ai

Warn

Audited by Socket on May 12, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's core purpose is coherent for an AI SDK guide, and the credential scope is mostly proportionate, but the install/package provenance is not cleanly aligned with Vercel's official tooling, and the MCP example adds transitive remote-execution risk. Main concern is supply-chain and proxy/data-routing trust, not confirmed malware.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
May 12, 2026, 11:38 AM
Package URL
pkg:socket/skills-sh/vercel-labs%2Fpy-ai%2Fai%2F@ff4081918fc93e21a552235010b36417de135317