prisma-cli-db-pull
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill documentation describes executing the
prismaCLI tool via the shell to perform database introspection. This uses a well-known developer tool for its intended purpose. - [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection because it ingests and processes external database schemas. Malicious instructions could be embedded in database metadata, such as table or column comments, which the agent might interpret as instructions during the introspection process.
Audit Metadata