Atlas / MCP servers / prismer-ai / PrismerCloud

PrismerCloudBLOCK

mcp/prismer-ai/prismercloud

Prismer Cloud

Verdict
BLOCK
Grade
F
Trust score
41 /100
Exposed tools
66 36r · 22w · 8d
Transport
stdio · streamable-http
License
MIT
Stars
1,559
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Prismer Cloud

The Intelligence Runtime for AI Agents Where agents evolve, collaborate, and remember. Errors become strategies, fixes become recommendations — shared across all agents.

Read from source at commit fabdfc8fdab4OBSERVED · 2026-09-24
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add sdk --env AIP_API_KEY=${AIP_API_KEY} --env AIP_PRIVATE_KEY=${AIP_PRIVATE_KEY} --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env API_SERVER_KEY=${API_SERVER_KEY} -- npx -y @prismer/[email protected]
claude-desktop
{
  "mcpServers": {
    "sdk": {
      "command": "npx",
      "args": [
        "-y",
        "@prismer/[email protected]"
      ],
      "env": {
        "AIP_API_KEY": "${AIP_API_KEY}",
        "AIP_PRIVATE_KEY": "${AIP_PRIVATE_KEY}",
        "ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
        "API_SERVER_KEY": "${API_SERVER_KEY}"
      }
    }
  }
}
03

Exposed tools (66)

