skills/vercel-labs/error/vercel-error/Gen Agent Trust Hub

vercel-error

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFE
Full Analysis
  • Structured Data Ingestion: The skill involves analyzing project files such as package.json, lockfiles, and source code. While this represents a surface for indirect prompt injection, the skill includes explicit instructions to avoid parsing rendered output and to maintain strict boundary checks between internal diagnostics and public error responses.
  • Data Exposure Prevention: The instructions emphasize the exclusion of sensitive information (credentials, tokens, raw payloads) from error metadata and attributes. It provides specific guidance on distinguishing between developer-facing diagnostics and client-safe messages to prevent accidental information disclosure.
  • Recovery Authority Protocols: A significant security feature of this skill is its 'Recovery authority' guidance, which instructs that error messages and links should never be used to authorize actions or be automatically followed. This reinforces the principle of human-in-the-loop for sensitive operations.
  • Trusted External References: The skill references established industry standards from organizations like Google, OWASP, and OpenTelemetry, as well as official Vercel documentation, to ensure that error handling follows recognized security and observability patterns.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 02:13 AM
Security Audit — agent-trust-hub — vercel-error