vibe-deploy

Warn

Audited by Socket on Mar 30, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill’s stated purpose matches its capabilities: it is a deployment guide for iblai apps across Vercel, Docker, and Tauri targets. The main concern is install/execution trust: it invokes an official but unpinned Vercel CLI and depends on an `iblai` CLI whose exact public provenance was not clearly verifiable from the provided evidence. Data flows otherwise appear proportionate and aligned with iblai deployment, with no clear credential-harvesting or exfiltration behavior shown.

Confidence: 82%Severity: 78%
Audit Metadata
Analyzed At
Mar 30, 2026, 02:08 PM
Package URL
pkg:socket/skills-sh/iblai%2Fvibe%2Fvibe-deploy%2F@cc3fd62f161c781941421850433bbcc598d7f5c0