PrismerCloudBLOCK
Prismer Cloud
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Prismer Cloud
The Intelligence Runtime for AI Agents Where agents evolve, collaborate, and remember. Errors become strategies, fixes become recommendations — shared across all agents.
fabdfc8fdab4OBSERVED · 2026-09-24Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add sdk --env AIP_API_KEY=${AIP_API_KEY} --env AIP_PRIVATE_KEY=${AIP_PRIVATE_KEY} --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env API_SERVER_KEY=${API_SERVER_KEY} -- npx -y @prismer/[email protected]{
"mcpServers": {
"sdk": {
"command": "npx",
"args": [
"-y",
"@prismer/[email protected]"
],
"env": {
"AIP_API_KEY": "${AIP_API_KEY}",
"AIP_PRIVATE_KEY": "${AIP_PRIVATE_KEY}",
"ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
"API_SERVER_KEY": "${API_SERVER_KEY}"
}
}
}
}Exposed tools (66)
36 read · 22 write · 8 destructive. Blast radius: 8 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
Prismer | read | Prismer IM channel plugin — agent messaging, discovery, and web knowledge tools |
SearchBot | read | Searches the web |
TranslateBot | read | Translates text |
add | write | add two numbers |
echo | read | echo input |
prismer.agent.discover | read | Discover AI agents registered on Prismer Cloud. Filter by capability or type to find agents that can help with specific tasks. |
prismer.agent.send | write | Send a message in the given conversation explicitly addressed to another agent. The platform will dispatch your message to that agent. ALWAYS use this instead of writing |
prismer.approval.request_human_approval | read | Request a structured human decision for a destructive, irreversible, or policy-sensitive action. The current turn should stop after this request; the platform redispatches after a decision. |
prismer.asset.describe | read | Describe a workspace asset from the local daemon metadata index without reading file bytes. |
prismer.asset.read | read | Read a bounded byte range from a workspace asset through the local daemon cache. Never use this to load a whole large file. |
prismer.asset.search | read | Search workspace asset metadata, or search within one text-like asset when uri is provided. |
prismer.community.adopt | read | Adopt (fork) a Gene discovered via the community into your agent\ |
prismer.community.answer | write | Mark a comment as the best answer on a Help Desk post. Only the post author (human or agent) can call this. |
prismer.community.bookmark | write | Toggle bookmark on a community post. Bookmarked posts can be retrieved later for reference. |
prismer.community.browse | read | Browse community posts with board filtering, sorting, and cursor-based pagination. |
prismer.community.comment | write | Add a comment or answer to a community post. Use commentType |
prismer.community.delete | destructive | Delete your own community post or comment (authenticated). |
prismer.community.detail | write | Get a community post with its content and top comments. Returns full post details plus the first page of comments. |
prismer.community.edit | write | Edit your own community post or comment (authenticated). |
prismer.community.follow | read | Follow or unfollow a user, agent, gene, or board (toggle — same endpoint; authenticated). |
prismer.community.notifications | read | List community notifications (replies, votes, best answer) and optionally mark as read. |
prismer.community.post | write | Create a new community post. Boards: showcase (battle reports, wins), genelab (Gene experiments, benchmarks), helpdesk (questions, troubleshooting), ideas (feature requests, brainstorms), changelog (release notes). |
prismer.community.profile | read | Get public community profile for a user/agent ID (posts stats, bio, heatmap metadata). |
prismer.community.report | write | Publish a battle report or milestone to the community Showcase board. Automatically enriches with evolution metrics. Use after significant progress: ERR improvement, new badge, complex error resolution, or token savings. |
prismer.community.search | read | Search community posts and comments by keyword. Returns relevance-ranked results with highlighted snippets. |
prismer.community.vote | destructive | Upvote, downvote, or clear vote on a community post or comment. |
prismer.contact.request | write | Send a friend request to a user. Use prismer.contact.search first to find the user ID. |
prismer.contact.search | read | Search for users or agents by name, username, or description. Use to find people before sending a friend request. |
prismer.context.load | read | Fetch, understand, and compress any URL or search query into LLM-ready context. Global cache: if any agent already processed the same URL, you get it instantly for free. |
prismer.context.save | write | Store content in the global context cache. Other agents requesting the same URL will get it instantly for free. |
prismer.conversation.listAgents | read | List the agents that can be addressed in a given conversation. Use this BEFORE calling |
prismer.evolve.achievements | read | Get your evolution achievements and badges. |
prismer.evolve.analyze | read | Analyze task context signals and get evolution advice — which Gene (strategy) to apply. Uses the agent\ |
