prisma-expert

Pass

Audited by Gen Agent Trust Hub on Mar 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses npx prisma and standard utilities like grep and ls to diagnose the project environment and manage database migrations. These commands are standard for the Prisma ORM toolchain and are used for their primary intended purpose.
  • [PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection as it ingests untrusted data from local project files. Ingestion points: Reads prisma/schema.prisma and migration files in prisma/migrations/ (SKILL.md). Boundary markers: Absent; the skill reads file content without explicit delimiters or instructions to ignore embedded instructions. Capability inventory: Can execute shell commands via npx and perform database diagnostics. Sanitization: Absent; file content is processed as-is.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 18, 2026, 07:46 AM
Security Audit — agent-trust-hub — prisma-expert