Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

io.github.prismnetwork-tech/mcp

NPM · @PRISMNETWORK/MCP · SCANNED SEP 29

Rent real NVIDIA GPUs from your agent. Browse with no wallet; pay per second onchain.

Available components

0 this week 85 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score → Why this is hard to score →

Supply Chain Security98
  • No malware found by supply-chain analysis.Pass
  • A known CVE affects elliptic, but no fixed version has been published, so there is nothing to upgrade to. View diagnostics → Partial
  • No install/post-install scripts declared.Pass
  • 42 of 133 dependencies flagged as unhealthy. View diagnostics → Partial
Provenance & Transparency48
  • Source repository is publicly reachable at the declared URL. View diagnostics → Pass
  • Provenance check failed: no build-provenance attestation is published. See how to fix → View diagnostics → Fail
  • Clear OSI-approved license (Apache-2.0).Pass
  • Actively maintained (last published 2 days ago).Pass
  • Publishes a security disclosure policy (SECURITY.md).Pass
Schema Quality & AI Usability76
  • AI-judged instruction clarity (excellent).Pass
  • Context-footprint check failed: tool/resource definitions use about 2415 tokens (~115/item across 21 items; 21 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management100
  • No destabilizing schema changes in the last 30 days.Pass
Tool Coverage98
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 93% of tool parameters carry a description.Partial
Tool Safety100
  • No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
  • All 1 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
  • An AI judge read all 21 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
  • Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Install

How do I install the io.github.prismnetwork-tech/mcp server?

io.github.prismnetwork-tech/mcp runs locally as an npm package, launched with npx -y @prismnetwork/mcp. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

npm · @prismnetwork/mcp

# add to Claude Code
claude mcp add prismnetwork-tech-mcp -- npx -y @prismnetwork/mcp
// .cursor/mcp.json
{
  "mcpServers": {
    "prismnetwork-tech-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "@prismnetwork/mcp"
      ]
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "prismnetwork-tech-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "@prismnetwork/mcp"
      ]
    }
  }
}
# add to Codex CLI
codex mcp add prismnetwork-tech-mcp -- npx -y @prismnetwork/mcp
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "prismnetwork-tech-mcp": {
      "type": "local",
      "command": [
        "npx",
        "-y",
        "@prismnetwork/mcp"
      ],
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add prismnetwork-tech-mcp --command npx --arg -y --arg @prismnetwork/mcp
# ~/.hermes/config.yaml
mcp_servers:
  prismnetwork-tech-mcp:
    command: "npx"
    args: ["-y", "@prismnetwork/mcp"]
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "prismnetwork-tech-mcp": {
      "Transport": "stdio",
      "Command": "npx",
      "Arguments": [
        "-y",
        "@prismnetwork/mcp"
      ]
    }
  }
}
# add to Vellum
assistant mcp add prismnetwork-tech-mcp -t stdio -c npx -a -y @prismnetwork/mcp
// mcp.json
{
  "mcpServers": {
    "prismnetwork-tech-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "@prismnetwork/mcp"
      ]
    }
  }
}
Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 29 Sept 26 +1
    • Stability: 0.97 → pass security
  • 28 Sept 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 27 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 90 to 93. That category is still filling its 30-day observation window: 27 days of observed history at the previous scan, 28 at this one. The score rises as the window fills, whether or not the server changes.

  • 26 Sept 26 0
    • Package version: 0.9.4 → 0.10.0 functional
  • 25 Sept 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 24 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 80 to 83. That category is still filling its 30-day observation window: 24 days of observed history at the previous scan, 25 at this one. The score rises as the window fills, whether or not the server changes.

  • 23 Sept 26 −3
    • Stability: pass → 0.80 functional
  • 22 Sept 26 +1
    • Stability: 0.97 → pass security
Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 29 Sept 2026 · Analysed npm/@prismnetwork/mcp@0.10.0

Provenance No attestation

The registry publishes no build provenance for this version, so there is nothing to verify.

