Mmcp.market

add-vercel skill

by nanocoai·nanocoai/nanoclaw·31k stars·MIT

Add Vercel deployment capability to NanoClaw agents. Installs the Vercel CLI in agent containers and sets up OneCLI credential injection for api.vercel.com. Use when the user wants agents to deploy web applications to Vercel.

D40/100content scan

Is the add-vercel skill safe?

Serious findings: read the flagged lines first. We read 4 files in the folder on 2026-09-28.

  • highSKILL.md:10

    Tells the agent to set aside its instructions, hide what it does from the user, or switch off safety checks.

    **Principle:** Do the work — don't tell the user to do it. Only ask for their input when it genuinely requires manual action (pasting a token).
  • highcontainer-skills/vercel-cli/SKILL.md:119

    Tells the agent to set aside its instructions, hide what it does from the user, or switch off safety checks.

    ⚠️ **CRITICAL**: If you skip step 2, nothing happens. The agent exists but has no work. You MUST send the message. Do NOT tell the user "it's working on it" until you have actually called send_mess...

Install the add-vercel skill

A skill is a folder. Copy it into your agent's skills folder and the agent loads it when the task matches its description. Read the findings above first.

git clone --depth 1 https://github.com/nanocoai/nanoclaw.git /tmp/nanoclaw
mkdir -p ~/.claude/skills
cp -r /tmp/nanoclaw/.claude/skills/add-vercel ~/.claude/skills/add-vercel
available in every project

In the Claude apps, zip the folder and upload it from the Skills settings. The folder on GitHub

The instructions your agent would load

SKILL.md as published, without the frontmatter. Read it on GitHub

Add Vercel

This skill gives NanoClaw agents the ability to deploy web applications to Vercel. It installs the Vercel CLI in agent containers and configures OneCLI to inject Vercel credentials automatically.

Principle: Do the work — don't tell the user to do it. Only ask for their input when it genuinely requires manual action (pasting a token).

Phase 1: Pre-flight

Check if already applied

Check if the container skill exists:

test -d container/skills/vercel-cli && echo "INSTALLED" || echo "NOT_INSTALLED"

If INSTALLED, skip to Phase 3 (Configure Credentials).

Check prerequisites

Verify OneCLI is working (required for credential injection):

onecli version 2>/dev/null && echo "ONECLI_OK" || echo "ONECLI_MISSING"

If ONECLI_MISSING, tell the user to run /init-onecli first, then retry /add-vercel. Stop here.

Phase 2: Install Container Skill

Copy the bundled container skill into the container skills directory:

rsync -a .claude/skills/add-vercel/container-skills/ container/skills/

Verify:

head -5 container/skills/vercel-cli/SKILL.md

Phase 3: Configure Credentials

Check if Vercel credential already exists

onecli secrets list 2>/dev/null | grep -i vercel

If a Vercel credential already exists, skip to Phase 4.

Set up Vercel API credential

The agent needs a Vercel personal access token. Tell the user:

I need your Vercel personal access token. Go to https://vercel.com/account/tokens and create one with these settings:

- Token name: nanoclaw (or any name you'll recognize)

- Scope: "Full Account" — the agent needs to create projects, deploy, and manage domains

- Expiration: "No expiration" recommended (avoids credential rotation), or pick a date if your security policy requires it

After creating the token, copy it — you'll only see it once.

Once the user provides the token, add it to OneCLI:

onecli secrets create \
  --name "Vercel API Token" \
  --type generic \
  --value "<TOKEN>" \
  --host-pattern "api.vercel.com" \
  --header-name "Authorization" \
  --value-format "Bearer {value}"

Verify:

onecli secrets list | grep -i vercel

Assign the secret to all agents

OneCLI uses selective secret mode — secrets must be explicitly assigned to each agent. Get the Vercel secret ID from the output above, then assign it to every agent:

# set-secrets replaces the entire list — read and merge for each agent.
VERCEL_SECRET_ID=$(onecli secrets list | jq -r '.data[] | select(.name | test("(?i)vercel")) | .id' | head -1)
for agent in $(onecli agents list | jq -r '.data[].id'); do
  CURRENT=$(onecli agents secrets --id "$agent" | jq -r '[.data[]] | join(",")')
  MERGED=$(printf '%s' "$CURRENT,$VERCEL_SECRET_ID" | tr ',' '\n' | sort -u | paste -sd ',' -)
  onecli agents set-secrets --id "$agent" --secret-ids "$MERGED"
done

Phase 4: Ensure Vercel CLI in Container Image

The Vercel CLI is not in the agent image by default — this skill is what adds it. It goes in container/cli-tools.json as a json-merge rather than a Dockerfile edit, which is what keeps the change deterministic and removable.

grep -q '"vercel"' container/cli-tools.json && echo "PRESENT" || echo "MISSING"

If MISSING, append the entry, keeping an exact pinned version — the manifest rejects ranges, so the supply-chain policy still applies:

{ "name": "vercel", "version": "52.2.1" }

Then apply it:

./container/build.sh

On an install that builds its own image, that rebuilds it. On one that fetches a published image, the same command adds Vercel as a single layer on top of the image already there, so the publisher's patched components underneath are kept — you are adding a tool, not replacing the runtime. The command says what that does and does not cover.

