# Security Audit Features in the skills CLI: How Gen, Socket, and Snyk Protect Your Code

> Discover how the skills CLI uses Gen, Socket, and Snyk to conduct comprehensive security audits and protect your code. Get risk assessments at a glance.

- Repository: [Vercel Labs/skills](https://github.com/vercel-labs/skills)
- Tags: deep-dive
- Published: 2026-04-23

---

**The skills CLI displays a three-column security audit table showing risk assessments from Gen (ATH), Socket, and Snyk partners when adding or listing skills.**

The `vercel-labs/skills` CLI integrates automated security scanning directly into your workflow. When you install or browse skills, the tool queries three partner audit services—**Gen**, **Socket**, and **Snyk**—and renders a concise table showing vulnerability risks and alert counts. This feature helps developers catch security issues before they reach production, all without blocking the install process.

## What the Security Audit Table Displays

The CLI renders a fixed three-column layout every time you run `skills add` or interact with the skill registry:

| Column | Partner | Data Shown |
|--------|---------|------------|
| **Gen** | ATH | Risk level: `Critical Risk`, `High Risk`, `Med Risk`, `Low Risk`, or `Safe` |
| **Socket** | Socket | Alert count: `N alerts` (red if >0, green if 0) |
| **Snyk** | Snyk | Risk level: Same format as Gen column |

This table appears in [`src/add.ts`](https://github.com/vercel-labs/skills/blob/main/src/add.ts) via the `buildSecurityLines` function (lines 109-155), which formats the raw partner data into aligned columns.

## How Each Security Audit Partner Works

### Gen (ATH) Risk Assessment

The **Gen** column pulls from the ATH partner's risk evaluation. In [`src/add.ts`](https://github.com/vercel-labs/skills/blob/main/src/add.ts), the `riskLabel` helper (lines 43-48) transforms the raw `data.ath.risk` value into a color-coded label:

```typescript
// src/add.ts – risk label helper
function riskLabel(risk: string): string {
  switch (risk) {
    case 'critical': return pc.red(pc.bold('Critical Risk'));
    case 'high':     return pc.red('High Risk');
    case 'medium':   return pc.yellow('Med Risk');
    case 'low':      return pc.green('Low Risk');
    case 'safe':     return pc.green('Safe');
    default:         return pc.dim('--');
  }
}

```

Critical risks appear in **bold red**, making them impossible to miss during skill installation.

### Socket Security Alerts

The **Socket** column shows the number of security alerts detected by Socket's supply chain security scanning. The `socketLabel` function in [`src/add.ts`](https://github.com/vercel-labs/skills/blob/main/src/add.ts) (lines 91-95) handles formatting:

```typescript
// src/add.ts – socket alert formatter
function socketLabel(audit: PartnerAudit | undefined): string {
  if (!audit) return pc.dim('--');
  const count = audit.alerts ?? 0;
  return count > 0
    ? pc.red(`${count} alert${count !== 1 ? 's' : ''}`)
    : pc.green('0 alerts');
}

```

Any positive alert count renders in **red**, while a clean scan shows **"0 alerts"** in green. This gives immediate visual feedback on supply chain risks.

### Snyk Vulnerability Risk

The **Snyk** column mirrors the Gen column's format, using the same `riskLabel` helper applied to `data.snyk.risk` (line 145 in [`src/add.ts`](https://github.com/vercel-labs/skills/blob/main/src/add.ts)). This consistency makes it easy to compare risk assessments across the two partners side-by-side.

## Fetching Security Audit Data: The Backend Flow

The CLI doesn't block your workflow while fetching security data. The `fetchAuditData` function in [`src/telemetry.ts`](https://github.com/vercel-labs/skills/blob/main/src/telemetry.ts) (lines 97-123) implements a **3-second timeout** to ensure responsiveness:

```typescript
// src/telemetry.ts – fetching audit data
export async function fetchAuditData(
  source: string,
  skillSlugs: string[],
  timeoutMs = 3000
): Promise<AuditResponse | null> {
  if (skillSlugs.length === 0) return null;
  const params = new URLSearchParams({ source, skills: skillSlugs.join(',') });
  const controller = new AbortController();
  const timeout = setTimeout(() => controller.abort(), timeoutMs);
  const response = await fetch(`${AUDIT_URL}?${params.toString()}`, {
    signal: controller.signal,
  });
  clearTimeout(timeout);
  return response.ok ? (await response.json()) as AuditResponse : null;
}

```

The function queries `https://add-skill.vercel.sh/audit` with:
- `source`: Your repository URL
- `skills`: Comma-separated skill slugs to audit

If the request times out or fails, the CLI gracefully continues without security data rather than blocking installation.

