cost-vercel

Pass

Audited by Gen Agent Trust Hub on Apr 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute Vercel CLI commands such as vercel ls and vercel project ls to retrieve project metadata and deployment status.
  • [EXTERNAL_DOWNLOADS]: The skill recommends installing the official vercel CLI utility from the public NPM registry for project inspection. This is standard configuration for interacting with a well-known service.
  • [PROMPT_INJECTION]: The skill incorporates data from Vercel CLI outputs and API responses into the agent's context, creating an indirect prompt injection surface.
  • Ingestion points: CLI command output and JSON responses from api.vercel.com (SKILL.md).
  • Boundary markers: Absent; the instructions do not specify delimiters or delimiters for tool output.
  • Capability inventory: Includes shell command execution via CLI and network operations via curl.
  • Sanitization: No explicit validation or sanitization of data retrieved from external tools is described.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 1, 2026, 07:45 AM
Security Audit — agent-trust-hub — cost-vercel