lov-deploy-to-vercel

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONCREDENTIALS_UNSAFEDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill performs shell-based operations including checking for and installing the Vercel CLI (npm i -g vercel), executing production deployments (vercel --yes --prod), and configuring domain aliases.
  • [EXTERNAL_DOWNLOADS]: The skill communicates with Cloudflare's official API (api.cloudflare.com) to retrieve zone information and manage DNS records. It also performs status checks on the deployed domain via curl.
  • [INDIRECT_PROMPT_INJECTION]: User-supplied domain arguments are interpolated directly into shell parsing commands (using awk and sed) and into JSON request bodies for API interactions. This creates a potential surface for injection if the input is not validated prior to execution.
  • [CREDENTIALS_UNSAFE]: The skill utilizes the CLOUDFLARE_API_KEY environment variable for DNS updates. The documentation suggests users persist this secret in shell configuration files like ~/.zshrc.
  • [DYNAMIC_EXECUTION]: The skill executes inline Python code (python3 -c) and Node.js scripts (node -p) via the command line to parse JSON data and extract metadata from package.json.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 10:06 PM
Security Audit — agent-trust-hub — lov-deploy-to-vercel