## Rendering the Complete Security Table

Once data is fetched, `buildSecurityLines` in [`src/add.ts`](https://github.com/vercel-labs/skills/blob/main/src/add.ts) (lines 109-155) assembles the final output:

1. **Validates** that at least one partner returned data
2. **Calculates column widths** for alignment
3. **Builds the header row** with "Gen", "Socket", "Snyk" labels
4. **Iterates each skill**, formatting:
   - `data?.ath` → `riskLabel`
   - `data?.socket` → `socketLabel`
   - `data?.snyk` → `riskLabel`
5. **Appends a footer** linking to `https://skills.sh/<source>` for full details

## Example Security Audit Output

When you run `skills add`, you might see:

```

Skill Name          Gen                Socket               Snyk
my-cool-skill       Critical Risk      2 alerts             High Risk

Details: https://skills.sh/github.com/owner/repo

```

This immediately tells you:
- **Gen (ATH)**: Critical risk detected — highest priority
- **Socket**: 2 supply chain alerts need investigation
- **Snyk**: High risk confirms the severity

## Key Source Files Reference

| File | Purpose |
|------|---------|
| [`src/add.ts`](https://github.com/vercel-labs/skills/blob/main/src/add.ts) | Renders security table (`riskLabel`, `socketLabel`, `buildSecurityLines`) |
| [`src/telemetry.ts`](https://github.com/vercel-labs/skills/blob/main/src/telemetry.ts) | Fetches audit data (`fetchAuditData`), defines `AuditResponse` type |
| [`src/types.ts`](https://github.com/vercel-labs/skills/blob/main/src/types.ts) | Type definitions for `PartnerAudit` and related structures |
| [`src/skill-lock.ts`](https://github.com/vercel-labs/skills/blob/main/src/skill-lock.ts) | Stores source URL used for audit API calls |

## Summary

- The **skills CLI security audit** displays three partner-provided assessments: **Gen (ATH)**, **Socket**, and **Snyk**
- **Gen and Snyk** show color-coded risk labels (`Critical` through `Safe`)
- **Socket** displays supply chain alert counts with visual red/green indicators
- Data fetches from `https://add-skill.vercel.sh/audit` with a **3-second timeout** to prevent blocking
- The table renders via `buildSecurityLines` in [`src/add.ts`](https://github.com/vercel-labs/skills/blob/main/src/add.ts), with full details available at `https://skills.sh/<source>`

## Frequently Asked Questions

### How do I read the security audit table when adding a skill?

The three columns show partner security assessments. **Gen** and **Snyk** display risk levels from `Critical Risk` (bold red) to `Safe` (green). **Socket** shows supply chain alert counts—any number above zero appears in red. Watch for `Critical` or `High` risk labels and non-zero Socket alerts before installing.

### What happens if the security audit service is down?

The `fetchAuditData` function in [`src/telemetry.ts`](https://github.com/vercel-labs/skills/blob/main/src/telemetry.ts) implements a **3-second timeout** using `AbortController`. If the audit service at [`add-skill.vercel.sh`](https://github.com/vercel-labs/skills/blob/main/add-skill.vercel.sh) is slow or unavailable, the request aborts and the CLI continues installation without security data. Your workflow is never blocked by audit failures.

### Where is the full security report for a skill?

The CLI outputs a footer link pointing to `https://skills.sh/<source>` where `<source>` is your repository URL. This page contains the complete audit details from all three partners. The `buildSecurityLines` function in [`src/add.ts`](https://github.com/vercel-labs/skills/blob/main/src/add.ts) appends this link after the security table.

### Do I need to configure API keys for Gen, Socket, or Snyk audits?

No configuration is required. The skills CLI queries a centralized audit service at [`add-skill.vercel.sh`](https://github.com/vercel-labs/skills/blob/main/add-skill.vercel.sh) that aggregates partner data. Individual API keys for ATH Gen, Socket, or Snyk are handled server-side; the CLI only consumes the unified response through `fetchAuditData` in [`src/telemetry.ts`](https://github.com/vercel-labs/skills/blob/main/src/telemetry.ts).