
Security News
Insecure Agents Podcast: How to Keep AI Agents From Bypassing Security Controls
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.
@repo-prism/mcp-server
Advanced tools
MCP server over Core: local repository intelligence for coding agents
prism-mcp — give any MCP-capable agent structural answers about the repo
you have open, plus Dispatch (start my day, jobs, connect). Same engine as the
CLI and IDE extension. Local analysis. 45 tools.
Website: https://www.prismhq.in · Docs: https://www.prismhq.in/docs/start/install
Requires Node.js 26.
You never type tool names. After setup, ask in plain language (“is this repo healthy?”, “start my day”, “connect Slack”). The server instructs the agent which tools to call.
No --workspace path. After connect the server asks the client for MCP
roots (the folder you have open in chat). It also honours
WORKSPACE_FOLDER_PATHS and then walks up from the process cwd to the nearest
git root.
cd /path/to/your/projectclaude mcp add prism -- npx -y @repo-prism/mcp-server
.cursor/mcp.json (project) or ~/.cursor/mcp.json (global):
{
"mcpServers": {
"prism": {
"command": "npx",
"args": ["-y", "@repo-prism/mcp-server"]
}
}
}
claude_desktop_config.json
(macOS: ~/Library/Application Support/Claude/ · Windows: %APPDATA%\Claude\).{
"mcpServers": {
"prism": {
"command": "npx",
"args": ["-y", "@repo-prism/mcp-server"]
}
}
}
env.PRISM_WORKSPACE once if the client always starts from a fixed dir).~/.codex/config.toml.[mcp_servers.prism]
command = "npx"
args = ["-y", "@repo-prism/mcp-server"]
Only if auto-detection is wrong:
npx -y @repo-prism/mcp-server --workspace /path/to/repo
# or
PRISM_WORKSPACE=/path/to/repo npx -y @repo-prism/mcp-server
Do not leave a terminal on ready on stdio — that means the server is
waiting for an MCP client. Configure the client; it starts the process.
--workspace <path> (or -w, or first positional)PRISM_WORKSPACEroots/list from the client (the folder you are chatting in)WORKSPACE_FOLDER_PATHS (Cursor / VS Code open folders).gitVSCODE_CWD / INIT_CWD| You say | Agent should call |
|---|---|
| “What is this repo?” / “Orient me” | repository_dna, landmarks / overview |
| “Is this codebase healthy?” | repository_health |
“What breaks if I edit src/…?” | prepare_change / work_order, then blast_radius, test_impact |
| “Can I delete this?” | safe_delete |
| “Review my changes” | review_changes (omit paths to auto-discover) |
| “What changed?” | changed_paths |
| “Is the index ready?” | workspace_status |
| “Can Prism do X?” | capabilities |
| “Start my day” | start_my_day |
| Any request to change code (“fix the news tab highlighting”) | start_job |
| The same request plus “do it now” / “right here” | no job — inline edit |
| “Prism init” / set up jobs | init |
| “Prism sleep” / put Prism to sleep | sleep |
| “Prism wake” / wake up | wake |
| “Prism use …” | use_skill |
| “Where are we?” | list_jobs |
| “What is it doing?” / “show me the logs” | job_logs |
| “Remember this” | remember |
| “Configure Dispatch” | configure |
Optional MCP prompts (picker / slash in some clients): orient,
before_edit, review_diff, start_my_day, start_work, where_are_we,
connect, configure, init, sleep, wake.
Say prism init to set up local workers. The worker matches your host:
Cursor signs in via a browser page; Claude Code reuses the claude CLI
sign-in. Do not paste CURSOR_API_KEY into mcp.json — it is only an optional
CI override. Dispatch docs:
see the public Dispatch guide.
MCP resources (for clients that bind context): prism://dna,
prism://landmarks, prism://health.
| Surface | Use it for |
|---|---|
CLI (@repo-prism/cli) | Gates and scripts — exit codes, JSON for CI jobs, prism health, prism review, thresholds that fail a build |
| MCP (this package) | Interactive agent queries — orient, blast radius, review a working tree, explore symbols while chatting |
Do not drive CI pass/fail from MCP tool calls. Agents are non-deterministic about which tools they pick; the CLI is the stable gate. Install both when you want agents in the IDE and the same engine in pipelines.
npm install -g @repo-prism/mcp-server
# then use "command": "prism-mcp" instead of npx in configs
Manifest prepared for owner submission: server.json ·
REGISTRY.md · copy-paste config mcp-install.json.
