Prismor is a free, open-source security layer for AI coding agents, built by PrismorSec. It sits between an agent and the actions that agent wants to take, checking each tool call against a policy before the call runs. Every call gets one of three verdicts: allow, warn, or block, according to Help Net Security.

The tool is aimed at a specific gap: AI coding agents run shell commands, read and write files, handle credentials, and call outside APIs, often chaining many steps with little human review. Risks include poisoned files, issues, or web pages that redirect the agent mid-task, an agent opening a .env file while debugging and sending its contents out, and installs of compromised packages. Endpoint security tools watch the kernel and file system, so they only see what the agent does after the choice is made; Prismor steps in before that point.

Prismor's rules start in observe mode by default, logging each call and any finding to a dashboard that runs locally. Users then choose which rules to switch to enforce, blocking actions in real time. PrismorSec measured the added delay at 0.8 milliseconds per tool call across 10,000 simulated agent sessions. The setup command offers three preset postures: the dev-safe preset rates 31 percent coverage and 9 percent friction, while the regulated-airgap preset, which cuts off network and shell access, rates 100 percent coverage and 90 percent friction.

The project also wraps package managers such as npm and pip, scoring each install on package age, maintainer count, install scripts, and known indicators of compromise. A score of 60 or higher blocks the install, and a match on a known indicator always does. Shipped rules cover two May 2026 attacks: mini-shai-hulud and the AntV hijacked-maintainer incident. Pattern-matching rules catch obvious prompt injections, while an optional semantic guard sends uncertain cases to an LLM for a second look; PrismorSec says it improved the catch rate by 30 percent across more than 800 cases without flagging more harmless text. Prismor is available for free on GitHub. The report is from a single source, so there are no conflicting accounts to compare.