vercel-deploy
Fail
Audited by Snyk on Apr 28, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 0.90). This skill intentionally uploads a user's project tarball (without excluding common secret files like .env) to an external, third‑party deployment endpoint (claude-skills-deploy.vercel.com) with no authentication, which enables unauthorized data exfiltration and potential credential leakage; there is no evidence of remote code execution or obfuscated backdoors in the script itself, but the unauthenticated external upload/hosting behavior is high‑risk for abuse.
Issues (1)
E006
CRITICALMalicious code pattern detected in skill scripts.
Audit Metadata