vercel-breach-best-practices
Incident-response and hardening playbook for Vercel compromises (platform breach, leaked access token, compromised integration, suspected env-var exposure, post-incident hardening). Written after the April 2026 Vercel incident. Preserves audit evidence, enumerates projects and env vars, classifies secrets by upstream service, surfaces exposure gaps the Vercel API cannot see, and produces a prioritized [DONE]/[MANUAL]/[BLOCKED] checklist with direct dashboard rotation links. The skill is an advisor, not an autonomous rotator — the user rotates every credential themselves in their own dashboards. Use when the user mentions "vercel got breached", "rotate my secrets", "leaked vercel token", "env vars exposed", "April 2026 Vercel incident", or similar, even if "breach" isn't the exact word.
2026-04-19