vercel-blob
Fail
Audited by Socket on Feb 15, 2026
1 alert found:
MalwareMalwareSKILL.md
HIGHMalwareHIGH
SKILL.md
This is documentation and example code for legitimate use of the official Vercel Blob SDK. Capabilities align with the stated purpose, network interactions point to Vercel storage endpoints, and credential usage (server token vs client tokens) is explicitly called out and constrained. No malicious code or obfuscation is present. Notable issues: small documentation inconsistencies (Dependencies: None), an odd 'https://dummy' Request placeholder that could confuse implementers, and optimistic marketing phrasing. Security risk is low if developers follow the guidance (never expose BLOB_READ_WRITE_TOKEN, validate files, use multipart for large files).
Confidence: 35%Severity: 20%
Audit Metadata