vercel-agent-vercel-optimize

Pass

Audited by Gen Agent Trust Hub on Aug 8, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill utilizes the Vercel CLI to collect production metrics and usage data. This behavior is documented and strictly necessary for the skill's purpose of optimizing Vercel deployments.
  • [SAFE]: Robust internal controls are provided through a comprehensive sanitization and verification pipeline located in lib/sanitizers and lib/verify-claim.js. This system mechanically checks AI-generated recommendations against the project codebase and metric signals to prevent hallucinations or incorrect guidance.
  • [SAFE]: Command execution is restricted to specific Vercel CLI subcommands using execFile, which prevents shell injection vulnerabilities and ensures controlled execution.
  • [SAFE]: The skill employs a curated allow-list for external documentation references (references/docs-library.json), ensuring that all citations point to trusted Vercel or framework-maintained domains and are appropriate for the user's specific software versions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 8, 2026, 02:47 PM
Security Audit — agent-trust-hub — vercel-agent-vercel-optimize