vercel-optimize
Pass
Audited by Gen Agent Trust Hub on May 20, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- Regulated Command Execution: The skill interacts with the Vercel CLI to retrieve metrics and billing data. These operations are conducted using restricted execution methods (execFile) and include comprehensive redaction logic in
lib/vercel.mjsto filter out authorization tokens and sensitive identifiers from logs. - Candidate-Bound Investigation Scope: To ensure privacy and efficiency, the skill follows a doctrine that limits the agent's read access to only the files directly associated with an observed performance signal. This prevents the agent from performing broad, recursive searches of the codebase.
- Automated Sanitization and Verification: Recommendations are processed through a series of deterministic sanitizers and verifiers. These checks ensure that any proposed changes are compatible with the project's framework version, free of precise (and potentially misleading) financial projections, and grounded in official documentation references.
Audit Metadata