vercel-deploy
Deploy applications and websites to Vercel. Use when the user requests deployment actions like "deploy my app", "deploy and give me the link", "push this live", or "create a preview deployment".
Savant verdict: Review advised
SkillSpector or the source hub flagged patterns to review before use.
Live evaluation
56overall
52quality
46compliance
59grounding
65actionability
70efficiency
Why this score may understate the skillThe live evaluation is a chat-only run: the model follows the skill's instructions but can't execute its scripts, call tools or reach the network.
- Ships 1 script the live run can't execute; outputs describe those steps rather than perform them.
- Expects tools, MCP servers, installs or network access that a chat-only run doesn't have.
0 pass · 3 investigate · 5 fail across 8 cases. Jev accepted 8 of 16 LLM-drafted cases. Drafted and run by nvidia/nemotron-3-super-120b-a12b, validated and scored by jev-latest.
- Deploy my React app to Vercel and give me the preview linkpositive case · fail
- Push this live as a preview deploymentpositive case · fail
- Create a preview deployment for my static sitepositive case · investigate
- Deploy my app but I don't have Vercel CLI installededge case · investigate
- Explain how Vercel pricing works for hobby vs pro plansnegative case · fail
- Help me set up a custom domain on my existing Vercel deploymentnegative case · fail
- Deploy my app to Verceledge case · investigate
- Deploy this to Vercel and give me the linkedge case · fail
Safety (NVIDIA SkillSpector)
Risk score
26/100
Recommendation
CAUTION
Severity
MEDIUM
Savant decision
Review advised
SkillSpector rated it CAUTION with a risk score of 20/100 or more; review the findings before use. SkillSpector 2.12.0, static analysis.
2 patterns found
- Privilege Escalation: .env'high · scripts/deploy.sh:204 · Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
- MCP Least Privilege: Skill declares no tool scope ('permissions' or 'allowed-tools') but code capabilities were detected: shell.medium · SKILL.md:1 · Without declared permissions the skill's intent is opaque and cannot be validated.
Structure
- Ships 1 executable scriptscripts/deploy.sh. Review what they do before enabling the skill for agents with tool access.
SKILL.md
--- name: vercel-deploy description: Deploy applications and websites to Vercel. Use when the user requests deployment actions like "deploy my app", "deploy and give me the link", "push this live", or "create a preview deployment". --- # Vercel Deploy Deploy any project to Vercel instantly. **Always deploy as preview** (not production) unless the user explicitly asks for production. ## Prerequisites - Check whether the Vercel CLI is installed **without** escalated permissions (for example, `command -v vercel`). - Only escalate the actual deploy command if sandboxing blocks the deployment network calls (`sandbox_permissions=require_escalated`). - The deployment might take a few minutes. Use appropriate timeout values. ## Quick Start 1. Check whether the Vercel CLI is installed (no escalation for this check): ```bash command -v vercel ``` 2. If `vercel` is installed, run this (with a 10 minute timeout): ```bash vercel deploy [path] -y ``` **Important:** Use a 10 minute (600000ms) timeout for the deploy command since builds can take a while. 3. If `vercel` is not installed, or if the CLI fails with "No existing credentials found", use the fallback method below. ## Fallback (No Auth) If CLI fails with auth error, use the deploy script: ```bash skill_dir="<path-to-skill>" # Deploy current directory bash "$skill_dir/scripts/deploy.sh" # Deploy specific project bash "$skill_dir/scripts/deploy.sh" /path/to/project # Deploy existing tarball bash "$skill_dir/scripts/deploy.sh" /path/to/project.tgz ``` The script handles framework detection, packaging, and deployment. It waits for the build to complete and returns JSON with `previewUrl` and `claimUrl`. **Tell the user:** "Your deployment is ready at [previewUrl]. Claim it at [claimUrl] to manage your deployment." ## Production Deploys Only if user explicitly asks: ```bash vercel deploy [path] --prod -y ``` ## Output Show the user the deployment URL. For fallback deployments, also show the claim URL. **Do not** curl or fetch the deployed URL to verify it works. Just return the link. ## Troubleshooting ### Escalated Network Access If deployment fails due to network issues (timeouts, DNS errors, connection resets), rerun the actual deploy command with escalated permissions (use `sandbox_permissions=require_escalated`). Do not escalate the `command -v vercel` installation check. The deploy requires escalated network access when sandbox networking blocks outbound requests. Example guidance to the user: ``` The deploy needs escalated network access to deploy to Vercel. I can rerun the command with escalated permissions—want me to proceed? ```