SkillAgentSearch skills...

PrismRefraction

The governance-native Agent OS. Cryptographically sealed 10-Law security, tri-model cognitive orchestration, and secure full-stack computer use with immutable CAC accountability.

Install / Use

claude mcp add kirklasalle -- npx -y github:kirklasalle/PrismRefraction

If the server publishes to npm under a different name, use that package instead — check the repo README.

About this skill
🔌

MCP Server

Model Context Protocol server

Quality Score

83/100

Category

Security

Supported Platforms

Claude Code
Claude Desktop

Our assessment of PrismRefraction

PrismRefraction scores 83/100 on our quality scale, 784th of 1,088 Security skills we index.

Its MCP Server is 32 KB long, well organised into 38 sections with 8 code examples: a thorough specification that gives an agent plenty to work with.

It has 3 GitHub stars, so there is little community track record yet; judge it on its content.

Substance
30/30
Structure
20/20
Description
15/15
Adoption
3/20
Freshness
15/15

Maintenance, license and trust

  • The repository was last updated 33 days ago, so PrismRefraction is actively maintained.
  • Our last check on 2026-09-12 found the source still online.
  • It is released under the Apache-2.0 license, a permissive license that allows use, modification and commercial use with attribution.
  • Its trust signals score 92/100, with 1 caution from licensing, adoption, age or documentation. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.

Safety scan

No issues found

Our scan of the first 100 KB of the file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands.

Automated pattern scan on 2026-10-03. It catches known dangerous patterns, not every risk — read a skill before letting an agent act on it.

PrismRefraction compared with similar skills

All 4 of these similar skills score higher than PrismRefraction; compare them before choosing.

SkillScoreStarsUpdatedFormat
PrismRefraction (this skill)by kirklasalle83333d agoMCP Server
Agent-Reachby Panniantong10088.6k17d agoCLAUDE.md
headroomby headroomlabs-ai10074.3ktodayCLAUDE.md
rufloby ruvnet10073.7ktodayCLAUDE.md
CowAgentby zhayujie10047.2ktodayCLAUDE.md

Frequently asked questions

How do I install PrismRefraction?
Run claude mcp add kirklasalle -- npx -y github:kirklasalle/PrismRefraction. The install tabs above show the steps for each supported agent.
Which AI agents does PrismRefraction work with?
It is written for Claude Code and Claude Desktop, as a MCP Server file. Other agents that read the same format can often use it too.
Is PrismRefraction safe to use?
Our scan of the first 100 KB of the file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. It is Apache-2.0-licensed and scores 92/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
Is PrismRefraction still maintained?
The repository was last updated 33 days ago, so PrismRefraction is actively maintained.
<p align="center"> <img src="https://img.shields.io/badge/version-0.23.0-06b6d4?style=for-the-badge&labelColor=0a0a0f" alt="Version" /> <img src="https://img.shields.io/badge/license-Apache_2.0-6366f1?style=for-the-badge&labelColor=0a0a0f" alt="License" /> <img src="https://img.shields.io/badge/node-%3E%3D22-22c55e?style=for-the-badge&labelColor=0a0a0f" alt="Node.js" /> <img src="https://img.shields.io/badge/tests-217_discovered_suites_passing-22c55e?style=for-the-badge&labelColor=0a0a0f" alt="Tests" /> <img src="https://img.shields.io/badge/CI-7_workflows-f59e0b?style=for-the-badge&labelColor=0a0a0f" alt="CI" /> </p> <p align="center"> <a href="https://youtu.be/Q16a-NMSoeI?si=ijSiqTazwBqKnYKY"> <img src="https://img.youtube.com/vi/Q16a-NMSoeI/maxresdefault.jpg" alt="Watch the video" width="70%" style="border-radius: 8px; box-shadow: 0 4px 8px rgba(0,0,0,0.2);" /> </a> </p>

PRISM — Governance-Native Agents-as-a-Service Runtime

The first open-source agent platform with cryptographically enforced governance, tri-model cognitive orchestration, and full computer-use autonomy — designed for operators who refuse to choose between power and accountability.

PRISM is not another chatbot wrapper. It is a production-grade autonomous agent operating system that orchestrates LLM reasoning, browser automation, terminal virtualization, container sandboxing, and multi-agent swarms — all governed by an immutable policy engine with cryptographic integrity verification at boot and runtime.

Where other platforms bolt on safety as an afterthought, PRISM makes governance load-bearing architecture: every tool invocation, every agent decision, every autonomous action passes through a 3-tier policy engine before execution. High-risk operations require explicit human approval. Denials and timeouts are first-class tested behaviors. The operator is always supreme.

