vercel-security-access

$npx mdskill add bobmatnyc/claude-mpm-skills/vercel-security-access

Manage Vercel security, access controls, and threat mitigation.

  • Control user roles, SSO, and authentication policies.
  • Integrates with SAML, OIDC, and Vercel's firewall.
  • Evaluates security context and access rules to enforce policies.
  • Applies deployment protection, audit logs, and 2FA settings.

SKILL.md

.github/skills/vercel-security-accessView on GitHub ↗
---
name: vercel-security-access
description: Vercel security and access controls including RBAC, SSO, deployment protection, firewall, bot defense, audit logs, and 2FA. Use when securing Vercel projects or managing access.
user-invocable: false
disable-model-invocation: true
progressive_disclosure:
  entry_point:
    summary: "Vercel security and access controls including RBAC, SSO, deployment protection, firewall, bot defense, audit logs, and 2FA. Use when securing Vercel projects or managing access."
    when_to_use: "When working with vercel-security-access or related functionality."
    quick_start: "1. Review the core concepts below. 2. Apply patterns to your use case. 3. Follow best practices for implementation."
---
# Vercel Security and Access Skill

---
progressive_disclosure:
  entry_point:
    summary: "Vercel security and access: RBAC, SSO (SAML/OIDC), deployment protection, firewall, BotID, audit logs, and 2FA."
    when_to_use:
      - "When managing access control and roles"
      - "When securing deployments and endpoints"
      - "When auditing activity and enforcing MFA"
    quick_start:
      - "Enable RBAC and role assignments"
      - "Configure SSO and authentication policies"
      - "Apply deployment protection and firewall"
      - "Review audit and activity logs"
  token_estimate:
    entry: 90-110
    full: 4000-5200
---

## Overview

Vercel security features cover identity, access control, deployment protection, and threat mitigation.

## Access Control

- Use RBAC to define project permissions.
- Configure SAML or OIDC for SSO.
- Require 2FA for sensitive access.

## Deployment Protection

- Apply deployment protection for previews and production.
- Limit access to protected deployments.

## Firewall and Bot Defense

- Use Vercel Firewall to manage traffic rules.
- Use BotID to mitigate automated abuse.

## Audit and Activity Logs

- Review audit logs for compliance.
- Track activity history for user actions.

## Complementary Skills

When using this skill, consider these related skills (if deployed):

- **vercel-teams-billing**: Team settings and account policy.
- **vercel-observability**: Operational visibility for security events.

*Note: Complementary skills are optional. This skill is fully functional without them.*

## Resources

**Vercel Docs**:
- RBAC: https://vercel.com/docs/rbac
- SAML: https://vercel.com/docs/saml
- OIDC: https://vercel.com/docs/oidc
- Deployment protection: https://vercel.com/docs/deployment-protection
- Vercel Firewall: https://vercel.com/docs/vercel-firewall
- BotID: https://vercel.com/docs/botid
- Audit log: https://vercel.com/docs/audit-log
- Activity log: https://vercel.com/docs/activity-log
- Two-factor authentication: https://vercel.com/docs/two-factor-authentication
- Code owners: https://vercel.com/docs/code-owners

More from bobmatnyc/claude-mpm-skills

SkillDescription
anthropicOfficial Anthropic SDK for Claude AI with chat, streaming, function calling, and vision capabilities
api-design-patternsComprehensive API design patterns covering REST, GraphQL, gRPC, versioning, authentication, and modern API best practices
api-documentationBest practices for documenting APIs and code interfaces, eliminating redundant documentation guidance per agent.
api-reviewAPI security checklist for reviewing endpoints before deployment. Use when creating or modifying API routes to ensure proper authentication, authorization, and input validation.
asyncioPython asyncio - Modern concurrent programming with async/await, event loops, tasks, coroutines, primitives, aiohttp, and FastAPI async patterns
axumAxum (Rust) web framework patterns for production APIs: routers/extractors, state, middleware, error handling, tracing, graceful shutdown, and testing
bad-example-skillANTI-PATTERN - Example showing violations of self-containment (DO NOT COPY)
better-auth-authenticationBetter Auth authentication flows for TypeScript apps. Use when enabling email/password auth, configuring social providers, or implementing sign-up, sign-in, and verification flows.
better-auth-coreBetter Auth core setup for TypeScript apps. Use when configuring the Better Auth instance, wiring server handlers and client instances, working with sessions, or calling server-side auth APIs.
better-auth-integrationsBetter Auth framework integrations for TypeScript. Use when wiring route handlers in Next.js, SvelteKit, Remix, Express, Hono, or other web frameworks.