Result No attestation
Ecosystem npm

Background: How many MCP packages publish verified provenance →

Vulnerabilities 1 finding
ID CVE Severity Vector Fix available
GHSA-848j-6mx2-7j84 CVE-2025-14505 medium CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L no

Background: What a vulnerability scan can and cannot prove →

Dependencies 133 packages
Packages resolved 133
Stale 41
No linked repository 1
Tree resolution Complete

Background: SBOMs and build attestations, explained →

MCP tools · 21 exposed · ~2,415 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
prism_batch_result ~58

Read the output of a batch lease by lease_id, once its node has reported. Use it to recover a result after prism_batch_run timed out.

NameTypeReqDescription
lease_idintegeryesThe lease_id from prism_batch_run's output or error.

No output schema declared.

No examples provided.

prism_batch_run ~253

Fund a lease that runs one command with no interactive access at all: the node executes it and reports the signed output. Matches only suppliers at trust class 'isolated' or above, so it can find no supplier when none is online; prefer prism_lease_and_run for broad availability. Output is capped at 64 KiB per stream.

NameTypeReqDescription
commandstringyesShell command to run (max 8 KiB).
decisionobject–Why this lease is being funded. Required when the operator set a spend policy (see prism_budget), and the lease is refused before anything is quoted if the decision does not meet it. Only a hash of i…
duration_secondsinteger–Paid window in seconds (default 900, max 21600). A command still running at the end is killed and reported exit 124.
max_usdgnumber–Cost ceiling for this lease in USDG. It lowers the operator's PRISM_MAX_USDG and cannot raise it; omitted, that ceiling applies. See prism_budget.
min_vram_mibinteger–Minimum GPU memory in MiB (default 16000).

No output schema declared.

No examples provided.

prism_budget ~55

Show the spending limits this server enforces and what it has already spent in the last 24 hours, with the recent charges. Needs no wallet. Check this before a long job; a lease refused for budget says the same numbers.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

prism_confidential_infer ~248

Buy one LLM generation that runs inside a GPU TEE, with the message contents encrypted end to end to a key the enclave's own attestation commits to, so Prism's relay in between carries ciphertext and cannot read the prompt or the answer. Costs a little more than prism_infer. Returns the answer, the cost, and a receipt id the workload signed over the exact bytes of the exchange; pass that id to prism_verify_attestation to check the whole chain. Use it for anything the operator of an ordinary endpoint should not be able to read.

NameTypeReqDescription
e2eeboolean–Encrypt message contents to the attested enclave key (default true). Turn it off only when the relay is allowed to read the prompt.
max_tokensinteger–Cap on generated tokens (default 512). The price is quoted against this cap.
max_usdgnumber–Refuse if the quoted price exceeds this (default 0.25). The operator's PRISM_MAX_USDG binds it either way.
modelstring–Confidential model to use; defaults to the endpoint's first.
promptstringyesThe prompt to generate from.

No output schema declared.

No examples provided.

prism_end_lease ~55

Release a lease. Access closes and billing stops here: settlement charges the seconds the lease was open and returns the rest of the deposit. A lease nobody releases bills until its window ends.

NameTypeReqDescription
lease_idintegeryes–

No output schema declared.

No examples provided.

prism_infer ~151

Buy one LLM generation from Prism's managed inference endpoint. Pays the quoted USDG price from this wallet (about 0.01 USDG), waits through a cold start when no box is warm (up to a few minutes), and returns the generation with token usage. Cheaper and simpler than leasing when all you need is a completion.

NameTypeReqDescription
max_usdgnumber–Refuse if the quoted price exceeds this (default 0.05). The operator's PRISM_MAX_USDG binds it either way.
modelstring–Model to use; defaults to the endpoint's first offered model.
promptstringyesThe prompt to generate from (max 32 KiB).

No output schema declared.

