Vercel AI Sdk Security Scan

Defensive security scan for the Vercel AI SDK (`ai` package). Detects unbounded experimental_attachments, streamText output rendered as HTML, tool execute handlers running shell from args, useChat endpoints without auth, generateObject schemas missing strict mode, and onFinish leaking content to telemetry. Invoke when the user asks to "review", "audit", or "scan" code using the AI SDK.

Dolphinllc c2c76a6 5.2 KB Updated

File contents

Dolphinllc/claude-security-skills/tree/main/skills/defensive/genai/vercel-ai-sdk-security-scan commit c2c76a60df

Frequently asked questions

npx skillmds@latest add dolphinllc/vercel-ai-sdk-security-scan