vercel-ai-sdk

Warn

Audited by Socket on Mar 24, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's capabilities mostly match its stated purpose as an LLM SDK guide, and its install path is standard PyPI/uv rather than a raw downloader. The main concern is provenance mismatch: the branded package is maintained by a third party, not a verifiable Vercel publisher, plus optional gateway/MCP patterns introduce extra trust and data-routing risk. This looks more like a moderately risky third-party developer skill than overtly malicious content.

Confidence: 86%Severity: 56%
Audit Metadata
Analyzed At
Mar 24, 2026, 07:46 AM
Package URL
pkg:socket/skills-sh/vercel-labs%2Fpy-ai%2Fvercel-ai-sdk%2F@c6f8692fd431cf52d2ccec14aa23a169c419c7ff