prism-mcp-server (brdonath1/prism-mcp-server) is an MCP server listed on the M8ven Trust Index. It scores 74 out of 100, grade C. It declares 32 tools. No publisher has claimed this listing.
PRISM MCP Server — remote MCP server for GitHub-backed session continuity
Emerging. No concerning findings. Grades remain capped until the project builds reputation through adoption. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
brdonath1
Source: github_repo_search
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.
These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.
prism_analyticsCross-session analytics. Metrics: decision_velocity, session_patterns, handoff_size_history, file_churn, decision_graph, health_summary, fresh_eyes_check.
prism_bootstrapInitialize a PRISM session. Returns handoff, decisions, behavioral rules, intelligence brief, standing rules, and pre-fetched docs in one call.
cc_dispatchDispatch a task to Claude Code. query mode = read-only analysis, execute mode = writes + PR. Returns inline for quick tasks; use async_mode for longer runs.
cc_statusRetrieve status / results of Claude Code dispatches. Supply dispatch_id for a specific run, or omit for the most recent N.
prism_fetchFetch files from a PRISM project repo. Summary mode returns summaries for files >5KB.
prism_finalizePRISM finalization. Actions: audit (document inventory + drift), draft (AI-generated files; in compose mode returns validated draft_files + a review digest and persists them server-side), commit (backup + push + validate; use_draft_files: true commits the persisted draft so chat approves instead of …
gh_create_releaseCreate a new release on a GitHub repository owned by the configured GITHUB_OWNER.
gh_delete_branchDelete a branch from a GitHub repository owned by the configured GITHUB_OWNER. Refuses to delete the repository's default branch. Optionally refuses if the branch has any open pull requests against it.
gh_delete_tagDelete a tag from a GitHub repository owned by the configured GITHUB_OWNER. Idempotent: a tag that does not exist resolves to success with a note. No default-tag or open-PR guards (tags have no such concepts).
gh_get_branch_protectionRead the branch protection settings for a branch on a GitHub repository owned by the configured GITHUB_OWNER. Returns { protected: false } when the branch has no protection rule.
gh_set_branch_protectionReplace the branch protection settings for a branch on a GitHub repository owned by the configured GITHUB_OWNER. The PUT replaces protection wholesale — read the current settings with gh_get_branch_protection first and merge to preserve them. Omitted required-or-null keys (required_status_checks, en…
gh_update_releaseUpdate an existing release on a GitHub repository owned by the configured GITHUB_OWNER.
prism_load_rulesMid-session lazy-load of Tier B / Tier C standing rules from a project's rule sources (.prism/standing-rules.md unioned with insights.md), filtered by an explicit topic keyword (D-156 §3.5) or fetched by exact INS-N rule_id (brief-459 / SRV-12). Tier A is always excluded — those rules are auto-loade…
prism_log_decisionLog a decision atomically to _INDEX.md and domain file. Server-side formatting.
prism_log_insightLog an insight. Standing rules (standing_rule: true) land in .prism/standing-rules.md and are auto-loaded at bootstrap; other insights go to insights.md.
prism_patchSection-level operations (append/prepend/replace) on living documents. All-or-nothing semantics.
prism_pushPush files to a PRISM project repo. Validates all files first — none pushed if any fail.
railway_create_domainGenerate a Railway service domain for a service and return the generated domain URL.
railway_create_projectCreate a new Railway project. Returns the project ID and its auto-created production environment.
railway_create_serviceCreate a Railway service from a GitHub repo or a Docker image. Supports variables (with reference-syntax passthrough), rootDirectory, branch, and region.
railway_create_volumeCreate a persistent Railway volume and mount it into a service at the given path.
railway_delete_servicePermanently delete a Railway service. Requires confirm=true — refuses otherwise. Destructive and irreversible.
railway_deployManage Railway deployments — status, list, redeploy, restart. Mutations target the most recent deployment.
railway_envRead, set, and delete Railway environment variables. Sensitive values are masked in list output by default.
railway_logsFetch Railway deployment or environment logs. Supports @level:error filtering and keyword search.
railway_statusHigh-level Railway project/service health overview. Omit project to list all accessible projects.
railway_update_service_settingsUpdate Railway service settings (rootDirectory, startCommand, healthcheckPath, restartPolicy) for a service in an environment.
