vercel-plugin-eval

Fail

Audited by Socket on Mar 9, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill describes a live-eval workflow for vercel-plugin with automated session orchestration and log-based verification. While the documented goals (hook coverage, dedup validation, and coverage reporting) align with a testing/QA context, the footprint shows notable security concerns: unverifiable plugin installation from a GitHub URL, potential exposure of sensitive data via local logs, and execution of real CLI sessions that could be misused if prompt content is untrusted. The design choice to rely on local logs and ephemeral claim files is fragile from a security perspective and could enable data leakage if logs are exposed. Overall, the footprint is suspicious rather than benign, with multiple risk signals concentrated around supply-chain trust (unverifiable binary), data exposure (logs/claims), and potential command execution surfaces during prompt handling. I would categorize this as SUSPICIOUS with elevated security risk pending stricter controls (verifiable source, sandboxed sessions, redacted logs, explicit permission prompts).

Confidence: 98%
Audit Metadata
Analyzed At
Mar 9, 2026, 06:29 AM
Package URL
pkg:socket/skills-sh/vercel-labs%2Fvercel-plugin%2Fvercel-plugin-eval%2F@b16a6ca2c6385d15873958b589b598e8367dc3b7