skills/openhands/extensions/vercel/Gen Agent Trust Hub

vercel

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill documentation includes several Vercel CLI commands such as vercel login, vercel env pull, and vercel logs intended for project management and credential handling.
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of untrusted data from external sources, creating a potential surface for indirect prompt injection.
  • Ingestion points: External data processed from vercel logs <deployment-url> and content retrieved from preview deployment URLs as described in SKILL.md.
  • Boundary markers: The instructions lack specific delimiters or "ignore embedded instructions" warnings for data returned by these external sources.
  • Capability inventory: The skill utilizes the vercel CLI, curl, and Invoke-WebRequest across SKILL.md and README.md.
  • Sanitization: There is no mention of sanitization, validation, or escaping of content retrieved from deployments or logs before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 03:36 PM
Security Audit — agent-trust-hub — vercel