vercel-deploy
Warn
Audited by Gen Agent Trust Hub on Apr 11, 2026
Risk Level: MEDIUMDATA_EXFILTRATIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The script packages the target directory into a tarball and uploads it to a remote endpoint (
claude-skills-deploy.vercel.com). While the destination is a well-known service domain, the script fails to exclude sensitive files like.env, SSH keys, or cloud credentials. This creates a significant risk of exposing private secrets and production configurations during the deployment process. - [COMMAND_EXECUTION]: The deployment script performs automated write operations on the user's local filesystem. It includes logic to rename files (e.g., renaming a single HTML file to
index.html) without explicit user confirmation for that specific action. This can lead to unexpected changes in the project structure. - [PROMPT_INJECTION]: The skill employs metadata poisoning by falsely claiming 'vercel' as the author in the YAML frontmatter. This impersonation of a well-known organization can mislead both the AI agent and the user into granting the skill higher levels of trust or access than an unverified third-party script should receive.
Audit Metadata