vercel-automation

Fail

Audited by Socket on Mar 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS: The skill is purpose-aligned and uses an apparently official Composio/Rube pathway, with no download-execute behavior or obvious malware indicators. Risk comes from third-party mediation of Vercel OAuth/API access and the ability to perform high-impact infrastructure changes through a hosted MCP service.

Confidence: 87%Severity: 58%
Audit Metadata
Analyzed At
Mar 18, 2026, 03:42 PM
Package URL
pkg:socket/skills-sh/davepoon%2Fbuildwithclaude%2Fvercel-automation%2F@ad535b9c7c92dffe860009612818de5b47400fb2