Findings by source

Vercel

Code · GitHub (demo) Vercel · Assistant · package: ai · package: @ai-sdk/openai

Policy · none set
Policy changes re-score this app on the next sync, which starts right away.
Finding · Open
Risk score
31
Medium
People
0
Committers are not collected
Repositories
1
0 public · 2 packages
Keys in code
0
None found in the files read
source-codefixture
Next steps

Recommended actions

  1. 01Vercel SDKs appear in 1 repository. Decide whether this vendor is approved for engineering, and route calls through one gateway or an Azure OpenAI deployment so keys, logging, and data terms are managed centrally.
GitHub (demo) · fixture

Where it lives in code

SDK packages · 2
Repositories
RepositorySignalsPushed
contoso/customer-portalSDK packages27 h ago
Packages
ai npm1 repo
@ai-sdk/openai npm1 repo
Who

People

Identifiers come from device telemetry and proxy logs, so they may be account names rather than full directory entries.

No people are linked to this app.

Why

Evidence

  1. source_code · Sep 13, 2026
    Vercel in 1 repository via GitHub (demo): packages ai, @ai-sdk/openai
    Detail
    {
      "repos": [
        "contoso/customer-portal"
      ],
      "configs": [],
      "packages": [
        {
          "name": "ai",
          "repos": 1,
          "ecosystem": "npm"
        },
        {
          "name": "@ai-sdk/openai",
          "repos": 1,
          "ecosystem": "npm"
        }
      ],
      "endpoints": []
    }