vercel-deploy

Fail

Audited by Snyk on Apr 28, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 0.90). This skill intentionally uploads a user's project tarball (without excluding common secret files like .env) to an external, third‑party deployment endpoint (claude-skills-deploy.vercel.com) with no authentication, which enables unauthorized data exfiltration and potential credential leakage; there is no evidence of remote code execution or obfuscated backdoors in the script itself, but the unauthenticated external upload/hosting behavior is high‑risk for abuse.

Issues (1)

E006
CRITICAL

Malicious code pattern detected in skill scripts.

Audit Metadata
Risk Level
CRITICAL
Analyzed
Apr 28, 2026, 01:27 AM
Issues
1
Security Audit — snyk — vercel-deploy