vercel
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill documentation includes several Vercel CLI commands such as
vercel login,vercel env pull, andvercel logsintended for project management and credential handling. - [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of untrusted data from external sources, creating a potential surface for indirect prompt injection.
- Ingestion points: External data processed from
vercel logs <deployment-url>and content retrieved from preview deployment URLs as described inSKILL.md. - Boundary markers: The instructions lack specific delimiters or "ignore embedded instructions" warnings for data returned by these external sources.
- Capability inventory: The skill utilizes the
vercelCLI,curl, andInvoke-WebRequestacrossSKILL.mdandREADME.md. - Sanitization: There is no mention of sanitization, validation, or escaping of content retrieved from deployments or logs before it is processed by the agent.
Audit Metadata