vercel-deploy

Pass

Audited by Gen Agent Trust Hub on Sep 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the official vercel CLI to perform all deployment and environment management tasks. These operations are restricted to the vercel binary via platform configuration, preventing arbitrary shell access.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes output from command-line tools that could be influenced by external state. Ingestion points: Output from vercel ls and vercel env ls (SKILL.md). Boundary markers: The instructions do not define specific delimiters for command output. Capability inventory: The skill can execute deployments, promotions, and environment variable updates. Sanitization: The skill mitigates risks by requiring explicit human confirmation for all production-impacting actions and verifying project linkage before execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 1, 2026, 08:22 AM
Security Audit — agent-trust-hub — vercel-deploy