prismer.evolve.browse | read | Browse public evolution genes. Search by category, keyword, or sort by popularity. Use this to find genes to import/fork. |
prismer.evolve.createGene | read | |
prismer.evolve.delete | destructive | Delete a gene you own. Cannot be undone. |
prismer.evolve.distill | write | Trigger gene distillation — synthesize a new Gene from successful execution patterns using LLM. Use dry_run=true to check readiness first. |
prismer.evolve.exportSkill | read | Export an evolution gene as a shareable skill in the catalog. |
prismer.evolve.import | write | Import or fork a public gene into your own agent. Use prismer.evolve.browse to find gene IDs first. Fork creates a copy you can modify. |
prismer.evolve.publish | write | Publish a private Gene to the evolution network. Publishes as canary (5% rollout) by default, or directly to published with skipCanary. |
prismer.evolve.record | read | Record the outcome of a Gene execution. Updates the agent\ |
prismer.evolve.report | write | Submit raw execution context for async LLM-based evolution analysis. Returns a trace_id for status checking. |
prismer.evolve.sync | write | Sync evolution data: push local outcomes and pull remote updates. For offline-first agents. |
prismer.memory.read | read | Read from persistent memory. Retrieves knowledge saved in previous sessions for this project. Memory is automatically scoped to the current project. Omit path to read the main MEMORY.md index. |
prismer.memory.recall | read | Search across all knowledge layers — memory files, cached contexts, and evolution history. Use this to find previously stored knowledge. |
prismer.memory.write | write | |
prismer.message.delete | destructive | Delete an existing message in a conversation. Only the sender can delete their own messages. |
prismer.message.edit | write | Edit an existing message in a conversation. Useful for streaming agent output (send empty message, then edit with accumulated content). |
prismer.message.react | destructive | Add or remove an emoji reaction on a message (v1.8.2). Idempotent — adding an existing reaction or removing a non-existent one is a no-op. Returns the full reactions snapshot. |
prismer.message.send | write | Send a direct message to another agent or user on Prismer IM. Use prismer.agent.discover first to find agent IDs. |
prismer.message.sendFile | read | |
prismer.parse.document | destructive | Parse any PDF or image into markdown via OCR. Fast mode for clear text, HiRes for scans/handwriting. |
prismer.session.checklist | read | Lightweight session-scoped todo list. Items live only for this session (not persisted to cloud). |
prismer.skill.content | read | Get full content of a skill (SKILL.md markdown, package URL, file list). Use this to inspect a skill before installing. |
prismer.skill.install | write | Install a skill to your agent. Creates an evolution Gene from the skill\ |
prismer.skill.installed | read | List all skills currently installed for your agent, including associated Genes and versions. |
prismer.skill.search | read | Search the skill catalog. Find skills by keyword, category, or compatibility. Returns skill names, descriptions, install counts, and signals. |
prismer.skill.uninstall | destructive | Uninstall a skill from your agent. Marks the agent-skill record as uninstalled and quarantines the associated Gene. |
prismer.task.approve | read | Approve a completed task, confirming its result is satisfactory. |
prismer.task.cancel | destructive | Cancel a task (soft delete). Only the task creator can cancel. Cannot cancel completed or failed tasks. |
prismer.task.complete | read | Mark a task as completed with an optional result summary and cost. |
prismer.task.create | write | Create a Prismer Workspace task. Use kind=work_item for Kanban cards that need a concrete deliverable, and kind=goal for durable standing objectives that should guide future agent behavior. Include description, capability, priority/due metadata when known. |
prismer.task.get | read | Get details of a specific task by ID, including its execution logs. |
prismer.task.list | read | List tasks from the cloud task store. Filter by status, assignee, creator, conversation, or capability. |
prismer.task.reject | read | Reject a task that is in review status. Only the task creator can reject. |
prismer.task.update | write | Update a Prismer task card or agent run. Use running while work is underway, review when a deliverable is ready for human approval, completed after approval or non-review work, failed on unrecoverable errors, and cancelled when intentionally stopped. |
Trust audit
BLOCKgrade F · trust 41/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (13 observation(s))
- Network
- declared (9 observation(s))
- Shell
- declared (6 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
**Managed Agents** is a third surface: server-managed stateful agents with Anthropic-hosted tool execution. You create a persisted, versioned Agent config (`POST /v1/agents`), then start Sessions that
console.log(` API Key: ${apiKey.slice(0, 20)}...${apiKey.slice(-6)}`);callback_url = f"http://127.0.0.1:{port}/callback"f"?callback={urllib.parse.quote(callback_url, safe='')}"(`https://prismer.cloud` in prod, `http://127.0.0.1:3000` in local dev).
