⏳ This skill is pending AI review.
Scores will appear once the review pipeline completes.
vercel-deepsec
Detects broad web application security vulnerabilities using the Vercel DeepSec benchmark prompt. Use when benchmarking security review coverage or running an open-ended appsec scan for auth bypass, missing auth, XSS, RCE, SQL injection, SSRF, path traversal, secrets, weak crypto, unsafe redirects, webhook verification, Next.js Server Actions, Lua/OpenResty, Go, cache poisoning, or header trust bugs.
Choose how to use this skill
You do not need every option. Choose the path your AI client supports. The stable page stays the same; versioned files are immutable.
1. Native installer
This listing has no registered native installer command. Use the complete package or source fallback below, depending on what your client supports.
Do not guess an installer command or replace an existing version without reviewing the diff.
2. Complete package recommended
Download the ZIP when available. It includes SKILL.md plus the references, security notes and version metadata.
No complete ProSkills package is published for this listing yet.3. Prompt-only
Copy the prompt above when the agent can read the stable page or when you want to adopt the workflow without installing a skill.
Need only the instruction file?
Download SKILL.md only if your client requires a single file. The complete ZIP is safer for a full installation because it preserves the references and release context.
No path installs or executes anything by itself. Your agent still needs access to the project files. Before updating, compare the installed version and review the diff.
// RATINGS
// README
vercel-deepsec
This Warden skill adapts the Vercel Labs DeepSec default processor prompt into SKILL.md form.
It is used to benchmark broad security-review behavior against the DeepSec prompt. It is intentionally wider than most production Warden skills, so focused skills such as authz, code execution, data exfiltration, GitHub Actions, or PII should remain preferred when the review target is narrower.
Upstream
- Repository: https://github.com/vercel-labs/deepsec
- Source prompt:
packages/processor/src/index.ts - Retrieved commit:
cf8bae9ad37e22a4f23c675493c4c553c6379162
The upstream Apache 2.0 LICENSE is included intact. The upstream NOTICE is included because DeepSec ships one.
// HOW IT'S BUILT
KEY FILES