vercel-automation

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s capabilities broadly match its Vercel automation purpose, and the MCP endpoint appears to be an official Composio/Rube service rather than an unknown installer. However, it routes all Vercel access through a third-party hosted MCP, enables high-impact write operations, and includes setup guidance that is outdated/incomplete about current API-key requirements. This looks like a legitimate but medium-risk proxy integration, not confirmed malware.

Confidence: 86%Severity: 61%
Audit Metadata
Analyzed At
Mar 29, 2026, 03:32 PM
Package URL
pkg:socket/skills-sh/sickn33%2Fantigravity-awesome-skills%2Fvercel-automation%2F@a043dff8ab3888f5413584f036cc276bcc470fdf