prisma-expert
Pass
Audited by Gen Agent Trust Hub on Mar 18, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
npx prismaand standard utilities likegrepandlsto diagnose the project environment and manage database migrations. These commands are standard for the Prisma ORM toolchain and are used for their primary intended purpose. - [PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection as it ingests untrusted data from local project files. Ingestion points: Reads
prisma/schema.prismaand migration files inprisma/migrations/(SKILL.md). Boundary markers: Absent; the skill reads file content without explicit delimiters or instructions to ignore embedded instructions. Capability inventory: Can execute shell commands vianpxand perform database diagnostics. Sanitization: Absent; file content is processed as-is.
Audit Metadata