Back to skill

Security audit

Vercel Deploy — BLOCKED, failed & 404 deploys, 4.5 MB limit

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed Vercel deployment troubleshooting guide with purpose-aligned API calls and an optional webhook relay, with no hidden execution or credential misuse found.

Before installing, be comfortable providing a scoped Vercel token through an environment variable and only run the optional relay if you can protect and purge its spool directory. Review any npm package before enabling install scripts, and use the relay only with verified webhook signatures and a trusted HTTPS forward target.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 27)May include surrounding context.

md
| Item | What this skill needs |
|---|---|
| Credentials | `VERCEL_TOKEN`: an access token you create in the Vercel dashboard, scoped to the one team. Env var only; §1 passes it to curl on stdin, never in argv (visible in `ps`). Never committed. |
| Network out | `api.vercel.com` (read-only GET), `openapi.vercel.sh` (schema), a DoH resolver. The §4 relay also calls **your** forward URL. |
| Data persisted | Only the §4 relay: raw webhook events in `SPOOL_DIR` until a 2xx forward, then deleted. If events carry personal data (emails, names), you need a legal basis, keep only the fields you forward, and purge `*.bad` quarantine files on a schedule you set (suggested: 7 days). |
| Writes | None in §1-§3, §5. Every deploy command is run by you, not by this skill. |

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 39)May include surrounding context.

md
: "${VERCEL_TOKEN:?set VERCEL_TOKEN}" "${VERCEL_PROJECT:?set VERCEL_PROJECT (id or name)}"
q="projectId=${VERCEL_PROJECT}&limit=${N:-5}${VERCEL_TEAM_ID:+&teamId=$VERCEL_TEAM_ID}"
printf 'Authorization: Bearer %s\n' "$VERCEL_TOKEN" |   # builtin: token stays out of ps
  curl -sS --max-time 20 -H @- "https://api.vercel.com/v7/deployments?$q" | python3 -c '
import json, sys
try:
    d = json.load(sys.stdin)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 239)May include surrounding context.

md
## 6. Global CLI installs under npm 12

npm 12 blocks dependency install scripts by default (`--allow-scripts <package-list>` exists on npm 12.0.2). The install reports success, and a CLI that downloads its native binary in `postinstall` breaks on first run (*observed 2026-08*: `could not find the CLI binary`). After any `npm i -g`, run `<cli> --version`. If broken: `npm install -g --allow-scripts=<pkg> <pkg>@latest`. `--allow-scripts` is refused on `--prefix` installs; use `allowScripts` in `package.json` or `.npmrc` there.

## Output Format

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 39)May include surrounding context.

md
: "${VERCEL_TOKEN:?set VERCEL_TOKEN}" "${VERCEL_PROJECT:?set VERCEL_PROJECT (id or name)}"
q="projectId=${VERCEL_PROJECT}&limit=${N:-5}${VERCEL_TEAM_ID:+&teamId=$VERCEL_TEAM_ID}"
printf 'Authorization: Bearer %s\n' "$VERCEL_TOKEN" |   # builtin: token stays out of ps
  curl -sS --max-time 20 -H @- "https://api.vercel.com/v7/deployments?$q" | python3 -c '
import json, sys
try:
    d = json.load(sys.stdin)

Static analysis

No suspicious patterns detected.