lov-deploy-to-vercel
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONCREDENTIALS_UNSAFEDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill performs shell-based operations including checking for and installing the Vercel CLI (
npm i -g vercel), executing production deployments (vercel --yes --prod), and configuring domain aliases. - [EXTERNAL_DOWNLOADS]: The skill communicates with Cloudflare's official API (
api.cloudflare.com) to retrieve zone information and manage DNS records. It also performs status checks on the deployed domain viacurl. - [INDIRECT_PROMPT_INJECTION]: User-supplied domain arguments are interpolated directly into shell parsing commands (using
awkandsed) and into JSON request bodies for API interactions. This creates a potential surface for injection if the input is not validated prior to execution. - [CREDENTIALS_UNSAFE]: The skill utilizes the
CLOUDFLARE_API_KEYenvironment variable for DNS updates. The documentation suggests users persist this secret in shell configuration files like~/.zshrc. - [DYNAMIC_EXECUTION]: The skill executes inline Python code (
python3 -c) and Node.js scripts (node -p) via the command line to parse JSON data and extract metadata frompackage.json.
Audit Metadata