NYC

vercel-blob

Fail

Audited by Socket on Feb 15, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This is documentation and example code for legitimate use of the official Vercel Blob SDK. Capabilities align with the stated purpose, network interactions point to Vercel storage endpoints, and credential usage (server token vs client tokens) is explicitly called out and constrained. No malicious code or obfuscation is present. Notable issues: small documentation inconsistencies (Dependencies: None), an odd 'https://dummy' Request placeholder that could confuse implementers, and optimistic marketing phrasing. Security risk is low if developers follow the guidance (never expose BLOB_READ_WRITE_TOKEN, validate files, use multipart for large files).

Confidence: 35%Severity: 20%
Audit Metadata
Analyzed At
Feb 15, 2026, 08:58 PM
Package URL
pkg:socket/skills-sh/ovachiever%2Fdroid-tings%2Fvercel-blob%2F@286991f438ed9c29965091a1360e4396dc7e610b