Install
$ agentstack add skill-build-with-dhiraj-ai-workflow-framework-portability-kit-vercel-plugin-eval Open-source listing, not yet scanned by AgentStack. Follow the source repository for install instructions.
Security review
⚠ Flagged1 finding(s); flagged for manual review. · v0.1.0 How review works →
- • Prompt-injection patterns
- • Secret / credential exfiltration
- • Dangerous shell & filesystem operations
- • Untrusted network calls
- • Known-malicious package signatures
- high Destructive filesystem operation.
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Plugin Eval
Launch real Claude Code sessions with the plugin installed, monitor debug logs in real-time, and verify every hook fires correctly with proper dedup.
DO NOT (Hard Rules)
- DO NOT use
claude --printor-p— hooks don't fire, no files created - DO NOT use
--dangerously-skip-permissions - DO NOT create projects in
/tmp/— always use~/dev/vercel-plugin-testing/ - DO NOT manually wire hooks or create
settings.local.json— usenpx add-plugin - DO NOT set
CLAUDE_PLUGIN_ROOTmanually - DO NOT use
bash -cin WezTerm — use/bin/zsh -ic - DO NOT use full path to claude — use the
xalias - DO NOT write eval scripts — do everything as Bash tool calls in the conversation
Copy the exact commands below. Do not improvise.
Quick Start
Always append a timestamp to directory names so reruns don't overwrite old projects:
# 1. Create test dir & install plugin (with timestamp)
TS=$(date +%Y%m%d-%H%M)
SLUG="my-eval-$TS"
mkdir -p ~/dev/vercel-plugin-testing/$SLUG
cd ~/dev/vercel-plugin-testing/$SLUG
npx add-plugin https://github.com/vercel/vercel-plugin -s project -y
# 2. Launch session via WezTerm
wezterm cli spawn --cwd /Users/johnlindquist/dev/vercel-plugin-testing/$SLUG -- /bin/zsh -ic \
"unset CLAUDECODE; VERCEL_PLUGIN_LOG_LEVEL=debug x '' --settings .claude/settings.json; exec zsh"
# 3. Find debug log (wait ~25s for session start)
find ~/.claude/debug -name "*.txt" -mmin -2 -exec grep -l "$SLUG" {} +
What to Monitor
Hook firing (all 8 registered hooks)
LOG=~/.claude/debug/.txt
# SessionStart (3 hooks)
grep "SessionStart.*success" "$LOG"
# PreToolUse skill injection
grep -c "executePreToolHooks" "$LOG" # total calls
grep -c "provided additionalContext" "$LOG" # injections
# UserPromptSubmit
grep "UserPromptSubmit.*success" "$LOG"
# PostToolUse validate + shadcn font-fix
grep "posttooluse-validate.*provided" "$LOG"
grep "PostToolUse:Bash.*success" "$LOG"
# SessionEnd cleanup
grep "SessionEnd" "$LOG"
Dedup correctness (the key metric)
TMPDIR=$(node -e "import {tmpdir} from 'os'; console.log(tmpdir())" --input-type=module)
CLAIMDIR="$TMPDIR/vercel-plugin--seen-skills.d"
# Claim files = one per skill, atomic O_EXCL
ls "$CLAIMDIR"
# Compare: injections should equal claims
inject_meta=$(grep -c "skillInjection:" "$LOG")
claims=$(ls "$CLAIMDIR" 2>/dev/null | wc -l | tr -d ' ')
echo "Injections: $((inject_meta / 3)) | Claims: $claims"
skillInjection: appears 3x per actual injection in the debug log (initial check, parsed, success). Divide by 3.
PostToolUse validate quality
Look for real catches — API key bypass, outdated models, wrong patterns:
grep "VALIDATION" "$LOG" | head -10
Scenario Design
Describe products and features, never name specific technologies. Let the plugin infer which skills to inject. Always end prompts with: "Link the project to my vercel-labs team so we can deploy it later. Skip any planning and just build it. Get the dev server running."
Coverage targets by scenario type
| Scenario Type | Skills Exercised | |--------------|-----------------| | AI chat app | ai-sdk, ai-gateway, nextjs, ai-elements | | Durable workflow | workflow, ai-sdk, vercel-queues | | Monorepo | turborepo, turbopack, nextjs | | Edge auth + routing | routing-middleware, auth, sign-in-with-vercel | | Chat bot (multi-platform) | chat-sdk, ai-sdk, vercel-storage | | Feature flags + CRM | vercel-flags, vercel-queues, ai-sdk | | Email pipeline | email, satori, ai-sdk, vercel-storage | | Marketplace/payments | payments, marketplace, cms | | Kitchen sink | micro, ncc, all niche skills |
Hard-to-trigger skills (8 of 44)
These need explicit technology references in the prompt because agents don't naturally reach for them:
ai-elements— say "use the AI Elements component registry"v0-dev— say "generate components with v0"vercel-firewall— say "use Vercel Firewall for rate limiting"marketplace— say "publish to the Vercel Marketplace"geist— say "install the geist font package"json-render— name filescomponents/chat-*.tsx
Coverage Report
Write results to .notes/COVERAGE.md with:
- Session index — slug, session ID, unique skills, dedup status
- Hook coverage matrix — which hooks fired in which sessions
- Skill injection table — which of the 44 skills triggered
- Dedup stats — injections vs claims per session
- Issues found — bugs, pattern gaps, validation findings
Cleanup
rm -rf ~/dev/vercel-plugin-testing
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: build-with-dhiraj
- Source: build-with-dhiraj/ai-workflow-framework-portability-kit
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.