Skip to main content

vercel-breach-best-practices

Incident-response and hardening playbook for Vercel compromises (platform breach, leaked access token, compromised integration, suspected env-var exposure, post-incident hardening). Written after the April 2026 Vercel incident. Preserves audit evidence, enumerates projects and env vars, classifies secrets by upstream service, surfaces exposure gaps the Vercel API cannot see, and produces a prioritized [DONE]/[MANUAL]/[BLOCKED] checklist with direct dashboard rotation links. The skill is an advisor, not an autonomous rotator — the user rotates every credential themselves in their own dashboards. Use when the user mentions "vercel got breached", "rotate my secrets", "leaked vercel token", "env vars exposed", "April 2026 Vercel incident", or similar, even if "breach" isn't the exact word.

Jump to install

Source facts

Repository
MoizIbnYousaf/vercel-breach-best-practices
Last source activity
April 19, 2026 at 22:09
Detected SKILL.md language
English
Stars
6
Forks
0

Install options

The review-first prompt is selected by default. You can switch to a direct command or download a local copy.

Review the source files

Read SKILL.md and any companion files shown by SkillsMP before deciding whether to install.