Audit History
prisma-postgres-setup - 10 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v10 Latest | Jul 23, 2026, 05:58 PM | 5 confirmed | 8 | No capability change |
| v9 | Jul 21, 2026, 10:22 AM | No confirmed findings | 0 | No capability change |
| v8 | Jul 21, 2026, 10:22 AM | No confirmed findings | 0 | No capability change |
| v7 | Jul 21, 2026, 10:22 AM | No confirmed findings | 0 | No capability change |
| v6 | Jul 21, 2026, 10:22 AM | No confirmed findings | 0 | No capability change |
| v5 | Jul 21, 2026, 10:22 AM | No confirmed findings | 0 | No capability change |
| v4 | Jul 21, 2026, 10:22 AM | No confirmed findings | 0 | No capability change |
| v3 | Jul 21, 2026, 10:22 AM | No confirmed findings | 0 | No capability change |
| v2 | Jul 21, 2026, 10:22 AM | No confirmed findings | 0 | No capability change |
| v1 | Jul 21, 2026, 10:22 AM | No confirmed findings | 0 | Baseline |
Jul 23, 2026, 05:58 PM
Ten static findings are confirmed: eight executable command spans and two operations involving secret-bearing environment files. Most alerts are Markdown, official Prisma URLs, placeholders, or standard local configuration. Contextual review found unsafe token handling and permanent project deletion, but no prompt injection or unrelated exfiltration.
Confirmed security concerns (5)
Capability review items (8)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
๐ Network access (17)
๐ Env variables (23)
โ๏ธ External commands (50)
Jul 21, 2026, 10:22 AM
All 128 static detections are false positives caused by Markdown formatting, documented Prisma API endpoints, and expected database credential configuration. The skill provisions a Prisma Postgres database only through the stated API workflow and includes safeguards for interactive choices, environment-file protection, and destructive deletion confirmation. No prompt injection, credential exfiltration, hidden execution, or unrelated network activity was found.
Risk Factors
๐ Network access (17)
๐ Env variables (23)
โ๏ธ External commands (50)
Jul 21, 2026, 10:22 AM
All 128 static detections are false positives caused by Markdown formatting, documented Prisma API endpoints, and expected database credential configuration. The skill provisions a Prisma Postgres database only through the stated API workflow and includes safeguards for interactive choices, environment-file protection, and destructive deletion confirmation. No prompt injection, credential exfiltration, hidden execution, or unrelated network activity was found.
Risk Factors
๐ Network access (17)
๐ Env variables (23)
โ๏ธ External commands (50)
Jul 21, 2026, 10:22 AM
All 128 static detections are false positives caused by Markdown formatting, documented Prisma API endpoints, and expected database credential configuration. The skill provisions a Prisma Postgres database only through the stated API workflow and includes safeguards for interactive choices, environment-file protection, and destructive deletion confirmation. No prompt injection, credential exfiltration, hidden execution, or unrelated network activity was found.
Risk Factors
๐ Network access (17)
๐ Env variables (23)
โ๏ธ External commands (50)
Jul 21, 2026, 10:22 AM
All 128 static detections are false positives caused by Markdown formatting, documented Prisma API endpoints, and expected database credential configuration. The skill provisions a Prisma Postgres database only through the stated API workflow and includes safeguards for interactive choices, environment-file protection, and destructive deletion confirmation. No prompt injection, credential exfiltration, hidden execution, or unrelated network activity was found.
Risk Factors
๐ Network access (17)
๐ Env variables (23)
โ๏ธ External commands (50)
Jul 21, 2026, 10:22 AM
All 128 static detections are false positives caused by Markdown formatting, documented Prisma API endpoints, and expected database credential configuration. The skill provisions a Prisma Postgres database only through the stated API workflow and includes safeguards for interactive choices, environment-file protection, and destructive deletion confirmation. No prompt injection, credential exfiltration, hidden execution, or unrelated network activity was found.
Risk Factors
๐ Network access (17)
๐ Env variables (23)
โ๏ธ External commands (50)
Jul 21, 2026, 10:22 AM
All 128 static detections are false positives caused by Markdown formatting, documented Prisma API endpoints, and expected database credential configuration. The skill provisions a Prisma Postgres database only through the stated API workflow and includes safeguards for interactive choices, environment-file protection, and destructive deletion confirmation. No prompt injection, credential exfiltration, hidden execution, or unrelated network activity was found.
Risk Factors
๐ Network access (17)
๐ Env variables (23)
โ๏ธ External commands (50)
Jul 21, 2026, 10:22 AM
All 128 static detections are false positives caused by Markdown formatting, documented Prisma API endpoints, and expected database credential configuration. The skill provisions a Prisma Postgres database only through the stated API workflow and includes safeguards for interactive choices, environment-file protection, and destructive deletion confirmation. No prompt injection, credential exfiltration, hidden execution, or unrelated network activity was found.
Risk Factors
๐ Network access (17)
๐ Env variables (23)
โ๏ธ External commands (50)
Jul 21, 2026, 10:22 AM
All 128 static detections are false positives caused by Markdown formatting, documented Prisma API endpoints, and expected database credential configuration. The skill provisions a Prisma Postgres database only through the stated API workflow and includes safeguards for interactive choices, environment-file protection, and destructive deletion confirmation. No prompt injection, credential exfiltration, hidden execution, or unrelated network activity was found.
Risk Factors
๐ Network access (17)
๐ Env variables (23)
โ๏ธ External commands (50)
Jul 21, 2026, 10:22 AM
All 128 static detections are false positives caused by Markdown formatting, documented Prisma API endpoints, and expected database credential configuration. The skill provisions a Prisma Postgres database only through the stated API workflow and includes safeguards for interactive choices, environment-file protection, and destructive deletion confirmation. No prompt injection, credential exfiltration, hidden execution, or unrelated network activity was found.