unity-cli

Warn

Audited by Socket on Aug 4, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The overall purpose is coherent for a Unity automation skill, and the localhost API use matches Unity's experimental Pipeline feature. However, install trust is weaker than claimed: the main setup path relies on an unprovided local script, the Docker image is community-run rather than Unity-owned, and the auth guidance uses plaintext credentials in env vars instead of the current official flow. This looks more like a risky or outdated automation guide than confirmed malware.

Confidence: 88%Severity: 72%
SecurityMEDIUM
scripts/setup.sh

This module is primarily an installation/validation wrapper for Unity CLI. It shows no explicit credential theft or covert behavior in the visible code, but it performs high-sensitivity supply-chain actions by downloading and executing remote installer scripts directly (curl|bash and irm|iex) without visible integrity verification. Treat integration into CI/pipelines as high-risk unless the downstream installer scripts are verified via pinned hashes/signatures and the download is constrained/validated.

Confidence: 70%Severity: 72%
Audit Metadata
Analyzed At
Aug 4, 2026, 05:39 AM
Package URL
pkg:socket/skills-sh/akillness%2Fjeo-skills%2Funity-cli%2F@9f744e08573aa625fb1013eac33bfeb007bb348e9900471878584f3092e5b14b
Security Audit — socket — unity-cli