vercel-automation
Fail
Audited by Socket on Feb 20, 2026
1 alert found:
MalwareMalwareSKILL.md
HIGHMalwareHIGH
SKILL.md
[Skill Scanner] Natural language instruction to download and install from URL detected This document is a legitimate-looking integration guide for automating Vercel via a Composio/Rube MCP-managed toolkit. There is no embedded malicious code in the provided file. The primary security concern is architectural: routing OAuth and API traffic through a third-party MCP (https://rube.app/mcp) centralizes tokens and high-privilege operations and therefore increases the risk of credential exfiltration or unauthorized changes if the MCP is untrusted or compromised. Before using this skill, validate the MCP's security posture, minimize granted scopes, and enable auditing and token rotation.
Confidence: 95%Severity: 90%
Audit Metadata