deploy-to-vercel
Fail
Audited by Snyk on May 3, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 1.00). The skill contains explicit code that packages and uploads the user's project to third‑party "claimable" deploy endpoints (external domains not Vercel-owned) and instructs sandbox permission escalation for network egress — this is direct data exfiltration to untrusted servers and constitutes a high‑risk backdoor vector even though no obfuscation or remote shell code is present.
Issues (1)
E006
CRITICALMalicious code pattern detected in skill scripts.
Audit Metadata