vercel-optimize

Pass

Audited by Gen Agent Trust Hub on Jul 3, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill uses execFile for all interactions with the Vercel CLI, which prevents shell injection by passing arguments as an array rather than a single string shell command.
  • [SAFE]: The code includes robust redaction logic in lib/vercel.mjs to ensure that Vercel tokens, project IDs, and other sensitive identifiers are not leaked in logs or error messages.
  • [SAFE]: Remote data collection is restricted to the official Vercel CLI and API. The skill uses deterministic gates to identify investigation candidates, ensuring the agent only inspects files directly linked to observed performance or cost issues.
  • [SAFE]: The skill implements a verification step for all generated recommendations, checking them against a curated documentation library and the project's actual framework versions to prevent hallucinations or invalid advice.
  • [SAFE]: No suspicious obfuscation, persistence mechanisms, or unauthorized data exfiltration patterns were detected. The skill operates within a temporary run directory and does not modify the user's environment configuration.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 3, 2026, 11:33 AM
Security Audit — agent-trust-hub — vercel-optimize