vercel-automation

Fail

Audited by Socket on Feb 20, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

[Skill Scanner] Natural language instruction to download and install from URL detected This document is a legitimate-looking integration guide for automating Vercel via a Composio/Rube MCP-managed toolkit. There is no embedded malicious code in the provided file. The primary security concern is architectural: routing OAuth and API traffic through a third-party MCP (https://rube.app/mcp) centralizes tokens and high-privilege operations and therefore increases the risk of credential exfiltration or unauthorized changes if the MCP is untrusted or compromised. Before using this skill, validate the MCP's security posture, minimize granted scopes, and enable auditing and token rotation.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 20, 2026, 08:22 AM
Package URL
pkg:socket/skills-sh/davepoon%2Fbuildwithclaude%2Fvercel-automation%2F@ad535b9c7c92dffe860009612818de5b47400fb2