Atlas / MCP servers / nganiet / Vercel Integration

Vercel IntegrationSAFE

mcp/nganiet/vercel-integration

MCP server connecting Claude to Vercel

Verdict
SAFE
Grade
B
Trust score
87 /100
Exposed tools
15 8r · 5w · 2d
Transport
stdio
License
—
Stars
69
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A Model Context Protocol (MCP) integration for Vercel's REST API, providing programmatic access to Vercel deployment management through AI Assistants like Claude and Cursor.

📋 Overview Last updated: May 2025

This MCP server implements Vercel's core API endpoints as tools, enabling:

  • Deployment monitoring & management
  • Environment variable retrieval
  • Project deployment status tracking
  • Team creation and management
  • CI/CD pipeline integration

✨ Features

Current Tools

Deployment Management

  • vercel-list-all-deployments - List deployments with filtering
  • vercel-get-deployment - Retrieve specific deployment details
  • vercel-list-deployment-files - List files in a deployment
  • vercel-create-deployment - Create new deployments

Project Management

  • vercel-create-project - Create new Vercel projects
  • vercel-list-projects - List all projects with pagination
  • vercel-find-project - Find a specific project by ID or name
  • vercel-create-environment-variables - Create multiple environment variables
  • vercel-get-project-domain - Get information about a specific domain within a project

Environment Management

  • vercel-get-environments - Access project environment variables
  • vercel-create-custom-environment - Create custom environments for projects

Team Management

  • vercel-list-all-teams - List all accessible
Read from source at commit e5fc577e449aOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add vercel --env VERCEL_API_TOKEN=${VERCEL_API_TOKEN} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "vercel": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "VERCEL_API_TOKEN": "${VERCEL_API_TOKEN}"
      }
    }
  }
}
03

Exposed tools (15)

8 read · 5 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
vercel-create-custom-environmentwriteCreate a custom environment for a Vercel project. Note: Cannot be named
vercel-create-deploymentwriteCreate a new Vercel deployment with the v13/deployments API
vercel-create-environment-variableswriteCreate environment variables for a Vercel project
vercel-create-projectwriteCreate a new Vercel project
vercel-create-teamwriteCreate a new Vercel team
vercel-delete-projectdestructiveDelete a Vercel project by its ID or name
vercel-find-projectreadFind a Vercel project by its ID or name
vercel-get-deploymentreadGet a deployment by its ID or URL
vercel-get-environmentsreadRetrieve environment variables for a project by ID or name
vercel-get-project-domainreadGet information about a specific domain within a Vercel project
vercel-list-all-deploymentsreadList deployments under the authenticated user or team.
vercel-list-all-teamsreadList all teams under the authenticated account
vercel-list-deployment-filesreadList all files of a Vercel deployment
vercel-list-projectsreadList all projects under the authenticated user or team
vercel-remove-environment-variabledestructiveRemove an environment variable from a Vercel project
04

Trust audit

SAFEgrade B · trust 87/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (6 observation(s))
Network
declared (1 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (9)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
vercel-delete-project, vercel-remove-environment-variable
Why it matters. 2 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/deployments/handlers.ts:1
import { vercelFetch } from "../../utils/api.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/environments/handlers.ts:1
import { vercelFetch } from "../../utils/api.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/projects/handlers.ts:1
import { vercelFetch } from "../../utils/api.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/projects/handlers.ts:2
import { VERCEL_API } from "../../utils/config.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/teams/handlers.ts:1
import { vercelFetch } from "../../utils/api.js";
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, dotenv, node-fetch, zod, @types/node, ts-node, typescript
Why it matters. 7 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:36
- [`vercel-get-environments`](docs/environments.md#vercel-get-environments) - Access project environment variables
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass, no_license.

Audited 2026-10-07 · audit v0.4.1 · source sha e5fc577e449afull audit observations/trust-audit/mcp-server/nganiet__vercel-integration.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07e5fc577e449aSAFEB87first audit
06

Questions

What is the Vercel Integration MCP server?

MCP server connecting Claude to Vercel

What tools does Vercel Integration expose?

15 in total: 8 read-only, 5 that write, and 2 that can delete or overwrite (vercel-delete-project, vercel-remove-environment-variable). Every one is listed on this page with its risk.

Is Vercel Integration safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (87/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Vercel Integration need?

It reads VERCEL_API_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Vercel Integration run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as vercel at 1.0.0.

How current is this page?

The grade is for one exact copy of the source (e5fc577e449a), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement