vercel-breach-best-practices

Warn

Audited by Socket on Apr 19, 2026

1 alert found:

Security
SecurityMEDIUM
scripts/enumerate.sh

No direct indicators of classic malware behavior are visible in this fragment (no reverse shells, persistence, arbitrary code execution, or network exfiltration to non-Vercel domains). However, the script is explicitly a broad, token-authorized reconnaissance/inventory tool: it enumerates projects and environment-variable metadata across all teams the token can access and labels likely secret-bearing keys. That makes it sensitive from a security perspective; misuse of a highly privileged token would enable attackers (or internal threat actors) to quickly map high-value configuration targets. Final risk is dominated by capability and output sensitivity rather than malicious payload characteristics.

Confidence: 66%Severity: 72%
Audit Metadata
Analyzed At
Apr 19, 2026, 07:30 PM
Package URL
pkg:socket/skills-sh/MoizIbnYousaf%2Fvercel-breach-best-practices%2Fvercel-breach-best-practices%2F@564e8251bd4e3003d0de85a7d8b63a9cc51df9b5