slr-prisma: why it is not safe to use
We did not identify security or privacy issues in slr-prisma based on the reviewed repository and documented workflow.
What we found
Our review of `keemanxp/slr-prisma` did not find evidence of the behaviors we typically flag in security and privacy reviews. The repository describes its triggers and workflow openly in `SKILL.md` and the README, without hidden or disguised instructions. We did not find hardcoded credentials, tokens, or API keys in the inspected files.
The skill appears focused on drafting documents, reading user-provided files, validating a DOCX, and copying results to a user output folder. Based on the reviewed materials, we did not see delete, overwrite, irreversible send actions, privilege escalation steps, or attempts to access unrelated credentials such as environment variables, keychains, browser data, or SSH keys. We also did not find obfuscated content, encoded payloads, undisclosed remote code fetches, or runtime execution from hidden sources. Its reference-checking behavior appears limited to ordinary web search.
What to do instead
This skill passed our review with a strong score. If you use it, keep standard safeguards in place: review the documented workflow, provide only the files needed for the task, and verify any web-sourced references before relying on the output.
Source: https://github.com/keemanxp/slr-prisma
We report what our security review found at the time we checked, with the goal of keeping people safe. Projects change; if a maintainer has since fixed this, we are glad to recheck it. Email hello@agentpod.com.