add-vercel

Warn

Audited by Socket on Apr 26, 2026

2 alerts found:

AnomalySecurity
AnomalyLOW
container-skills/vercel-cli/SKILL.md

SUSPICIOUS: the stated purpose is legitimate and most CLI usage matches Vercel documentation, but the auth/data-flow model is not native to Vercel. Routing Vercel credentials and API requests through third-party OneCLI proxy injection is an integrity and credential-forwarding risk disproportionate to a simple deployment skill.

Confidence: 89%Severity: 69%
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core purpose is coherent: enabling Vercel deployment via the official CLI. The main risk is disproportionate credential handling and scope: a full-account long-lived Vercel token is stored in OneCLI, then assigned to every agent and injected through a third-party gateway. This is not clearly malicious, but it materially expands trust and blast radius beyond what a narrowly scoped deployment skill should need.

Confidence: 86%Severity: 72%
Audit Metadata
Analyzed At
Apr 26, 2026, 09:52 PM
Package URL
pkg:socket/skills-sh/qwibitai%2Fnanoclaw%2Fadd-vercel%2F@09790b2a9e9786a3d3e6f890b7a5a6a60aa4ac1b