Atlas / MCP servers / prismatic-io / Prismatic

PrismaticSAFE

mcp/prismatic-io/prismatic

An MCP server for interacting with Prismatic dev tools.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
19 11r · 8w · 0d
Transport
stdio
License
MIT
Stars
26
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

@prismatic-io/prism-mcp

Prism MCP Server is a local Model Context Protocol (MCP) server that helps AI assistants work with the Prismatic API for code-native integration and custom component development.

Agent Skills Also Available If you're interested in AI-assisted coding, also check out our Claude Plugin, which helps your AI assistant understand the Prismatic ecosystem and provides tools for integration development, component development, and more.

Features

This MCP server provides several tools, organized into categories. You may register whatever set of tools are most relevant to your use case.

General Tools (Always Available)

  • prism_me: Check login status and display current user profile information
  • prism_components_list: List all available components with version options

Integration Tools (Toolset: "integration")

Utilities

  • prism_integrations_list: List all integrations
  • prism_integrations_init: Initialize a new Code Native Integration
  • prism_integrations_convert: Convert an existing Low-Code Integration to Code Native
  • prism_integrations_flows_list: List flows for an integration
  • prism_integrations_flows_test: Test a flow in an integration
  • prism_integrations_flows_listen: Set a flow to "Listening Mode" to capture webhook payloads or polling trigger responses, saving them as payloads for prism_integrations_flows_test
  • prism_integrations_import: Import an integration from a specific directory

Codegen

  • prism_install_component_manifest: Generate component manifest in CNI src directory (requires [email protected] or greater)
  • prism_install_legacy_component_manifest: Generate line to add to a CNI's devDependencies for legacy component manifest installation
  • prism_integrations_generate_flow: Generate boilerplate fil
Read from source at commit 893d740202c1OBSERVED · 2026-10-09
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code (npm)
claude mcp add prism-mcp -- npx -y @prismatic-io/[email protected] {workingDirectory} {toolFilter}
03

Exposed tools (19)

11 read · 8 write · 0 destructive.

ToolRiskDescription
prism_components_generate_manifestwriteGenerate the type manifest for a Prismatic component to enable its usage within a Code-Native Integration. The component is built with
prism_components_initreadInitialize a new Prismatic custom component. Passing a WSDL or OpenAPI spec scaffolds the component from that definition.
prism_components_listreadList the components available in your organization. Searching for
prism_components_publishwritePublish a custom Prismatic component from a specific directory. The directory is built with
prism_install_component_manifestwriteIf using [email protected] or greater, generate a manifest in CNI src.
prism_install_legacy_component_manifestwriteFallback for when prism_install_component_manifest fails. Generates the devDependencies entry that installs a legacy component manifest.
prism_integrations_add_connection_config_varwriteReturns the path to a file that contains a connection wrapper function. If not available, generates boilerplate code for a connection config variable.
prism_integrations_add_datasource_config_varwriteReturns the path to a file that contains a data source wrapper function. If not available, generates boilerplate code for a data source config variable.
prism_integrations_convertreadConvert an existing Low-Code Integration into a Code Native Integration, scaffolding the generated code in the working directory
prism_integrations_flows_listreadList flows for an integration
prism_integrations_flows_listenwriteSet a flow to
prism_integrations_flows_testreadTest a flow in a Prismatic integration. Output is always returned quietly, as JSONL when tailing logs or results.
prism_integrations_generate_config_pagereadGenerate boilerplate code for a CNI config page. The result should be included in the CNI
prism_integrations_generate_config_varreadGenerate boilerplate code for a config variable. The result should be included in a CNI
prism_integrations_generate_flowreadGenerate boilerplate file for a CNI flow. The result should be included in the CNI
prism_integrations_importwriteImport a Prismatic code-native integration from a specific directory. The directory is built with
prism_integrations_initreadInitialize a new Prismatic Code Native Integration (CNI)
prism_integrations_listreadList all integrations in your organization
prism_mereadCheck Prismatic login status and display current user profile information
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (3)

LOWObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
README.md:133
Or, click this link to install automatically: [Add MCP Server to Cursor](cursor://anysphere.cursor-deeplink/mcp/install?name=prism&config=ewogICJ0eXBlIjogInN0ZGlvIiwKICAiY29tbWFuZCI6ICJucHgiLAogICJhcm
LOWPrivilege escalation / persistence · priv.escalate · CWE-269, CWE-250
.github/workflows/release.yml:107
sudo mv mcp-publisher /usr/local/bin/
Why it matters. asks for elevated privileges
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, @prismatic-io/prism, lodash-es, tinyexec, zod, @biomejs/biome, @types/lodash-es, @types/node
Why it matters. 10 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-09 · audit v0.4.1 · source sha 893d740202c1full audit observations/trust-audit/mcp-server/prismatic-io__prismatic.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-09893d740202c1SAFEB89first audit
06

Questions

What is the Prismatic MCP server?

An MCP server for interacting with Prismatic dev tools.

What tools does Prismatic expose?

19 in total: 11 read-only, 8 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Prismatic safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Prismatic need?

No credential environment variables were found in its source, so it appears to need none.

How does Prismatic run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @prismatic-io/prism-mcp at 1.5.0.

How current is this page?

The grade is for one exact copy of the source (893d740202c1), read on 2026-10-09. The repository is watched and re-audited when it changes.

Advertisement