prism_scale_handoffHandoff scaling — redistributes content to living documents. Modes: full (default), analyze (preview), execute (run plan).
prism_searchSearch living documents within a single PRISM project. Returns ranked snippets. Single-project only.
prism_statusHealth status for one or all PRISM projects. Checks document completeness and handoff size.
prism_synthesizeGenerate or check AI-synthesized artifacts. Modes: generate (kick off background refresh of BOTH intelligence-brief.md AND pending-doc-updates.md and return immediately — INS-331; check completion via mode=status), status (existence + Last-synthesized of both).
prism_x_sentimentAnalyze aggregate public X sentiment for a topic using xAI x_search. Returns handle-free source URLs and aggregate labels only; never raw post text.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
When Vitest UI server is listening, arbitrary file can be read and executed
Claude SDK for TypeScript has Insecure Default File Permissions in Local Filesystem Memory Tool
Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock
ALLOWED_CIDRSANALYTICS_WALL_CLOCK_DEADLINE_MSANTHROPIC_API_KEYBANNER_DECISIONS_RACE_MSBOOTSTRAP_OVERSIZE_ERROR_BYTESBOOTSTRAP_OVERSIZE_WARN_BYTESBOOTSTRAP_WALL_CLOCK_DEADLINE_MSCC_DISPATCH_EFFORTCC_DISPATCH_MAX_TURNSCC_DISPATCH_MODELCC_DISPATCH_SYNC_TIMEOUT_MSCC_SUBPROCESS_SYNTHESIS_TIMEOUT_MSCLAUDE_CODE_OAUTH_TOKENDEFAULT_CONTEXT_WINDOW_TOKENSENABLE_IP_ALLOWLISTFETCH_AGGREGATE_BUDGET_BYTESFETCH_CONTENT_CAP_BYTESFETCH_WALL_CLOCK_DEADLINE_MSFINALIZE_AUDIT_DEADLINE_MSFINALIZE_COMMIT_DEADLINE_MSFINALIZE_DRAFT_DEADLINE_CC_MSFINALIZE_DRAFT_DEADLINE_MSFINALIZE_DRAFT_TIMEOUT_MSFINALIZE_FULL_AUDIT_DEADLINE_MSFRAMEWORK_REPOGITHUB_OWNERGITHUB_PATGITHUB_RETRY_BUDGET_MSHANDOFF_ITEM_BUDGET_BYTESLOAD_RULES_WALL_CLOCK_DEADLINE_MSLOG_LEVELMCP_AUTH_TOKENPATCH_WALL_CLOCK_DEADLINE_MSPREFETCH_SUMMARY_CAP_BYTESPUSH_WALL_CLOCK_DEADLINE_MSSCALE_WALL_CLOCK_DEADLINE_MSSEARCH_WALL_CLOCK_DEADLINE_MSSTANDING_RULES_WARNING_SIZESTATUS_WALL_CLOCK_DEADLINE_MSSUPABASE_ACCESS_TOKENSUPABASE_PROJECT_CREDENTIALS_JSONSYNTHESIS_INPUT_MAX_TOKENSSYNTHESIS_INPUT_TARGET_TOKENSSYNTHESIS_LOG_LOOKBACK_MSSYNTHESIS_MODELSYNTHESIS_TIMEOUT_MSTRIGGER_AUTO_ENROLLTRIGGER_STALE_ACTIVE_THRESHOLD_MSPORTTool annotations
8/32 tools have annotations
Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.
All four hints declared on every tool
32/32 tools missing one or more hints — prism_analytics (missing: readOnlyHint, idempotentHint); prism_bootstrap (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); cc_dispatch (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +29 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.
For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.
Tool inputs are validated
31/32 tool handlers declare input schemas (97%)
Declare an inputSchema with zod/joi/yup on every tool definition.
License file
No license file
Add a LICENSE file (MIT, Apache-2.0, etc.).
Shell command execution
3 calls in production code run through a shell (src/claude-code/client.ts:112, src/claude-code/client.ts:125, src/claude-code/client.ts:131)
Prefer library functions over shell-outs. If you must shell out, ensure all inputs are properly escaped.
Production dependencies are patched
1 medium severity in production deps
Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.
Dev dependencies
1 critical/high in dev-only deps (does not ship to users)
Upgrade dev dependencies when convenient.
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/brdonath1/prism-mcp-server)?variant=verified to the badge URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check