"PRISM doesn't just run agents — it runs them with honor."


Why PRISM

The Problem

Every agentic framework today asks you to make the same trade-off: power or safety, autonomy or control, speed or transparency. The result is platforms that are either too constrained to be useful or too unconstrained to be trusted.

The PRISM Difference

PRISM eliminates that trade-off entirely through governance-native architecture — safety isn't a guardrail bolted onto the side; it's the foundation everything else is built on.

| Capability | Other Frameworks | PRISM | | :------------------ | :--------------------------------------- | :------------------------------------------------------------------------------------ | | Governance | Prompt-level guardrails, easily bypassed | Cryptographically enforced 10 Laws (SHA-256 integrity, CI-gated) | | Policy Engine | Basic allow/deny lists | 3-tier authority model with approval queues, timeouts, and denial paths | | Multi-Model | Single model per request | Spectrum Refraction: tri-model parallel fan-out with structured aggregation | | Computer Use | Browser-only or terminal-only | Full-stack: browser + terminal + container sandbox, all policy-governed | | Agent Lifecycle | Stateless tool calls | Managed lifecycles (ephemeral → semi-permanent → permanent) with swarm coordination | | Identity | API key auth | IAM with RBAC, SSO (OIDC/SAML), SCIM provisioning, character accountability chains | | Observability | Basic logging | SHA-256 hashed activity events, LLRE cognitive economics, retrieval quality telemetry | | Self-Hosting | Cloud-only or limited local | Fully self-hostable, runs on consumer hardware, your data never leaves your machine |


✦ Architecture at a Glance

┌──────────────────────────────────────────────────────────────┐
│                    OPERATOR DASHBOARD                        │
│  Chat │ Agents │ Browser │ Computer │ Network │ Telemetry    │
└──────────────────────────┬───────────────────────────────────┘
                           │
┌──────────────────────────▼───────────────────────────────────┐
│               GOVERNANCE PLANE                               │
│  ┌─────────┐  ┌──────────────┐  ┌──────────────────────┐    │
│  │ 10 Laws │  │ 3-Tier Policy│  │ Approval Queue       │    │
│  │ (PAD)   │──│ Engine       │──│ (tier2/tier3 gates)  │    │
│  │ SHA-256 │  │ auto│cond│apv│  │ approve/deny/timeout │    │
│  └─────────┘  └──────────────┘  └──────────────────────┘    │
└──────────────────────────┬───────────────────────────────────┘
                           │
┌──────────────────────────▼───────────────────────────────────┐
│              COGNITIVE RUNTIME                               │
│  ┌──────────┐ ┌──────────────┐ ┌─────────────────────┐      │
│  │ Spectrum │ │ Agent Pool   │ │ Skills Engine        │      │
│  │Refraction│ │ + Swarm Coord│ │ (Browser Researcher, │      │
│  │ (SR)     │ │ + Task Decomp│ │  Terminal, Calendar, │      │
│  │ 3-model  │ │ 4 topologies │ │  Email, Media, etc.) │      │
│  └──────────┘ └──────────────┘ └─────────────────────┘      │
│  ┌──────────┐ ┌──────────────┐ ┌─────────────────────┐      │
│  │ LLRE     │ │ Causal Memory│ │ Guardian Agent       │      │
│  │ Cognitive│ │ Fabric       │ │ (local llama.cpp,    │      │
│  │Economics │ │ (episodic +  │ │  autonomous health   │      │
│  │ TEQ/RSI  │ │  session +   │ │  monitor + PAD       │      │
│  │ CSR/TCA  │ │  semantic)   │ │  integrity checker)  │      │
│  └──────────┘ └──────────────┘ └─────────────────────┘      │
└──────────────────────────┬───────────────────────────────────┘
                           │
┌──────────────────────────▼───────────────────────────────────┐
│           TOOL ADAPTERS (Agent-Computer Interface)            │
│  System │ Protocol │ Application │ Network │ Cognition       │
│  Shell    HTTP       Browser       50+ cmds   SR Tool        │
│  FS       A2A        Terminal PTY  ipconfig    Autonomous     │
│  Docker              Container     ping        Planner        │
│  Images              Email/OAuth   tracert                    │
│  Audio               Calendar      netstat                    │
│  Video               Tasks/Notes   nslookup                   │
│  Screen              Media Gen                                │
└──────────────────────────────────────────────────────────────┘

✦ Novel Engineering

1. Permanent Active Directives (PAD) — Cryptographic Governance

PRISM's governance isn't configurable — it's constitutional. The 10 Laws (authored by Kirk LaSalle, rooted in Asimov's Three Laws and extended to cover privacy, equity, transparency, and operational boundaries) are cryptographically sealed:

  • SHA-256 integrity verification at every boot and every 10 minutes by the Guardian Agent
  • CI Gate blocks any merge/release where directives are modified without updating the integrity constant
  • Machine-readable law manifest maps each directive to its runtime enforcement mechanism
  • Governance preamble injection into all Tier 2+ LLM system prompts — every model interaction operates within the 10 Laws
  • Amendment requires Governance Council approval + cryptographic re-signing

No other agent platform enforces governance at the cryptographic level.