Intelligence tools are read-only. Dispatch tools write state under
~/.prism/workspaces/<key>/dispatch/. Dispatch makes no network calls and
holds no third-party credentials — connectors belong to the agent window
(ADR-0049).
| Tool | Answers | Arguments |
|---|---|---|
start_my_day | Standup: jobs, git, connected drivers, connect CTAs | — |
init | One-time worker sign-in (Cursor browser login; Claude CLI check) | — |
sleep | Park the Console and hold queued jobs until wake | confirm |
wake | Bring the Console back and start queued jobs | confirm |
use_skill | Load a Prism skill (prism use <name>) | name |
start_job | Start a named teammate in its own worktree; returns immediately | title, prd, jobId, branch, confirmOverlap |
queue_finding | Fix one finding from a report tool; re-scans the report once checks pass instead of trusting job status (M-071) | finding, instructions |
list_jobs | Live activity plus finished results (“where are we”); names the jobs board | — |
job_logs | One job's console: activity lines (subagent lines marked) plus the review awaiting you | jobId, limit, since |
job_control | pause / resume / cancel / attach_context / commit (checkout jobs) | jobId, action, context |
remember | Save, list, or forget memories for the next job | action, text, scope, confirm |
configure | Standup settings or export a non-secret template | action, Slack channels, maxJobs, ticketHost |
dispatch_doctor | Worker backend + sign-in, role, job cap | — |
working_set | Get/patch a job's (or an inline session's) accumulated files, symbols, decisions, neighbors (M-073) | action, jobId, files, symbols, decisions, neighbors |
| Tool | Answers | Arguments |
|---|---|---|
repository_dna | Languages, frameworks, package manager, architecture hints, test runners, ranked domains | — |
repository_health | Overall health 0-100 with the per-factor breakdown | — |
repository_map | Structural map at a zoom level: nodes, edges, regions (default zoom package) | zoom, layers |
repository_overview | The dashboard snapshot: totals, coupling, regions, most connected, activity | activityDays |
list_packages | Packages in a monorepo, with roots | limit |
stack_profile | Frameworks, runtimes and build tooling, with detection signals | packageId |
landmarks | Entrypoints, package roots and feature anchors — where to start reading | limit |
explain_area | What a module or folder does: domains, degree, ownership | path |
workspace_status | Index readiness, freshness, git/cache presence, graph counts | — |
capabilities | Core + consent-gated capabilities with availability reasons | — |
| Tool | Answers | Arguments |
|---|---|---|
dependency_graph | The import graph, file-level or aggregated to packages (bounded) | packageAggregation, resolveAliases, limit, summaryOnly |
dependency_cycles | Import and re-export cycles | packageAggregation, limit |
knowledge_graph | Symbol declarations and the references between them | path or limit (required) |
feature_graph | Inferred features and how they depend on each other (bounded) | limit, summaryOnly |
list_features | Inferred features with member files and confidence | limit |
find_symbol | Exact-name symbol lookup | name, path, kind, limit |
search_symbols | Substring/regex symbol search (hard max 50) | pattern, regex, path, kind, limit |
find_references | Who actually calls or imports a symbol | name, path, start, limit |
dependency_route | How one file or symbol reaches another | from, to, maxAlternatives, maxHops |
| Tool | Answers | Arguments |
|---|---|---|
prepare_change | Pack, reuse, House Style, notes, and a work order for a task — never file bodies | task, budget |
work_order | In-scope, off-limits (generated/vendor), and needs-sign-off paths; optional path evaluates the advisory hook (M-076) | task, path |
blast_radius | What depends on this, and how risky is changing it | kind, id, path, intent, limit |
safe_delete | Can this be deleted? Blockers and files left orphaned | kind, id, path |
rename_impact | Every edit site a rename would touch | kind, id, path, newName |
test_impact | Which tests cover this change target | kind, id, path, limit |
breaking_change_hints | Deprecated — included in blast_radius | kind, id, path |
changed_paths | Working-tree or base-ref changed paths | base |
guard_session | Rank the current dirty session by blast risk, flagged for duplicate/orphan/boundary (M-072) | preExistingChanges |
review_changes | Rolled-up review; omit paths to auto-discover | paths?, base |
agents_md | Generate/verify the Living AGENTS.md — features, cycles, tests, owners; writes only ~/.prism, never the repo (M-073) | action |
list_findings | Unused exports, duplicate implementations, wrapper functions; excludes muted findings by default (M-074) | limit, includeMuted |
| Tool | Answers | Arguments |
|---|---|---|
engineering_health | Hotspots, churn, complexity, ownership, knowledge decay, debt | — |
health_history | Health over time, with provenance on each point | maxPoints |
explore_code | Everything about one file or symbol in one call (usages bounded) | kind, path, name, start, limit |
backend_report | Endpoints, auth, data layer, env, background jobs | packageId |
testing_report | Test structure, and coverage when artifacts are on disk | — |
security_report | Left-shift security posture against local configuration | — |
Full reference: MCP tools.
| CLI | @repo-prism/cli — npm i -g @repo-prism/cli then prism health |
| IDE | Prism |
| Docs | MCP guide |
| Website | prismhq.in |
| Source | github.com/Shailesh200/prism |
FAQs
MCP server over Core: local repository intelligence for coding agents
The npm package @repo-prism/mcp-server receives a total of 120 weekly downloads. As such, @repo-prism/mcp-server popularity was classified as not popular.
We found that @repo-prism/mcp-server demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.

Security News
GPT-6 Astra tried to plant malicious code in simulated open source projects using fake GitHub accounts and deceptive PRs during an assigned CTF challenge.

Security News
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.