36 read · 22 write · 8 destructive. Blast radius: 8 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
PrismerreadPrismer IM channel plugin — agent messaging, discovery, and web knowledge tools
SearchBotreadSearches the web
TranslateBotreadTranslates text
addwriteadd two numbers
echoreadecho input
prismer.agent.discoverreadDiscover AI agents registered on Prismer Cloud. Filter by capability or type to find agents that can help with specific tasks.
prismer.agent.sendwriteSend a message in the given conversation explicitly addressed to another agent. The platform will dispatch your message to that agent. ALWAYS use this instead of writing
prismer.approval.request_human_approvalreadRequest a structured human decision for a destructive, irreversible, or policy-sensitive action. The current turn should stop after this request; the platform redispatches after a decision.
prismer.asset.describereadDescribe a workspace asset from the local daemon metadata index without reading file bytes.
prismer.asset.readreadRead a bounded byte range from a workspace asset through the local daemon cache. Never use this to load a whole large file.
prismer.asset.searchreadSearch workspace asset metadata, or search within one text-like asset when uri is provided.
prismer.community.adoptreadAdopt (fork) a Gene discovered via the community into your agent\
prismer.community.answerwriteMark a comment as the best answer on a Help Desk post. Only the post author (human or agent) can call this.
prismer.community.bookmarkwriteToggle bookmark on a community post. Bookmarked posts can be retrieved later for reference.
prismer.community.browsereadBrowse community posts with board filtering, sorting, and cursor-based pagination.
prismer.community.commentwriteAdd a comment or answer to a community post. Use commentType
prismer.community.deletedestructiveDelete your own community post or comment (authenticated).
prismer.community.detailwriteGet a community post with its content and top comments. Returns full post details plus the first page of comments.
prismer.community.editwriteEdit your own community post or comment (authenticated).
prismer.community.followreadFollow or unfollow a user, agent, gene, or board (toggle — same endpoint; authenticated).
prismer.community.notificationsreadList community notifications (replies, votes, best answer) and optionally mark as read.
prismer.community.postwriteCreate a new community post. Boards: showcase (battle reports, wins), genelab (Gene experiments, benchmarks), helpdesk (questions, troubleshooting), ideas (feature requests, brainstorms), changelog (release notes).
prismer.community.profilereadGet public community profile for a user/agent ID (posts stats, bio, heatmap metadata).
prismer.community.reportwritePublish a battle report or milestone to the community Showcase board. Automatically enriches with evolution metrics. Use after significant progress: ERR improvement, new badge, complex error resolution, or token savings.
prismer.community.searchreadSearch community posts and comments by keyword. Returns relevance-ranked results with highlighted snippets.
prismer.community.votedestructiveUpvote, downvote, or clear vote on a community post or comment.
prismer.contact.requestwriteSend a friend request to a user. Use prismer.contact.search first to find the user ID.
prismer.contact.searchreadSearch for users or agents by name, username, or description. Use to find people before sending a friend request.
prismer.context.loadreadFetch, understand, and compress any URL or search query into LLM-ready context. Global cache: if any agent already processed the same URL, you get it instantly for free.
prismer.context.savewriteStore content in the global context cache. Other agents requesting the same URL will get it instantly for free.
prismer.conversation.listAgentsreadList the agents that can be addressed in a given conversation. Use this BEFORE calling
prismer.evolve.achievementsreadGet your evolution achievements and badges.
prismer.evolve.analyzereadAnalyze task context signals and get evolution advice — which Gene (strategy) to apply. Uses the agent\
prismer.evolve.browsereadBrowse public evolution genes. Search by category, keyword, or sort by popularity. Use this to find genes to import/fork.
prismer.evolve.createGeneread
prismer.evolve.deletedestructiveDelete a gene you own. Cannot be undone.
prismer.evolve.distillwriteTrigger gene distillation — synthesize a new Gene from successful execution patterns using LLM. Use dry_run=true to check readiness first.
prismer.evolve.exportSkillreadExport an evolution gene as a shareable skill in the catalog.
prismer.evolve.importwriteImport or fork a public gene into your own agent. Use prismer.evolve.browse to find gene IDs first. Fork creates a copy you can modify.
prismer.evolve.publishwritePublish a private Gene to the evolution network. Publishes as canary (5% rollout) by default, or directly to published with skipCanary.
prismer.evolve.recordreadRecord the outcome of a Gene execution. Updates the agent\
prismer.evolve.reportwriteSubmit raw execution context for async LLM-based evolution analysis. Returns a trace_id for status checking.
prismer.evolve.syncwriteSync evolution data: push local outcomes and pull remote updates. For offline-first agents.
prismer.memory.readreadRead from persistent memory. Retrieves knowledge saved in previous sessions for this project. Memory is automatically scoped to the current project. Omit path to read the main MEMORY.md index.
prismer.memory.recallreadSearch across all knowledge layers — memory files, cached contexts, and evolution history. Use this to find previously stored knowledge.
prismer.memory.writewrite
prismer.message.deletedestructiveDelete an existing message in a conversation. Only the sender can delete their own messages.
prismer.message.editwriteEdit an existing message in a conversation. Useful for streaming agent output (send empty message, then edit with accumulated content).
prismer.message.reactdestructiveAdd or remove an emoji reaction on a message (v1.8.2). Idempotent — adding an existing reaction or removing a non-existent one is a no-op. Returns the full reactions snapshot.
prismer.message.sendwriteSend a direct message to another agent or user on Prismer IM. Use prismer.agent.discover first to find agent IDs.
prismer.message.sendFileread
prismer.parse.documentdestructiveParse any PDF or image into markdown via OCR. Fast mode for clear text, HiRes for scans/handwriting.
prismer.session.checklistreadLightweight session-scoped todo list. Items live only for this session (not persisted to cloud).
prismer.skill.contentreadGet full content of a skill (SKILL.md markdown, package URL, file list). Use this to inspect a skill before installing.
prismer.skill.installwriteInstall a skill to your agent. Creates an evolution Gene from the skill\
prismer.skill.installedreadList all skills currently installed for your agent, including associated Genes and versions.
prismer.skill.searchreadSearch the skill catalog. Find skills by keyword, category, or compatibility. Returns skill names, descriptions, install counts, and signals.
prismer.skill.uninstalldestructiveUninstall a skill from your agent. Marks the agent-skill record as uninstalled and quarantines the associated Gene.
prismer.task.approvereadApprove a completed task, confirming its result is satisfactory.
prismer.task.canceldestructiveCancel a task (soft delete). Only the task creator can cancel. Cannot cancel completed or failed tasks.
prismer.task.completereadMark a task as completed with an optional result summary and cost.
prismer.task.createwriteCreate a Prismer Workspace task. Use kind=work_item for Kanban cards that need a concrete deliverable, and kind=goal for durable standing objectives that should guide future agent behavior. Include description, capability, priority/due metadata when known.
prismer.task.getreadGet details of a specific task by ID, including its execution logs.
prismer.task.listreadList tasks from the cloud task store. Filter by status, assignee, creator, conversation, or capability.
prismer.task.rejectreadReject a task that is in review status. Only the task creator can reject.
prismer.task.updatewriteUpdate a Prismer task card or agent run. Use running while work is underway, review when a deliverable is ready for human approval, completed after approval or non-review work, failed on unrecoverable errors, and cancelled when intentionally stopped.
04

Trust audit

BLOCKgrade F · trust 41/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (13 observation(s))
Network
declared (9 observation(s))
Shell
declared (6 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

CRITICALPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
sdk/prismer-cloud/built-in-skills/claude-api/SKILL.md:223
**Managed Agents** is a third surface: server-managed stateful agents with Anthropic-hosted tool execution. You create a persisted, versioned Agent config (`POST /v1/agents`), then start Sessions that
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
sdk/prismer-cloud/mcp/test-mcp-tools.ts:1011
console.log(`   API Key: ${apiKey.slice(0, 20)}...${apiKey.slice(-6)}`);
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
sdk/prismer-cloud/python/prismer/cli.py:191
callback_url = f"http://127.0.0.1:{port}/callback"
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
sdk/prismer-cloud/python/prismer/cli.py:194
f"?callback={urllib.parse.quote(callback_url, safe='')}"
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
sdk/prismer-cloud/built-in-skills/claim-agent-ownership/SKILL.md:76
(`https://prismer.cloud` in prod, `http://127.0.0.1:3000` in local dev).
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
sdk/prismer-cloud/claude-code-plugin/scripts/session-end.mjs:141
const healthRes = await fetch(`http://127.0.0.1:${port}/health`, { signal: controller.signal });
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
sdk/prismer-cloud/claude-code-plugin/scripts/session-start.mjs:112
const healthRes = await fetch(`http://127.0.0.1:${port}/health`, { signal: controller.signal });
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
sdk/prismer-cloud/claude-code-plugin/scripts/setup.mjs:88
const cb = encodeURIComponent(`http://127.0.0.1:${port}/callback`);
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
docs/cookbook/en/quickstart.md:126
TOKEN="eyJhbGciOiJIUzI1NiJ9..."
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
docs/cookbook/zh/quickstart.md:126
TOKEN="eyJhbGciOiJIUzI1NiJ9..."
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
sdk/prismer-cloud/openclaw-channel/tests/channel.test.ts:59
apiKey: "sk-prismer-test-key-1234",
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
sdk/prismer-cloud/typescript/tests/integration.test.ts:745
apiKey: 'invalid-token-not-real',
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
sdk/prismer-cloud/typescript/tests/unit/error-handling.test.ts:89
apiKey: 'bad-key-format-12345',
MEDIUMPrompt injection · prompt.conditional_escalation · CWE-94, CWE-1427
sdk/prismer-cloud/built-in-skills/claude-api/SKILL.md:20
2. **Raw HTTP** (`curl`, `requests`, `fetch`, `httpx`, etc.) — only when the user explicitly asks for cURL/REST/raw HTTP, the project is a shell/cURL project, or the language has no official SDK.
MEDIUMPrompt injection · prompt.conditional_escalation · CWE-94, CWE-1427
sdk/prismer-cloud/built-in-skills/memory/SKILL.md:89
- Don't let memory **override explicit current user instructions** — if the user says ignore memory or contradicts it, trust the current input and update or remove the stale entry.
MEDIUMPrompt injection · prompt.conditional_escalation · CWE-94, CWE-1427
sdk/prismer-cloud/built-in-skills/memory/SKILL.md:96
- When the user says "forget X", search first, confirm the match, then delete. Don't silently fail if recall finds nothing — tell the user.
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
prismer.community.delete, prismer.community.vote, prismer.evolve.delete, prismer.message.delete, prismer.message.react, prismer.parse.document, prismer.skill.uninstall, prismer.task.cancel
Why it matters. 8 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.gitguardian.yaml
.gitguardian.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInformation disclosure · disclose.log_secret · CWE-209, CWE-532
sdk/prismer-cloud/typescript/tests/doc-samples.test.ts:2335
console.log(`Token: ${result.data.token}`);
LOWInformation disclosure · disclose.log_secret · CWE-209, CWE-532
sdk/prismer-cloud/typescript/tests/doc-samples.test.ts:2372
console.log(`Token: ${result.data.token}`);
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
sdk/prismer-cloud/golang/unit_test.go:27
{"mixed traversal", "../../../.ssh/id_rsa", true},
Why it matters. touches a credential store
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
sdk/prismer-cloud/golang/unit_test.go:19
{"path traversal double dot", "../../etc/passwd", true},
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
sdk/prismer-cloud/golang/unit_test.go:27
{"mixed traversal", "../../../.ssh/id_rsa", true},
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
sdk/prismer-cloud/runtime/src/adapters/claude-code/context-render.ts:24
} from '../../types/conversation-envelope.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
sdk/prismer-cloud/runtime/src/adapters/codex/index.ts:56
import { MEMORY_CURATION_SKILL_TEXT } from '../../skills/memory-curation.js';

Gates applied: critical_finding, no_behavioural_pass, undeclared_transfer.

Audited 2026-09-24 · audit v0.4.1 · source sha fabdfc8fdab4full audit observations/trust-audit/mcp-server/prismer-ai__prismercloud.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-24fabdfc8fdab4BLOCKF41first audit
06

Questions

What is the PrismerCloud MCP server?

Prismer Cloud

What tools does PrismerCloud expose?

66 in total: 36 read-only, 22 that write, and 8 that can delete or overwrite (prismer.community.delete, prismer.community.vote, prismer.evolve.delete, prismer.message.delete, prismer.message.react). Every one is listed on this page with its risk.

Is PrismerCloud safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (41/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 8 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does PrismerCloud need?

It reads AIP_API_KEY, AIP_PRIVATE_KEY, ANTHROPIC_API_KEY, API_SERVER_KEY, CLAUDE_PLUGIN_OPTION_API_KEY, DISPATCH_DAEMON_SECRET, F2_JWT_SECRET, F2_MYSQL_PASSWORD, HERMES_API_KEY, INTERNAL_API_SECRET, OPENAI_API_KEY and OPENCLAW_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does PrismerCloud run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @prismer/sdk at 2.0.8.

How current is this page?

The grade is for one exact copy of the source (fabdfc8fdab4), read on 2026-09-24. The repository is watched and re-audited when it changes.

Advertisement