prisma-orm-setup
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill installs official Prisma packages (e.g., prisma, @prisma/client, and database-specific adapters) from the npm registry. It also utilizes the prisma skills sync command, which may fetch updated guidance from the vendor's official repository.
- [DYNAMIC_EXECUTION]: The skill implements a workflow to synchronize and load dynamic guidance by running prisma skills sync, which updates local files (e.g., .agents/skills/prisma-8/SKILL.md) that the agent is then instructed to read and follow.
- [COMMAND_EXECUTION]: The skill utilizes the Prisma CLI for project initialization (prisma orm init) and maintenance via the project's native package manager.
- [INDIRECT_PROMPT_INJECTION]: The skill performs static analysis on project files to determine the application environment. Ingestion points: Reads project manifest files (package.json), lockfiles, environment variables, and Prisma schema files. Boundary markers: Includes explicit instructions to verify versions and database provider support before proceeding, and warns against inventing supported targets. Capability inventory: Executes shell commands for package installation and CLI operations, and reads/writes local configuration files. Sanitization: Relies on specific identification of version strings and provider names from structured files.
- [SAFE]: The use of placeholder credentials in connection string examples (e.g., user:password, Password123) is for documentation purposes and follows standard industry practice for environment variable management.
Audit Metadata