skills/openai/plugins/vercel-api/Gen Agent Trust Hub

vercel-api

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFE
Full Analysis
  • Credential Security: The skill provides instructions for authenticating with Vercel using tokens. It follows security best practices by suggesting the use of environment variables (e.g., VERCEL_TOKEN) rather than hardcoding sensitive credentials in the instruction files or scripts.
  • Integration with Official Services: The skill interacts with the platform's infrastructure through official API endpoints and MCP servers. All external links and resources point to legitimate domains and repositories managed by the service provider, which is consistent with the skill's stated purpose.
  • External Package Management: The skill recommends the use of official software development kits (SDKs) and handlers for interacting with the platform. These packages, such as @vercel/sdk and mcp-handler, are standard tools and do not introduce unverifiable dependencies.
  • Data Retrieval and Processing: The skill includes capabilities to retrieve and process information from external sources, which is a common pattern for management and observability tools.
  • Ingestion points: Data enters the agent's context through tools that query deployment logs, build output, and documentation search results in SKILL.md.
  • Capability inventory: The skill facilitates API calls and CLI commands to manage and read project resources.
  • Sanitization and Boundary Markers: The instructions do not specify custom delimiters or sanitization steps for the retrieved data, relying instead on the platform's default mechanisms for handling tool outputs and external content. Users should ensure the agent is authorized only for required projects to maintain the principle of least privilege.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 03:19 PM
Security Audit — agent-trust-hub — vercel-api