No examples provided.

prism_infer_batch ~190

Buy many LLM generations from Prism's managed inference endpoint in one paid call. Every prompt runs whole on a rented GPU, spread across every GPU the endpoint holds, so a list of prompts finishes far sooner than the same prompts sent one at a time. Costs the single-generation price times the number of prompts. Returns every answer in order plus a Merkle receipt naming the leases that did the work. Use it for evals, dataset passes, rollouts, or anything with more than a handful of independent prompts.

NameTypeReqDescription
max_usdgnumber–Refuse if the quoted total exceeds this (default 0.5). The operator's PRISM_MAX_USDG binds it either way.
modelstring–Model to use; defaults to the endpoint's first offered model.
promptsarrayyesIndependent prompts, answered in the order given (each max 32 KiB).

No output schema declared.

No examples provided.

prism_lease ~214

Lease a GPU and keep it running. Returns a lease_id and SSH access. Use prism_run to execute commands and prism_end_lease when done.

NameTypeReqDescription
decisionobject–Why this lease is being funded. Required when the operator set a spend policy (see prism_budget), and the lease is refused before anything is quoted if the decision does not meet it. Only a hash of i…
duration_secondsinteger–Lease length in seconds (default 900, max 21600).
max_usdgnumber–Cost ceiling for this lease in USDG. It lowers the operator's PRISM_MAX_USDG and cannot raise it; omitted, that ceiling applies. See prism_budget.
min_trust_classstring–Refuse suppliers below this trust class (default 'open'). Raise it for anything the host operator must not read.
min_vram_mibinteger–Minimum GPU memory in MiB (default 16000).

No output schema declared.

No examples provided.

prism_lease_and_run ~260

Lease a GPU, run one shell command on it, and return the output. The lease stays alive (use prism_run for more commands, prism_end_lease to release). Prefer this for a single command; use prism_lease when you'll run several.

NameTypeReqDescription
commandstringyesShell command to run on the GPU (e.g. 'nvidia-smi').
decisionobject–Why this lease is being funded. Required when the operator set a spend policy (see prism_budget), and the lease is refused before anything is quoted if the decision does not meet it. Only a hash of i…
duration_secondsinteger–Lease length in seconds (default 900, max 21600).
max_usdgnumber–Cost ceiling for this lease in USDG. It lowers the operator's PRISM_MAX_USDG and cannot raise it; omitted, that ceiling applies. See prism_budget.
min_trust_classstring–Refuse suppliers below this trust class (default 'open'). Raise it for anything the host operator must not read.
min_vram_mibinteger–Minimum GPU memory in MiB (default 16000).

No output schema declared.

No examples provided.

prism_leases ~22

List this wallet's leases on Prism Network with their current state.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

prism_list_gpus ~116

List GPUs currently available to lease on Prism Network, with model, VRAM, price per second in USDG, and trust class. Trust class runs open < isolated < attested < confidential; on an 'open' supplier the host operator can read anything the workload touches. Keep secrets and credentials in prism_vault_store rather than on the box, and raise min_trust when the workload itself must not be readable.

NameTypeReqDescription
min_truststring–Only list suppliers at or above this trust class (default 'open').

No output schema declared.

No examples provided.

prism_price_index ~50

Current GPU pricing on Prism Network by model: sourced low/median/high and settled mean, in USDG per hour. Needs no wallet. Use it to estimate what an analysis job will cost before leasing.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

prism_receipts ~72

Recent settled lease receipts from the public proof feed: GPU model, runtime, what was charged and refunded, and the settlement transaction hash on Robinhood Chain. Needs no wallet. Every Prism lease ends in one of these.

NameTypeReqDescription
limitinteger–Max receipts to return (default 10, max 50).

No output schema declared.

No examples provided.

prism_run ~66

Run a shell command on a GPU you already leased with prism_lease.

NameTypeReqDescription
commandstringyesShell command to run.
lease_idintegeryesThe lease_id returned by prism_lease.
timeout_secondsinteger–Max seconds to wait (default 120).

