prisma-postgres
Fail
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSMETADATA_POISONING
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill recommends executing code via
npxusing packages that are not owned by the intended vendor. - Evidence: In
SKILL.mdandreferences/create-db-cli.md, the commandsnpx create-pg@latestandnpx create-postgres@latestare explicitly listed as aliases for the official Prismacreate-dbtool. - Evidence: Investigation of the NPM registry confirms that
create-pgandcreate-postgresare owned by unrelated third-party developers (kofandjaredpalmer) and have no affiliation with the Prisma organization. Executing these vianpxallows for arbitrary code execution from unverifiable sources. - [METADATA_POISONING]: The skill contains deceptive author metadata that misrepresents the source of the information.
- Evidence: The
SKILL.mdYAML frontmatter identifies the author as 'prisma', whereas the actual skill author context provided is 'midudev'. This mismatch indicates an attempt to leverage the reputation of a well-known service provider to vouch for the safety of unverified commands. - [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of multiple external dependencies, some of which are non-official.
- Evidence: While
@prisma/management-api-sdkandcreate-dbare official vendor packages, the recommendation to use unverified 'alias' packages poses a significant supply-chain risk. - [SAFE]: Legitimate interactions with official Prisma infrastructure are documented correctly for standard operations.
- Evidence: The use of official domains such as
console.prisma.ioandapi.prisma.iofor console operations and API integrations is consistent with the vendor's official practices.
Recommendations
- AI detected serious security threats
Audit Metadata