πŸ“¦

Audit History

prisma-next-debug - 1 audit

Aug 17, 2026, 08:41 AM

Static analysis misidentified Markdown inline-code formatting as executable shell syntax. The skill is documentation-only, but it recommends a command that can apply destructive database changes without explicit approval.

1
Files scanned
146
Lines analyzed
5
Review items
0
False positives ignored

Confirmed security concerns (1)

High
Destructive Database Confirmation Bypass
The recovery table advises re-running db update with -y to apply destructive changes without requiring explicit user approval or a backup.
Line 101 explicitly recommends the confirmation-bypass flag for a command identified as destructive. A dry-run alternative reduces, but does not remove, the risk.
Audited by: codex