ai-gateway
Pass
Audited by Gen Agent Trust Hub on Mar 15, 2026
Risk Level: SAFE
Full Analysis
- [Authentication Best Practices]: The skill strongly recommends the use of OpenID Connect (OIDC) via the
vercel env pullcommand. This is a security best practice that replaces long-lived static API keys with short-lived, automatically rotated tokens, reducing the risk of credential exposure.- [Official Resource Integration]: The skill references official Vercel documentation, GitHub repositories, and API endpoints (e.g.,api.vercel.com) for configuration and log management. These are well-known, trusted services associated with the skill's author.- [Validation and Linting]: The skill includes several validation patterns designed to ensure code quality and adherence to specific model naming conventions. These patterns check for hyphenation in version numbers, missing provider prefixes, and the use of hardcoded provider keys, providing helpful feedback to the developer.- [Instructional Model Guidance]: Within the validation and documentation sections, the skill includes instructions regarding model selection and versioning. While these patterns direct the agent toward specific model identifiers (such as GPT-5.4 and Claude 4.x), they are provided within the context of the gateway's routing functionality and do not represent a security bypass or malicious instruction.- [Data Handling]: References to fetching audit logs via the Vercel API are consistent with the skill's purpose. The instructions specify that content logging is disabled by default, which is a privacy-conscious configuration.
Audit Metadata