Audit History
prisma-cli - 7 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v7 Latest | Jul 23, 2026, 05:24 PM | 1 confirmed | 0 | No capability change |
| v6 | Jul 21, 2026, 10:22 AM | No confirmed findings | 0 | No capability change |
| v5 | Jul 21, 2026, 10:22 AM | No confirmed findings | 0 | No capability change |
| v4 | Jul 21, 2026, 10:22 AM | No confirmed findings | 0 | No capability change |
| v3 | Jul 21, 2026, 10:22 AM | No confirmed findings | 0 | No capability change |
| v2 | Jul 21, 2026, 10:22 AM | No confirmed findings | 0 | No capability change |
| v1 | Jul 21, 2026, 10:22 AM | No confirmed findings | 0 | Baseline |
Jul 23, 2026, 05:24 PM
The static alerts are false positives caused by Markdown backticks, standard Prisma environment configuration, relative project paths, and schema examples. No prompt injection, credential exfiltration, or hidden executable payload was found. A medium operational risk remains because quick references include destructive database commands without mandatory confirmation or target checks.
Confirmed security concerns (1)
Risk Factors
🔑 Env variables (26)
⚙️ External commands (49)
📁 Filesystem access (11)
Jul 21, 2026, 10:22 AM
All 102 static matches are false positives caused by Markdown command examples, fixed project-relative paths, and standard Prisma environment configuration. The reviewed files are documentation only; no prompt injection, credential exfiltration, or embedded executable payload was found. Some documented Prisma commands can modify or delete database data, so users should review targets and confirmations before running them.
Risk Factors
🔑 Env variables (26)
⚙️ External commands (49)
📁 Filesystem access (11)
Jul 21, 2026, 10:22 AM
All 102 static matches are false positives caused by Markdown command examples, fixed project-relative paths, and standard Prisma environment configuration. The reviewed files are documentation only; no prompt injection, credential exfiltration, or embedded executable payload was found. Some documented Prisma commands can modify or delete database data, so users should review targets and confirmations before running them.
Risk Factors
🔑 Env variables (26)
⚙️ External commands (49)
📁 Filesystem access (11)
Jul 21, 2026, 10:22 AM
All 102 static matches are false positives caused by Markdown command examples, fixed project-relative paths, and standard Prisma environment configuration. The reviewed files are documentation only; no prompt injection, credential exfiltration, or embedded executable payload was found. Some documented Prisma commands can modify or delete database data, so users should review targets and confirmations before running them.
Risk Factors
🔑 Env variables (26)
⚙️ External commands (49)
📁 Filesystem access (11)
Jul 21, 2026, 10:22 AM
All 102 static matches are false positives caused by Markdown command examples, fixed project-relative paths, and standard Prisma environment configuration. The reviewed files are documentation only; no prompt injection, credential exfiltration, or embedded executable payload was found. Some documented Prisma commands can modify or delete database data, so users should review targets and confirmations before running them.
Risk Factors
🔑 Env variables (26)
⚙️ External commands (49)
📁 Filesystem access (11)
Jul 21, 2026, 10:22 AM
All 102 static matches are false positives caused by Markdown command examples, fixed project-relative paths, and standard Prisma environment configuration. The reviewed files are documentation only; no prompt injection, credential exfiltration, or embedded executable payload was found. Some documented Prisma commands can modify or delete database data, so users should review targets and confirmations before running them.
Risk Factors
🔑 Env variables (26)
⚙️ External commands (49)
📁 Filesystem access (11)
Jul 21, 2026, 10:22 AM
All 102 static matches are false positives caused by Markdown command examples, fixed project-relative paths, and standard Prisma environment configuration. The reviewed files are documentation only; no prompt injection, credential exfiltration, or embedded executable payload was found. Some documented Prisma commands can modify or delete database data, so users should review targets and confirmations before running them.