This is Vercel's official set of Agent Skills, written by its engineers for coding agents. The best known is react-best-practices, more than 40 React and Next.js performance rules ranked by impact, from removing request waterfalls to cutting bundle size. Alongside it sit composition-patterns for component APIs, react-native-skills, react-view-transitions, web-design-guidelines (100+ rules on accessibility, focus states, forms and more) and writing-guidelines, which checks docs against Vercel's writing handbook.
The rest are about Vercel itself. deploy-to-vercel deploys a project from the conversation, through the Vercel CLI when you are logged in, and otherwise by uploading it to a claimable deployment you can later move into your own account. vercel-cli-with-tokens covers the Vercel CLI with access tokens, and vercel-optimize audits a deployed project for cost, caching and function usage.
It has about 32,000 stars and 26 contributors, and installs with Vercel's own npx skills CLI. The README ends with a line saying MIT, but there is no licence file in the repository and GitHub shows none, so the reuse terms are not formally stated.
- Repository: github.com/vercel-labs/agent-skills
- Licence: none
- Language: JavaScript. Stars: 32.1K. Forks: 2,812. Last push: Aug 28, 2026.
- Scan: safe, Oct 8, 2026, commit 063bee9
Who it is for
React and Next.js developers who want their coding agent to follow Vercel's performance and UI rules, and Vercel users who want the agent to deploy or tune their projects.
Getting started
1. Install the skills (you choose which skills and agents)
npx skills add vercel-labs/agent-skills2. See the list first without installing
npx skills add vercel-labs/agent-skills --list3. Or install just one skill
npx skills add vercel-labs/agent-skills --skill web-design-guidelinesNeeds Node.js. Once installed, the agent picks a skill up when a task matches, for example when you ask it to review a React component or deploy your app.
Safety scan
We cloned vercel-labs/agent-skills at commit 063bee9 on Oct 8, 2026 and ran the checks described on the GitHub Tools page: credential patterns, decode-and-execute code, install-time scripts, committed binaries, risky CI workflows, every host the code talks to, known vulnerabilities in pinned dependencies, and project hygiene. A person read every hit. This is what we found.
- No secrets, no suspicious code patterns and no executables across 446 files and about 233,000 lines, most of it JSON. A second, skill-specific pass found nothing malicious.
- deploy-to-vercel's scripts (deploy.sh and deploy-codex.sh, about 300 lines each, no sudo) pack your project into a tarball and upload it to Vercel's claimable deployment endpoints, claude-skills-deploy.vercel.com and codex-deploy-skills.vercel.sh, as the fallback when the Vercel CLI cannot log in. They leave out node_modules, .git and .env files, but anything else in the folder, such as a stray key file, leaves your machine with it.
- Committed .zip copies of five skills sit beside their folders, packaged for uploading to claude.ai. We unpacked them: Markdown, JSON and the same two deploy scripts (one zip also nests an older copy of them), talking only to the same Vercel endpoints, with no executables. Three of the zips are older than the folders beside them, so install from the folders.
- One known advisory, rated low: esbuild 0.27.4 in the build package for react-best-practices, which only affects its development server on Windows and is not part of the installed skills.
- Two workflows, none using pull_request_target; the one third-party action (pnpm/action-setup) is pinned to a tag, not a commit. No licence file, security policy, contributing guide or Dependabot.
What the scanner counted
| Check | Result |
|---|---|
| Secrets | None found. |
| Suspicious code | None found. |
| Install-time code | 2 installer scripts |
| Committed binaries | None. |
| CI workflows | 2 workflows. None use pull_request_target. 1 of 1 third-party action pinned to a tag rather than a commit. |
| Network hosts | 16 distinct hosts referenced from source; most often vercel.com, nextjs.org, api.example.com, workflow-sdk.dev. No URLs to bare IP addresses. |
| Known vulnerabilities | 1 advisory across 35 pinned packages: 0 critical, 0 high, 0 moderate, 1 low. package-lock.json: 1 packages, 0 advisories; packages/react-best-practices-build/pnpm-lock.yaml: 34 packages, 1 advisories. |
| Project hygiene | Has none of the usual files. Missing security policy, automated dependency updates, CodeQL, licence file, contributing guide. |
| OpenSSF Scorecard | Not scored: the project is not in Scorecard's weekly index. |
The raw findings
Every hit the scanner wrote out, with a link to the exact line at the scanned commit. Secrets candidates are redacted.
Installer scripts (2)
- skills/deploy-to-vercel/resources/deploy-codex.sh, 302 lines; talks to codex-deploy-skills.vercel.sh
- skills/deploy-to-vercel/resources/deploy.sh, 302 lines; talks to claude-skills-deploy.vercel.com
Worst known vulnerabilities (1 of 1)
| Advisory | Severity | Package | Summary |
|---|---|---|---|
| GHSA-g7r4-m6w7-qqqr | low | esbuild@0.27.4 | esbuild allows arbitrary file read when running the development server on Windows |
By the numbers
| Stars | 32.1K |
|---|---|
| Forks | 2,812 |
| Contributors | 26 |
| Commits | 275 |
| Open issues | 67 |
| Open pull requests | 111 |
| Releases | 3 |
| Latest release | agent-skills-063bee94c3f4df8453406c830b0a7df0f2860278 |
| Licence | none |
| Main language | JavaScript |
| Project age | 10 months |
| Last push | Aug 28, 2026 |
| Tracked files | 446 |
| Lines of code | 233.3K |
| Checkout size | 8 MB |
Lines by language: JSON 180.5K, JavaScript 27.4K, Markdown 23.6K, TypeScript 1,142, Shell 604, YAML 84.
Questions
Are Vercel Agent Skills free?
They are free to install and use, and the README says MIT, but the repository has no licence file, so check with Vercel before copying them into a product of your own. Running them needs a coding agent under its own pricing, and the deploy and optimize skills work with your Vercel account and plan.
Does the deploy skill need a Vercel account?
No. It prefers the Vercel CLI and your own account, deploying as a preview unless you ask for production. When the CLI cannot log in, as in the claude.ai sandbox, it falls back to a claimable deployment and returns a preview link plus a claim URL that moves it into your account.
Which agents do these skills work in?
Any agent that supports the Agent Skills format. The npx skills installer can put them into Claude Code, Codex, Cursor and dozens of other agents, and the .zip copies are there for uploading to claude.ai.
This post is part of GitHub Tools, where every repository is cloned and scanned before it is written up. The scan is a snapshot of one commit on one day; the repository has moved on since, so check it before you install.
