by helixnow
An open-source, local-first AI learning workbench
# Add to your Claude Code skills
git clone https://github.com/helixnow/deep-studentLast scanned: 10/5/2026
{
"issues": [
{
"type": "npm-audit",
"message": "@boundaries/elements: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@hono/node-server: Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@vitest/mocker: Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "baseline-browser-mapping: baseline-browser-mapping process termination on invalid input causes denial of service",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "body-parser: body-parser vulnerable to denial of service when invalid limit value silently disables size enforcement",
"severity": "low"
},
{
"type": "npm-audit",
"message": "brace-expansion: brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups",
"severity": "high"
},
{
"type": "npm-audit",
"message": "braces: braces vulnerable to stack-exhaustion denial of service through deeply nested patterns",
"severity": "high"
},
{
"type": "npm-audit",
"message": "browserslist: Browserslist: Unbounded memory growth (no cache eviction) via distinct query results, leading to eventual OOM",
"severity": "high"
},
{
"type": "npm-audit",
"message": "chokidar: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "colord: Colord: Slow rejection of oversized malformed color strings",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "dompurify: DOMPurify: IN_PLACE hook removal leaves a detached subtree executable, causing XSS",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "eslint-plugin-boundaries: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "fast-glob: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "fast-uri: fast-uri vulnerable to host confusion via literal backslash authority delimiter",
"severity": "high"
},
{
"type": "npm-audit",
"message": "find-yarn-workspace-root: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "globby: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "hono: Hono: ReDoS in CORS middleware via Access-Control-Request-Headers",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "ip-address: ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass",
"severity": "high"
},
{
"type": "npm-audit",
"message": "js-yaml: JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported",
"severity": "high"
},
{
"type": "npm-audit",
"message": "mermaid: Mermaid configuration APIs allow prototype pollution",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "micromatch: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "nanoid: nanoid: non-secure generators can loop indefinitely with negative size",
"severity": "high"
},
{
"type": "npm-audit",
"message": "patch-package: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "postcss: PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappingURL reads arbitrary .map files when `from` is unset",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "postcss-selector-parser: postcss-selector-parser allows denial of service through uncontrolled AST recursion",
"severity": "low"
},
{
"type": "npm-audit",
"message": "qs: qs array-limit bypass via bracket-key comma parsing",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "sharp: sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591",
"severity": "high"
},
{
"type": "npm-audit",
"message": "stylelint: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "tailwindcss: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "vite-plugin-static-copy: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "vitest: Vulnerability found",
"severity": "medium"
}
],
"status": "WARNING",
"scannedAt": "2026-10-05T11:12:48.426Z",
"npmAuditRan": true,
"pipAuditRan": true,
"promptInjectionRan": true
}See how deep-student compares with popular alternatives.
deep-student is an open-source ai agents skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by helixnow. An open-source, local-first AI learning workbench. It has 274 GitHub stars.
deep-student returned warnings in SkillsLLM's automated security scan. It has no critical vulnerabilities, but review the flagged issues in the Security Report section before adding it to your workflow.
Clone the repository with "git clone https://github.com/helixnow/deep-student" and add it to your Claude Code skills directory (see the Installation section above).
deep-student is primarily written in TypeScript. It is open-source under helixnow on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other AI Agents skills you can browse and compare side by side. Open the AI Agents category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh deep-student against similar tools.
No comments yet. Be the first to share your thoughts!
⚠️ Third-Party Software Notice
This skill is third-party open-source software developed and hosted independently on GitHub. SkillsLLM is an informational directory and does not control or maintain the underlying repository.
Any security checks, ratings, or warnings displayed by SkillsLLM are automated and limited in scope. They do not constitute a security certification or guarantee that the software is safe, error-free, or free from malicious code, vulnerabilities, compromised dependencies, or prompt-injection risks.
Review the source code, permissions, dependencies, and configuration before installing or running any third-party skill. Use is at your own risk. To the maximum extent permitted by applicable law, SkillsLLM is not liable for losses arising from third-party software.
简体中文 | English
It's not that learning is hard — it's that learning tools are too scattered.
Study materials, note-taking, mind maps, quizzes, translation, and flashcard review — all in one unified learning workbench.
Think of it as: research notebook + knowledge workspace + mind mapping + practice + translation but they all share the same learning data and workflow.
Website · Download · Quick Start · User Guide · Report Issues · Contributing
Learning workflows are spread across too many tools — read here, take notes there, build mind maps elsewhere, review in yet another app. PDF readers, mind-mapping tools, translation apps, note-taking tools, LMS platforms, arXiv, flashcard apps, AI assistants… every tool is its own silo. Once your learning data is scattered, you spend more energy shuttling between tools than actually learning.
DeepStudent's answer: give AI native read-write access to all your learning data. One sentence from you, and it generates a mind map from your textbook, creates questions from your materials, turns key points into flashcards, searches and downloads papers, or researches the web and writes conclusions into your notes — all without leaving the workbench.
| Capability | DeepStudent |
|---|---|
| AI Q&A over materials | ✓ 12 providers |
| Cross-platform out-of-box | ✓ Win/Mac/Linux/Android |
| Smart memory system | ✓ AI-driven persistent |
| Note-taking system | ✓ rich text + tags + AI |
| AI-generated mind maps | ✓ |
| AI quiz + practice modes | ✓ |
| Flashcards + SRS | ✓ APKG / FSRS |
| Translation + close reading | ✓ 7 domain presets |
| Cross-module data flow | ✓ unified data layer |
The core idea isn't "more features" — it's the unified data layer. The same material can be read, queried, turned into a mind map, used to generate quizzes, made into flashcards, researched, and written back — no data shuttling between apps.
| Capability | DeepStudent |
|---|---|
| Local-first storage | ✓ |
| Cloud sync | △ experimental (backup-style, not real-time collab) |
| Open source / self-host | ✓ AGPL-3.0 |
| Unified data layer (VFS) | ✓ |
| Auto-index on import | ✓ incl. OCR |
| Mind map ↔ outline mode | ✓ |
| Deep research + papers | ✓ multi-engine + arXiv |
| AI essay correction | ✓ multi-scenario |
| MCP ecosystem / skills | ✓ native + presets1 |
| Real-time collaboration | ✗ |
| Community & ecosystem | △ new project |
1 agent browser automation: Windows + macOS only(Linux has WebKitGTK eval bridge code, but Agent tool surface remains closed)
Study around your materials, not just general chat.
Organize materials, notes, questions, mind maps, translations, and flashcards in one place.
Structure your knowledge, not just get answers.
Turn textbooks and exam papers into practice-ready question banks.
Push understanding into long-term memory.
Study around your documents, not just open them.
Translation as part of your learning chain.