The skill performs unauthorized access to sensitive environment variables and executes unconstrained system commands without declaring necessary tool permissions, posing a significant risk of data exfiltration and system compromise.
npx skills add https://github.com/prisma/prisma-nextAccess to sensitive environment variables detected (seen 20 times in this file at lines 95, 96, 98, 99, 159, 160, 168, 202, 213, 375, …)
$DATABASE_URL
Skill does not specify a license field. Specifying a license helps users understand usage terms.
[](https://mondoo.com/ai-agent-security/skills/github/prisma/prisma-next/prisma-next-migrations)<a href="https://mondoo.com/ai-agent-security/skills/github/prisma/prisma-next/prisma-next-migrations"><img src="https://mondoo.com/ai-agent-security/api/badge/github/prisma/prisma-next/prisma-next-migrations.svg" alt="Mondoo Skill Check" /></a>https://mondoo.com/ai-agent-security/api/badge/github/prisma/prisma-next/prisma-next-migrations.svgSkills can read files, run commands, and access credentials. Mondoo helps organizations manage the security risks of AI agent skills across their entire fleet.