prisma-postgres

Fail

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSMETADATA_POISONING
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill recommends executing code via npx using packages that are not owned by the intended vendor.
  • Evidence: In SKILL.md and references/create-db-cli.md, the commands npx create-pg@latest and npx create-postgres@latest are explicitly listed as aliases for the official Prisma create-db tool.
  • Evidence: Investigation of the NPM registry confirms that create-pg and create-postgres are owned by unrelated third-party developers (kof and jaredpalmer) and have no affiliation with the Prisma organization. Executing these via npx allows for arbitrary code execution from unverifiable sources.
  • [METADATA_POISONING]: The skill contains deceptive author metadata that misrepresents the source of the information.
  • Evidence: The SKILL.md YAML frontmatter identifies the author as 'prisma', whereas the actual skill author context provided is 'midudev'. This mismatch indicates an attempt to leverage the reputation of a well-known service provider to vouch for the safety of unverified commands.
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of multiple external dependencies, some of which are non-official.
  • Evidence: While @prisma/management-api-sdk and create-db are official vendor packages, the recommendation to use unverified 'alias' packages poses a significant supply-chain risk.
  • [SAFE]: Legitimate interactions with official Prisma infrastructure are documented correctly for standard operations.
  • Evidence: The use of official domains such as console.prisma.io and api.prisma.io for console operations and API integrations is consistent with the vendor's official practices.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 17, 2026, 11:21 PM
Security Audit — agent-trust-hub — prisma-postgres