Installation
September 2, 2026 · View on GitHub
Full detail behind the three methods in the README Quick Start, plus the less-common paths.
| Platform | Install | Notes | |
|---|---|---|---|
| macOS | curl, pip, clone | everything supported | |
| Linux | curl, pip, clone | everything supported | |
| Windows | pip | hooks, policy and audit trail; see below |
Curl
curl -sSL https://prismor.dev/install | sh
Detects your environment and uses the right install method automatically.
Skill (zero-interrupt setup)
Point your agent at SKILL.md. It is a standing instruction file: the agent reads it at session start, checks whether Prismor is installed, and follows the decision tree throughout the session without pausing your workflow.
For Claude Code, add to your CLAUDE.md:
Read `SKILL.md` and follow its instructions for runtime security.
Or via raw URL (works in any agent config file: CLAUDE.md, AGENTS.md, .cursorrules, .windsurfrules):
Read `https://raw.githubusercontent.com/PrismorSec/prismor/main/SKILL.md` and follow its instructions.
See SKILL.md for the full decision tree and hard rules.
Pip
pip install prismor
prismor setup # interactive onboarding wizard
prismor setup lets you pick enforcement mode, choose which rules block (enforce mode starts with nothing selected and the safety floor marked recommended), select agents, optionally enable secret cloaking, and optionally set an unlock password for the agent self-edit window. Pass --non-interactive to skip the TUI (--recommended or --enforce-rules id1,id2 picks the blocking set). See Choosing what blocks.
Git clone + wizard
pip3 install pyyaml # on Debian/Ubuntu use: sudo apt install python3-yaml
git clone https://github.com/PrismorSec/prismor.git ~/.prismor
PRISMOR_MODE=enforce PRISMOR_CLOAK=1 bash ~/.prismor/scripts/init.sh .
If you are testing from a source checkout on a machine that already has a
different prismor install, use the repo shim for health checks:
python3 ~/.prismor/bin/prismor --version
python3 ~/.prismor/bin/prismor status
That path forces imports to resolve to the checked-out runtime instead of a
stale package earlier on sys.path.
On externally-managed Pythons (PEP 668 — Ubuntu 23.04+, Homebrew)
pip3 installrefuses to run; install PyYAML from your system package manager instead (sudo apt install python3-yaml,brew install pyyaml, …).init.shwill tell you if it's missing.
This installs enforce-mode Prismor hooks and the Cloak prevention layer. To register a secret, run prismor cloak add stripe_key and enter the value when prompted. To import an entire dotenv file at once, run prismor cloak add --env-file .env. Claude/Hermes can auto-decloak placeholders at the tool boundary. Codex hooks are block-only, so run placeholder commands through prismor cloak run -- <command>.
Prefer the interactive wizard? Drop the env vars:
bash ~/.prismor/scripts/init.sh .
Windows
Install with pip and run the wizard — the curl installer and
init.sh are
shell scripts and are not the path here:
pip install prismor
prismor setup
CI runs prismor setup on windows-latest, and the enforcement path is
verified end to end on Windows Server 2022 with Claude Code: setup exits 0, the
hook fires in a real session, a floor rule blocks, and the audit trail is
written and signed.
What is different under the hood:
- Hooks run through a shim. Agent configs store a hook as a shell string,
and the shell on Windows is
cmd.exe, which has noVAR=value cmdsyntax.prismor setupwriteshook-dispatch.pyinto$PRISMOR_HOMEand registers"<python>" "<shim>" hook-dispatch ...— the one command shapeshandcmd.exeboth accept. The shim does thesys.pathfix-up the oldPYTHONPATHprefix did, so hooks survive a launcher that strips user site-packages. If you edit hooks by hand, keep that shape: a broken hook fails open (agents treat hook failure as non-blocking), which reads as "installed" while screening nothing. - Threat-feed signatures need the
cryptographyextra. There is noopensslto shell out to, so installpip install "prismor[signing]"— the same extra that signs the audit trail. Without it, setup reports the verification as skipped rather than failed.
Not yet on Windows:
- Cloak — its hooks are bash scripts registered by
path, so
cmd.execannot run them. Use it from WSL or Git Bash.