vercel

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill leverages the vercel CLI to perform a wide range of actions including deploying code, managing domains, and switching teams.
  • [INDIRECT_PROMPT_INJECTION]: The skill acts as an interface for managing project data and environment variables, which could be exploited by malicious content within a project.
  • Ingestion points: Project source code, configuration files, and environment variable values processed by commands like vercel, vercel build, and vercel env ls (SKILL.md).
  • Boundary markers: No specific delimiters or warnings to ignore instructions within project files are defined.
  • Capability inventory: The skill can execute deployments, modify project settings, manage domains, and read/write environment variables (SKILL.md).
  • Sanitization: The skill does not describe any validation or sanitization mechanisms for the data it processes.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 10:18 AM
Security Audit — agent-trust-hub — vercel