vercel-composition-patterns
Warn
Audited by Gen Agent Trust Hub on Feb 24, 2026
Risk Level: MEDIUMPROMPT_INJECTIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: The skill uses deceptive metadata to misrepresent its origin and context. The
SKILL.mdandAGENTS.mdfiles identify the author as 'vercel', which is an impersonation of a trusted organization; the true author is 'yuji-hatakeyama'. Additionally, the document lists a future date of January 2026. This deceptive information is a form of metadata poisoning that could be used to bypass trust-based security evaluations. - [NO_CODE]: The skill files consist entirely of Markdown documentation and JSON metadata. There is no executable code, such as shell scripts, Python files, or JavaScript binaries, included in the skill package.
Audit Metadata