropic API key, or Vercel AI Gateway — and then works unattended: it studies your codebase,
Xem thêm từ README.md

Đánh giá chi tiết

Tổng quan

deepsec là một security harness dùng coding agents để quét codebase và tìm những lỗ hổng khó thấy trong các repo lớn. Tool này không dừng ở grep hay rule-based scan. Nó tách quy trình thành scan, process, revalidate rồi cho agent đào sâu từng điểm nghi ngờ, nên hợp với các team muốn rà lại nợ bảo mật trong code cũ.

Điểm đáng chú ý là deepsec thiết kế cho workload nặng ngay từ đầu. Bạn có thể chạy local, dùng subscription sẵn có của Claude hoặc Codex, hoặc fan-out qua Vercel Sandbox để xử lý monorepo lớn. Job có tính idempotent nên bị ngắt giữa chừng vẫn resume lại được.

Tính năng chính

  • Quét repo theo nhiều bước: scan để tìm candidate nhanh, process để agent điều tra, revalidate để giảm false positive
  • Hỗ trợ repo lớn và nhiều ngôn ngữ, có nhận diện framework như Next.js, Express, Django, FastAPI, Rails, Laravel, Go web frameworks và thêm matcher riêng khi cần
  • Chạy song song trên nhiều worker hoặc Vercel Sandbox để rút ngắn thời gian xử lý cho monorepo lớn
  • Xuất findings ra markdown, JSON, metrics và report để dùng cho security review hoặc CI workflow
  • Tận dụng Claude, Codex hoặc Vercel AI Gateway, đồng thời giữ state scan trong thư mục .deepsec để chạy incremental

Ai nên dùng

Hợp với security engineer, platform team hoặc developer phụ trách codebase lớn muốn tìm bug bảo mật theo kiểu investigation sâu thay vì chỉ dựa vào static rule scanner.

Hạn chế

  • Chi phí có thể rất cao với repo lớn vì process dùng model mạnh và mức reasoning cao
  • Cần đầu tư context ban đầu như INFO.md và matcher riêng nếu muốn kết quả sát với hệ thống nội bộ
  • Đây là tool cho repo bạn tự kiểm soát, không phải dịch vụ scan nhẹ để chạy nhanh trên mọi project
deepsec | Atlas for AI