AgentPod is building a private, secure device for your AI agent.The AgentPod device is coming.Coming soonBe first
We checked this and rejected itsecurity

slr-prisma: why it is not safe to use

We did not identify security or privacy issues in slr-prisma based on the reviewed repository and documented workflow.

What we found

Our review of `keemanxp/slr-prisma` did not find evidence of the behaviors we typically flag in security and privacy reviews. The repository describes its triggers and workflow openly in `SKILL.md` and the README, without hidden or disguised instructions. We did not find hardcoded credentials, tokens, or API keys in the inspected files.

The skill appears focused on drafting documents, reading user-provided files, validating a DOCX, and copying results to a user output folder. Based on the reviewed materials, we did not see delete, overwrite, irreversible send actions, privilege escalation steps, or attempts to access unrelated credentials such as environment variables, keychains, browser data, or SSH keys. We also did not find obfuscated content, encoded payloads, undisclosed remote code fetches, or runtime execution from hidden sources. Its reference-checking behavior appears limited to ordinary web search.

What to do instead

This skill passed our review with a strong score. If you use it, keep standard safeguards in place: review the documented workflow, provide only the files needed for the task, and verify any web-sourced references before relying on the output.

Want the same outcome, safely? Use our checked skill instead.

Source: https://github.com/keemanxp/slr-prisma

We report what our security review found at the time we checked, with the goal of keeping people safe. Projects change; if a maintainer has since fixed this, we are glad to recheck it. Email hello@agentpod.com.

Copied to clipboard. Paste it into your AI (ChatGPT, Claude, or your agent) to add the skill.