skills/vercel/flags/flags-sdk/Gen Agent Trust Hub

flags-sdk

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • Command Line Operations: The skill utilizes the Vercel CLI to perform project linking (vercel link), pull environment variables (vercel env pull), and manage remote flags. While these operations involve authentication and environment modification, they are necessary for the skill's intended functionality within a development workflow.
  • External Package Dependencies: The instructions guide the installation of various NPM packages, such as flags, @flags-sdk/vercel, and other provider adapters. These are standard dependencies for the Flags SDK ecosystem and are sourced from official registries.
  • Environment Variable and Token Handling: The skill manages sensitive data like VERCEL_OIDC_TOKEN and FLAGS_SECRET. The documentation includes specific safety instructions to prevent the accidental exposure of these secrets in logs or terminal output, reflecting a security-conscious approach to credential management.
  • Indirect Input Processing: The feature flag evaluation logic ingests data from request headers and cookies via the identify and decide hooks. This represents a potential surface for indirect input influence, which is a standard characteristic of dynamic feature flagging systems and is handled with a low-severity consideration.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 11:49 AM
Security Audit — agent-trust-hub — flags-sdk