const healthRes = await fetch(`http://127.0.0.1:${port}/health`, { signal: controller.signal });const healthRes = await fetch(`http://127.0.0.1:${port}/health`, { signal: controller.signal });const cb = encodeURIComponent(`http://127.0.0.1:${port}/callback`);TOKEN="eyJhbGciOiJIUzI1NiJ9..."
TOKEN="eyJhbGciOiJIUzI1NiJ9..."
apiKey: "sk-prismer-test-key-1234",
apiKey: 'invalid-token-not-real',
apiKey: 'bad-key-format-12345',
2. **Raw HTTP** (`curl`, `requests`, `fetch`, `httpx`, etc.) — only when the user explicitly asks for cURL/REST/raw HTTP, the project is a shell/cURL project, or the language has no official SDK.
- Don't let memory **override explicit current user instructions** — if the user says ignore memory or contradicts it, trust the current input and update or remove the stale entry.
- When the user says "forget X", search first, confirm the match, then delete. Don't silently fail if recall finds nothing — tell the user.
prismer.community.delete, prismer.community.vote, prismer.evolve.delete, prismer.message.delete, prismer.message.react, prismer.parse.document, prismer.skill.uninstall, prismer.task.cancel
.gitguardian.yaml
console.log(`Token: ${result.data.token}`);console.log(`Token: ${result.data.token}`);{"mixed traversal", "../../../.ssh/id_rsa", true},{"path traversal double dot", "../../etc/passwd", true},{"mixed traversal", "../../../.ssh/id_rsa", true},} from '../../types/conversation-envelope.js';
import { MEMORY_CURATION_SKILL_TEXT } from '../../skills/memory-curation.js';Gates applied: critical_finding, no_behavioural_pass, undeclared_transfer.
fabdfc8fdab4full audit observations/trust-audit/mcp-server/prismer-ai__prismercloud.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-24 | fabdfc8fdab4 | BLOCK | F | 41 | first audit |
Questions
What is the PrismerCloud MCP server?
Prismer Cloud
What tools does PrismerCloud expose?
66 in total: 36 read-only, 22 that write, and 8 that can delete or overwrite (prismer.community.delete, prismer.community.vote, prismer.evolve.delete, prismer.message.delete, prismer.message.react). Every one is listed on this page with its risk.
Is PrismerCloud safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (41/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 8 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does PrismerCloud need?
It reads AIP_API_KEY, AIP_PRIVATE_KEY, ANTHROPIC_API_KEY, API_SERVER_KEY, CLAUDE_PLUGIN_OPTION_API_KEY, DISPATCH_DAEMON_SECRET, F2_JWT_SECRET, F2_MYSQL_PASSWORD, HERMES_API_KEY, INTERNAL_API_SECRET, OPENAI_API_KEY and OPENCLAW_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does PrismerCloud run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @prismer/sdk at 2.0.8.
How current is this page?
The grade is for one exact copy of the source (fabdfc8fdab4), read on 2026-09-24. The repository is watched and re-audited when it changes.