prisma-client-api

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a detailed technical reference for the Prisma Client API, covering CRUD operations, filtering, and transactions without any malicious patterns detected.- [REMOTE_CODE_EXECUTION]: The documentation for raw database queries ($queryRaw, $executeRaw) includes a dedicated 'SQL Injection Prevention' section. This section explicitly warns developers against using string concatenation with unsafe methods and provides clear examples of secure parameterization using tagged templates.- [CREDENTIALS_UNSAFE]: All code snippets involving database connections correctly demonstrate the use of environment variables (process.env.DATABASE_URL) rather than hardcoding sensitive credentials, adhering to security best practices.- [EXTERNAL_DOWNLOADS]: The skill references several official Node.js packages from the Prisma ecosystem (e.g., @prisma/adapter-pg, @prisma/extension-accelerate, @prisma/sqlcommenter-query-insights). These are well-known, legitimate libraries required for the functionality described.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 11:20 PM
Security Audit — agent-trust-hub — prisma-client-api