No output schema declared.

No examples provided.

prism_vault_delete ~36

Permanently delete a vault item. The ciphertext is removed and the value cannot be recovered.

NameTypeReqDescription
item_idstringyes–

No output schema declared.

No examples provided.

prism_vault_list ~39

List the agent's sealed vault items: item_id, label, version and trust floor. Values are not returned and are not readable by Prism.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

prism_vault_read ~71

Decrypt and return one vault item, in this process, using the wallet-derived key. The plaintext exists only here; do not echo it into a leased workspace, a log, or a message.

NameTypeReqDescription
item_idstringyesThe item_id from prism_vault_store or prism_vault_list.

No output schema declared.

No examples provided.

prism_vault_release ~88

Authorize a vault item into a lease you hold and return its plaintext for use there. Refused when the lease's trust class is below the item's trust floor, which is what stops a secret reaching a host that can read it. Every allowed release is recorded against the account.

NameTypeReqDescription
item_idstringyes–
lease_idintegeryesA lease from prism_lease.

No output schema declared.

No examples provided.

prism_vault_store ~185

Store private data (a card, an identity document, an API credential) encrypted under a key derived from this agent's wallet on this machine. Prism receives ciphertext only and cannot read it. Use this instead of writing a secret into a workspace or a file. Returns an item_id; the value is not recoverable without the wallet.

NameTypeReqDescription
labelstring–Optional plain-text name so the item is findable. Stored unencrypted, so keep it non-revealing (e.g. 'billing card', not the number).
trust_floorstring–The weakest workspace this item may ever be released into. Defaults to 'confidential', which is above anything the network serves today, so the item cannot reach a rented GPU at all. Only lower it de…
valuestringyesThe data to seal. Encrypted before it leaves this process.

No output schema declared.

No examples provided.

prism_verify_attestation ~144

Check a confidential generation against its signed receipt and the hardware behind it: the TDX quote verifies to Intel's root and commits to the key set that signed the receipt, the boot log replays to the measurement in that quote, the receipt covers the exact bytes of this call, the upstream that ran the model was itself verified, and the GPU is attested by NVIDIA. Returns every check with its result, including the ones that cannot be established today. Needs no wallet.

NameTypeReqDescription
modelstring–Model to fetch GPU evidence for; defaults to the one recorded for this receipt.
receipt_idstringyesThe receipt_id from prism_confidential_infer.

No output schema declared.

No examples provided.

prism_wallet ~42

Show the agent's wallet address and on-chain balances (USDG and ETH for gas) on Robinhood Chain. Check this before leasing to confirm the wallet can pay.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

Common questions

What is the io.github.prismnetwork-tech/mcp server?

io.github.prismnetwork-tech/mcp is listed in the public MCP registry as io.github.prismnetwork-tech/mcp. Rent real NVIDIA GPUs from your agent. Browse with no wallet; pay per second onchain. This page covers its npm package (@prismnetwork/mcp).

Is the io.github.prismnetwork-tech/mcp server safe to use?

io.github.prismnetwork-tech/mcp scores 85 out of 100 on VerifyMCP. We recorded 1 known advisory against it as of 29 September 2026. It declares no install or post-install scripts. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the io.github.prismnetwork-tech/mcp server expose?

io.github.prismnetwork-tech/mcp exposes 21 tools: prism_budget, prism_wallet, prism_list_gpus, prism_price_index, prism_receipts, and 16 more. Their descriptions and schemas cost roughly 2,415 tokens of context every time the server is loaded.

Is the io.github.prismnetwork-tech/mcp server still maintained?

io.github.prismnetwork-tech/mcp is still listed as active in the MCP registry. We last reached this channel on 29 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

What licence is the io.github.prismnetwork-tech/mcp server under?

io.github.prismnetwork-tech/mcp declares the Apache-2.0 licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.