vercel-platforms
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill documents patterns for routing and data isolation that ingest untrusted request data, which constitutes a surface for indirect prompt injection attacks. \n
- Ingestion points: Tenant identifiers are extracted from user-controlled inputs including
request.headers.get('host')andrequest.nextUrl.pathnameas described inreferences/routing.mdandreferences/concepts.md. \n - Boundary markers: The provided implementation patterns do not include explicit instructions or markers to distinguish between legitimate tenant identifiers and embedded malicious instructions. \n
- Capability inventory: Resolved identifiers are used to drive sensitive application behaviors including internal route rewrites (
NextResponse.rewrite), user redirects, and the setting of custom security headers (x-tenant-id). The skill also describes the use of the Vercel SDK for programmatic project and domain management. \n - Sanitization: Input processing relies on simple string splitting and replacement without formal validation, filtering, or escaping of the extracted identifiers. \n- [PROMPT_INJECTION]: The skill includes deceptive metadata and content, such as a source verification date in the year 2026 and references to Next.js 16 (which is not currently released). While likely intended as a synthetic example, these misleading claims could cause an agent to generate non-functional code or follow incorrect framework conventions.
Audit Metadata