add-vercel

Warn

Audited by Socket on Aug 30, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose is plausible and the Vercel CLI source is mostly coherent, but the skill’s core auth model routes a powerful Vercel token through third-party OneCLI infrastructure and then propagates it to all agents. That combination makes the data flow and permission scope disproportionate to a narrowly scoped deployment helper.

Confidence: 89%Severity: 78%
SecurityMEDIUM
container-skills/vercel-cli/SKILL.md

SUSPICIOUS. The core Vercel functionality is aligned and uses the official CLI, but the skill’s auth model routes credentials and API traffic through OneCLI’s third-party proxy using placeholder-token indirection. That intermediary credential/data path, plus raw OneCLI installer trust and delegated agent chaining, makes the footprint higher risk than a normal direct-to-Vercel deployment skill.

Confidence: 89%Severity: 74%
Audit Metadata
Analyzed At
Aug 30, 2026, 02:01 AM
Package URL
pkg:socket/skills-sh/nanocoai%2Fnanoclaw%2Fadd-vercel%2F@0adbcb48a29bfa9f8a6dea4f4c6e7b65531b80cdcd6df6fe59030bd8422581d2
Security Audit — socket — add-vercel