vercel

Fail

Audited by Socket on Mar 12, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The vercel skill shows coherent purpose-capability alignment: it uses curl to manage Vercel resources via the official API as described. Credential usage (VERCEL_TOKEN) is correctly scoped to API authentication, with no indication of credential harvesting or exfiltration beyond standard API calls. Data flow is straightforward: token -> API -> responses parsed locally. No suspicious install sources or autonomous actions detected. Overall, the footprint is benign and proportionate to its stated goal, with some caution around ensuring logs do not inadvertently reveal secrets.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 12, 2026, 03:22 PM
Package URL
pkg:socket/skills-sh/vm0-ai%2Fvm0-skills%2Fvercel%2F@871d161cfc15316a7820b4e15f78f5524adf5848