Install
$ agentstack add skill-ariadoss-superskills-vercel-cli-with-tokens ✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ● Network access Used
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ● Environment & secrets Used
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README — it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming — see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps — measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Vercel CLI with Tokens
Deploy and manage projects on Vercel using the CLI with token-based authentication, without relying on vercel login.
Step 1: Locate the Vercel Token
Before running any Vercel CLI commands, identify where the token is coming from. Work through these scenarios in order:
A) VERCEL_TOKEN is already set in the environment
printenv VERCEL_TOKEN
If this returns a value, you're ready. Skip to Step 2.
B) Token is in a .env file under VERCEL_TOKEN
grep '^VERCEL_TOKEN=' .env 2>/dev/null
If found, export it:
export VERCEL_TOKEN=$(grep '^VERCEL_TOKEN=' .env | cut -d= -f2-)
C) Token is in a .env file under a different name
Look for any variable that looks like a Vercel token (Vercel tokens typically start with vca_):
grep -i 'vercel' .env 2>/dev/null
Inspect the output to identify which variable holds the token, then export it as VERCEL_TOKEN:
export VERCEL_TOKEN=$(grep '^=' .env | cut -d= -f2-)
D) No token found — ask the user
If none of the above yield a token, ask the user to provide one. They can create a Vercel access token at vercel.com/account/tokens.
Important: Once VERCEL_TOKEN is exported as an environment variable, the Vercel CLI reads it natively — do not pass it as a --token flag. Putting secrets in command-line arguments exposes them in shell history and process listings.
# Bad — token visible in shell history and process listings
vercel deploy --token "vca_abc123"
# Good — CLI reads VERCEL_TOKEN from the environment
export VERCEL_TOKEN="vca_abc123"
vercel deploy
Step 2: Locate the Project and Team
# Check environment
printenv VERCEL_PROJECT_ID
printenv VERCEL_ORG_ID
# Or check .env
grep -i 'vercel' .env 2>/dev/null
If you have a project URL (e.g. https://vercel.com/my-team/my-project), extract the team slug:
echo "$PROJECT_URL" | sed 's|https://vercel.com/||' | cut -d/ -f1
If you have both VERCEL_ORG_ID and VERCEL_PROJECT_ID in your environment, export them — the CLI will use these automatically:
export VERCEL_ORG_ID=""
export VERCEL_PROJECT_ID=""
Note: VERCEL_ORG_ID and VERCEL_PROJECT_ID must be set together — setting only one causes an error.
CLI Setup
Ensure the Vercel CLI is installed and up to date:
npm install -g vercel
vercel --version
Deploying a Project
Always deploy as preview unless the user explicitly requests production.
Quick Deploy (have project ID — no linking needed)
vercel deploy -y --no-wait
vercel deploy --scope -y --no-wait
vercel deploy --prod --scope -y --no-wait # production only if explicitly requested
Check status:
vercel inspect
Full Deploy Flow (no project ID — need to link)
# Check git remote and link state
git remote get-url origin 2>/dev/null
cat .vercel/project.json 2>/dev/null || cat .vercel/repo.json 2>/dev/null
# Link with git remote (preferred)
vercel link --repo --scope -y
# Link without git remote
vercel link --scope -y
# Link to specific project
vercel link --project --scope -y
Then deploy via git push (if remote exists) or vercel deploy -y --no-wait.
Managing Environment Variables
# Set for all environments
echo "value" | vercel env add VAR_NAME --scope
# Set for a specific environment (production, preview, development)
echo "value" | vercel env add VAR_NAME production --scope
# List environment variables
vercel env ls --scope
# Pull env vars to local .env.local file
vercel env pull --scope
# Remove a variable
vercel env rm VAR_NAME --scope -y
Inspecting Deployments
# List recent deployments
vercel ls --format json --scope
# Inspect a specific deployment
vercel inspect
# View build logs (requires Vercel CLI v35+)
vercel inspect --logs
# View runtime request logs
vercel logs
Working Agreement
- Never pass
VERCEL_TOKENas a--tokenflag. Export it as an environment variable and let the CLI read it natively. - Check the environment for tokens before asking the user. Look in the current env and
.envfiles first. - Default to preview deployments. Only deploy to production when explicitly asked.
- Ask before pushing to git. Never push commits without the user's approval.
- Do not modify
.vercel/files directly. The CLI manages this directory. Reading them is fine. - Do not curl/fetch deployed URLs to verify. Just return the link to the user.
- Use
--format jsonwhen structured output will help with follow-up steps. - Use
-yon commands that prompt for confirmation to avoid interactive blocking.
Troubleshooting
Token not found
printenv | grep -i vercel
grep -i vercel .env 2>/dev/null
Authentication error
If the CLI fails with Authentication required:
- The token may be expired or invalid.
- Verify:
vercel whoami(usesVERCEL_TOKENfrom environment). - Ask the user for a fresh token.
Wrong team
vercel whoami --scope
Build failure
vercel inspect --logs
Common causes:
- Missing dependencies — ensure
package.jsonis complete and committed. - Missing environment variables — add with
vercel env add. - Framework misconfiguration — check
vercel.json.
CLI not installed
npm install -g vercel
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: ariadoss
- Source: ariadoss/superskills
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.