prisma-client-api
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill serves as a detailed technical reference for the Prisma Client API, covering CRUD operations, filtering, and transactions without any malicious patterns detected.- [REMOTE_CODE_EXECUTION]: The documentation for raw database queries (
$queryRaw,$executeRaw) includes a dedicated 'SQL Injection Prevention' section. This section explicitly warns developers against using string concatenation with unsafe methods and provides clear examples of secure parameterization using tagged templates.- [CREDENTIALS_UNSAFE]: All code snippets involving database connections correctly demonstrate the use of environment variables (process.env.DATABASE_URL) rather than hardcoding sensitive credentials, adhering to security best practices.- [EXTERNAL_DOWNLOADS]: The skill references several official Node.js packages from the Prisma ecosystem (e.g.,@prisma/adapter-pg,@prisma/extension-accelerate,@prisma/sqlcommenter-query-insights). These are well-known, legitimate libraries required for the functionality described.
Audit Metadata