flags-sdk
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- Command Line Operations: The skill utilizes the Vercel CLI to perform project linking (
vercel link), pull environment variables (vercel env pull), and manage remote flags. While these operations involve authentication and environment modification, they are necessary for the skill's intended functionality within a development workflow. - External Package Dependencies: The instructions guide the installation of various NPM packages, such as
flags,@flags-sdk/vercel, and other provider adapters. These are standard dependencies for the Flags SDK ecosystem and are sourced from official registries. - Environment Variable and Token Handling: The skill manages sensitive data like
VERCEL_OIDC_TOKENandFLAGS_SECRET. The documentation includes specific safety instructions to prevent the accidental exposure of these secrets in logs or terminal output, reflecting a security-conscious approach to credential management. - Indirect Input Processing: The feature flag evaluation logic ingests data from request headers and cookies via the
identifyanddecidehooks. This represents a potential surface for indirect input influence, which is a standard characteristic of dynamic feature flagging systems and is handled with a low-severity consideration.
Audit Metadata