vercel-deploy

Warn

Audited by Socket on Mar 20, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/deploy.sh

No clear signs of classical malware (no obfuscated payloads, no persistence, no reverse shells, no credential harvesting code reading environment variables). The main security concern is that it uploads the entire project directory (minus some exclusions) to a hardcoded third-party endpoint — this is a potential data exfiltration vector if the endpoint is untrusted or if sensitive files are present in the project. Use caution: verify the DEPLOY_ENDPOINT is legitimate before running, and ensure secrets are not present in the project tree (or add stricter exclude rules).

Confidence: 90%Severity: 60%
Audit Metadata
Analyzed At
Mar 20, 2026, 01:03 AM
Package URL
pkg:socket/skills-sh/Hainrixz%2Fclaude-webkit%2Fvercel-deploy%2F@d1f088c3bf9206929b46caa40491f7180c651587
Security Audit — socket — vercel-deploy