vercel-deploy

Warn

Audited by Gen Agent Trust Hub on Apr 11, 2026

Risk Level: MEDIUMDATA_EXFILTRATIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The script packages the target directory into a tarball and uploads it to a remote endpoint (claude-skills-deploy.vercel.com). While the destination is a well-known service domain, the script fails to exclude sensitive files like .env, SSH keys, or cloud credentials. This creates a significant risk of exposing private secrets and production configurations during the deployment process.
  • [COMMAND_EXECUTION]: The deployment script performs automated write operations on the user's local filesystem. It includes logic to rename files (e.g., renaming a single HTML file to index.html) without explicit user confirmation for that specific action. This can lead to unexpected changes in the project structure.
  • [PROMPT_INJECTION]: The skill employs metadata poisoning by falsely claiming 'vercel' as the author in the YAML frontmatter. This impersonation of a well-known organization can mislead both the AI agent and the user into granting the skill higher levels of trust or access than an unverified third-party script should receive.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 11, 2026, 03:42 AM
Security Audit — agent-trust-hub — vercel-deploy