ai

Warn

Audited by Socket on May 19, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill mostly matches its stated purpose as an AI SDK reference, and there is no direct malware, stealth, or credential theft behavior. However, the install target appears to be a third-party package using Vercel branding, and the documented support for custom base URLs and transitive MCP/stdIO tool installation increases trust and credential-routing risk beyond a straightforward docs skill.

Confidence: 87%Severity: 61%
Audit Metadata
Analyzed At
May 19, 2026, 05:52 AM
Package URL
pkg:socket/skills-sh/vercel-labs%2Fpy-ai%2Fai%2F@00f3bf4a4180298ee8899308a5e25c9a0f60f835
Security Audit — socket — ai