vercel-ai-sdk-security-scan
Pass
Audited by Gen Agent Trust Hub on May 18, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is entirely defensive in nature, providing an instructional framework for auditing applications built with the Vercel AI SDK (@ai-sdk). It helps identify critical security misconfigurations.- [SAFE]: Although the skill contains examples of dangerous code—including shell command injection via
execAsyncand XSS vectors viadangerouslySetInnerHTML—these are explicitly marked as negative patterns for identification and are not intended for execution.- [SAFE]: All external links point to official documentation for Vercel, which is a well-known and trusted service in the web development ecosystem.- [SAFE]: No malicious patterns such as obfuscation, hidden URLs, or unauthorized data exfiltration were identified during the analysis.
Audit Metadata