deploy-to-vercel

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXFILTRATION]: The skill identifies project configuration by reading .vercel/project.json and .vercel/repo.json. The fallback deployment scripts in the resources directory include specific logic to exclude sensitive credentials and secrets, such as .env files and the .git directory, from the project archive before it is transmitted. This reduces the risk of accidental secret exposure during the deployment process.
  • [EXTERNAL_DOWNLOADS]: The fallback deployment scripts utilize curl to upload project archives to external endpoints hosted on vercel.com and vercel.sh. These domains represent official infrastructure for a well-known technology service, and the operations are necessary for the skill's stated primary purpose of application deployment.
  • [COMMAND_EXECUTION]: The skill instructions utilize standard development tools including git, npm, and the vercel CLI. These tools are used for routine tasks such as linking projects, checking authentication status, and triggering deployments through version control systems or direct CLI commands.
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits an ingestion surface by parsing project data to determine framework settings.
  • Ingestion points: Project package.json files are read and processed by resources/deploy.sh and resources/deploy-codex.sh.
  • Boundary markers: Explicit delimiters or warnings regarding embedded data instructions are not present within the shell scripts.
  • Capability inventory: The skill has access to project files, network transmission tools (curl), and the vercel command-line interface.
  • Sanitization: Input variables, such as paths and detected framework names, are correctly quoted within the shell scripts to prevent command injection vulnerabilities during execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 11:19 PM
Security Audit — agent-trust-hub — deploy-to-vercel