2. Spectrum Refraction (SR) — Tri-Model Cognitive Orchestration

PRISM's novel compounding parallel fan-out architecture simultaneously engages three model instances:

| Hemisphere | Role | Example | | :--------------------- | :---------------------------------------- | :---------- | | Left (Logic) | Analytical reasoning, structured analysis | Claude Opus | | Right (Creative) | Creative generation, lateral thinking | GPT-5 | | Main (Coordinator) | Synthesis, arbitration, final response | Gemini Pro |

  • Mandatory instance isolation: Left ≠ Right enforced at configuration, activation, and runtime gates
  • Structured XML-tagged aggregation fuses analytical rigor with creative breadth
  • Three isolation quality levels: full (different providers), model (same provider, different models), insufficient (rejected)
  • Media artifact extraction from Creative hemisphere responses

No competing framework offers native multi-model simultaneous fan-out with structured aggregation and isolation enforcement.

3. LLRE Cognitive Economics Engine

The Low-Level Reasoning Engine provides unprecedented visibility into how efficiently your agents think:

  • Token Efficacy Quotient (TEQ) — Are tokens being used effectively?
  • Request Satisfaction Index (RSI) — Are user requests being fulfilled?
  • Context Saturation Ratio (CSR) — Is context window capacity being optimized?
  • Tool Call Accuracy (TCA) — Are tool invocations precise and successful?
  • Prompt AST Compiler with <objective> and <constraints> tag parsing and signal density checks
  • SQLite persistence with interactive performance rings in the operator console

4. Full Computer Use — Browser, Terminal, Container

PRISM treats computer use as a first-class governed capability, not an auxiliary feature:

  • Browser Automation — Playwright-powered headless and headed browser control with screenshot capture, page navigation, element interaction, and multi-tab management
  • Terminal Virtualization — Real PTY sessions via node-pty with full shell access, command risk classification, and destructive-command deny lists
  • Container Sandboxing — Docker container orchestration for isolated execution environments with resource limits and lifecycle management
  • Autonomous Research — Browser Researcher skill that autonomously navigates, searches, extracts, and synthesizes information from the web
  • All pathways governed by the 3-tier policy engine with approval gates for high-risk operations

5. Multi-Agent Swarm Orchestration

  • Agent lifecycles: ephemeral (per-task), semi-permanent (idle-reaped), permanent (manual stop)
  • Per-agent model assignment: dynamic provider/model override per agent, hot-swappable at runtime
  • Four swarm topologies: mesh, star, pipeline, broadcast
  • Task decomposition with dependency-aware parallel batch execution
  • Intelligent telemetry: pattern detection, role hotspot analysis, lifecycle promotion recommendations
  • CAC Main Agent: each operator's certificate-bound primary assistant, agent, and interaction identity; one CAC Main Agent per operator per Initialization Certificate, reused across sessions
  • Guardian Agent: permanent secondary system agent powered by local llama.cpp inference; supports the CAC Main Agent and monitors, protects, and heals the complete dashboard and all platform services

6. Advanced Model Routing

  • Fully Configurable & AI-Assisted: Complete operator control over routing topologies with AI assistance to dynamically determine the optimal model assignments based on task parameters.
  • Role-Based Overrides: Map specific models or providers to individual task roles (e.g., chat, code-generation, summarization, memory indexing, or research) with automatic validation.
  • Power-Aware Strategies: Supports routing strategies based on target profiles: eco (prioritizes local models to eliminate API charges), performance (highest available capability tier), and adaptive (balances VRAM and API costs dynamically).

7. Advanced Model Matrix (Exclusive Platform Core)

  • Operator-Exclusive Registry: A dynamically updated, proprietary database of providers, models, use cases, capabilities, and attributes.
  • Local Model Auto-Discovery: Aut

Truncated for display — read the full file on GitHub.

Related Skills

View on GitHub
GitHub Stars3
CategorySecurity
Updated1mo ago
Forks0

Languages

TypeScript

Trust signals

92/100

From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.

1 low