Security scanner for AI Agent skills, plugins, and MCP servers with A-F grading.
Most payments and commerce work still happens through a UI a human drives. Prism Scanner MCP server moves it into the conversation instead. Security scanner for AI Agent skills, plugins, and MCP servers with A-F grading.
Prism analyzes code for malicious behavior before you install it — and checks your system for leftover threats after you uninstall.
prism-scanner on npm is all you need. Most clients run it directly, so configuration is a few lines and a restart.
The server publishes 13 tools. What each one is for:
P10 — Agent psychological manipulation detection**: detects gaslighting, guilt-tripping, authority impersonation, urgency pressure, and emotional coercionuses — actions/checkout@v4name — Set up PythonMulti-Platform — Scans ClawHub skills, MCP servers, npm packages, and pip packages with platform-aware rulesSuppression — Use .prismignore to suppress known findings by rule ID with justificationPre-install — :white_check_mark: Reputation scorePost-uninstall — :x:Inspection — Black-box ratingPlatforms — Single ecosystemSource — ClosedExecution — Requires uploadLayer — FocusPlenty of payments and commerce servers cover similar ground. The differences that matter in practice are scope of access and how much setup stands between you and a working tool call. Prism Scanner's toolset — P10, uses, name and 10 more — is a fair guide to whether it matches your workflow. It is maintained by aidongise-cell; worth a glance at recent repository activity before you build anything load-bearing on it.
SyncDev reviews every entry in this directory against the project's own documentation before publishing, and revisits them as servers change.
| Tool | What it does |
|---|---|
| P10 | Agent psychological manipulation detection**: detects gaslighting, guilt-tripping, authority impersonation, urgency pressure, and emotional coercion patterns embedded in skill descriptions, prompts, and code strings. Bas |
| uses | actions/checkout@v4 |
| name | Set up Python |
| Multi-Platform | Scans ClawHub skills, MCP servers, npm packages, and pip packages with platform-aware rules |
| Suppression | Use .prismignore to suppress known findings by rule ID with justification |
| Pre-install | :white_check_mark: Reputation score |
| Post-uninstall | :x: |
| Inspection | Black-box rating |
| Platforms | Single ecosystem |
| Source | Closed |
| Execution | Requires upload |
| Layer | Focus |
| Grade | Label |
{
"mcpServers": {
"prism-scanner": {
"command": "npx",
"args": ["-y", "prism-scanner"]
}
}
}Add to claude_desktop_config.json, then restart Claude Desktop.
Payments infrastructure meets AI — customers, invoices, subscriptions and current API docs from Stripe's server.
Build for Shopify with current APIs — the official Dev MCP server for schema-accurate storefront and admin code.
Give your AI assistant a supervised window into your Interactive Brokers account — balances, positions, live quotes and orders.
Invoices, payments and disputes through PayPal's official server — commerce operations by conversation.
Enables querying and listing Azure resources and costs directly from an MCP client.
Empowers LLMs with Bitcoin Lightning Network payment capabilities via the ZBD API.