vercel
Warn
Audited by Socket on Apr 22, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s purpose matches Vercel administration, and the CLI install path appears legitimate, but the actual data flow is mediated through Membrane rather than direct Vercel APIs. That third-party credential and API proxying is disproportionate for a simple Vercel integration and materially increases trust and data exposure risk, especially with access to decrypted environment variables and destructive account actions.
Confidence: 89%Severity: 68%
Audit Metadata