If PRESENT, the CLI is already in the manifest — skip the rebuild.

Phase 4b: Copy and Run the Dependency Guard

The Vercel CLI is a globally-installed binary — not importable or typed — so a structural test guards the install. Copy it into the host test tree and run it:

cp .claude/skills/add-vercel/vercel-manifest.test.ts src/vercel-manifest.test.ts
pnpm exec vitest run src/vercel-manifest.test.ts

The test asserts both halves of the install: a pinned vercel entry in container/cli-tools.json, and the container skill at container/skills/vercel-cli/. Either alone is a broken install — a manifest entry with no skill leaves the agent a binary nobody told it about, and a skill with no entry tells it to run a command that is not there.

Phase 5: Sync Skills to Running Agent Groups

Container skills are copied once at group creation and not auto-synced. After installing or updating a container skill, sync it to all existing agent groups:

for session_dir in data/v2-sessions/ag-*; do
  if [ -d "$session_dir/.claude-shared/skills" ]; then
    rsync -a container/skills/ "$session_dir/.claude-shared/skills/"
    echo "Synced skills to: $session_dir"
  fi
done

Phase 6: Restart Running Containers

Stop all running agent containers so they pick up the new skills on next wake:

docker ps --filter label=nanoclaw-session -q | xargs -r docker stop

Done

The agent can now deploy web applications to Vercel. Key commands:

  • vercel deploy --yes --prod --token placeholder — deploy to production
  • vercel ls --token placeholder — list deployments
  • vercel whoami --token placeholder — check auth

For the full command reference, the agent has the vercel-cli container skill loaded automatically.

More skills from nanocoai/nanoclaw

  • Aadd-anydocAdd local office-document-to-Markdown conversion to NanoClaw agent containers with the pinned Firecrawl AnyDoc CLI. Use when agents need to read attached Word, PowerPoint, Excel, OpenDocument, RTF, EPUB, CSV, or text-based PDF files without uploading them to a hosted parser.
  • Aadd-atomic-chat-toolAdd Atomic Chat MCP server so the container agent can call local models served by the Atomic Chat desktop app via its OpenAI-compatible API.
  • Fadd-clidashAdd clidash — a zero-dependency, read-only web dashboard that derives its tabs and tables at runtime from any CLI that lists resources as JSON. Ships pre-wired for NanoClaw's ncl CLI (agent groups, sessions, channels, users, roles), plus message-activity charts, a log tail, and a read-only file viewer for group skills/CLAUDE.md/profiles.
  • Aadd-codexUse Codex (OpenAI's codex app-server) as a full agent provider — planning, tool orchestration, MCP tools, server-side history, session resume — alongside or instead of Claude. ChatGPT subscription or OpenAI API key, vault-only via the selected gateway. Per-group via `ncl groups config update --provider codex`. Distinct from using OpenAI as an MCP tool (where Claude remains the planner).
  • Aadd-dashboardAdd a monitoring dashboard to NanoClaw. Installs @nanoco/nanoclaw-dashboard and a pusher that sends periodic JSON snapshots.
  • Aadd-deltachatAdd DeltaChat channel integration via @deltachat/stdio-rpc-server. Native adapter — no Chat SDK bridge. Email-based messaging with end-to-end encryption.
  • Cadd-dialAdd Dial channel integration — a real phone number for SMS and AI voice calls via the Dial platform (getdial.ai). Native adapter — no Chat SDK bridge.
  • Aadd-dial-numberAdd another phone number to an existing Dial channel — a second (or third) public line for the agent, so one NanoClaw install answers SMS and AI voice calls on multiple numbers. Use when Dial is already installed and the operator wants an additional number (e.g. a personal line plus a support line). Requires the Dial channel to already be installed (see /add-dial).
  • Aadd-dial-toolGive chosen NanoClaw agents a real phone number as a container tool — the `dial` CLI baked into the agent image plus OneCLI credential injection for api.getdial.ai, scoped per agent, so the agents you pick can send SMS, place AI voice calls, and receive verification codes from inside the sandbox. Independent of the Dial channel; idempotent; re-run to change which agents may use it. Use when the user wants agents to text, call, or run `dial …` from a chat, without wiring Dial as a messaging channel.
  • Aadd-discordAdd Discord bot channel integration via Chat SDK.
  • Aadd-emacsAdd Emacs as a channel. Opens an interactive chat buffer and org-mode integration so you can talk to NanoClaw from within Emacs (Doom, Spacemacs, or vanilla). Local HTTP bridge — no bot token or external service needed.
  • Aadd-gchatAdd Google Chat channel integration via Chat SDK.

All agent skills → · MCP servers