test-engineer
Pass
Audited by Gen Agent Trust Hub on Jul 5, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill serves as a static reviewer for local Unity test reports generated by companion tools.
- [PROMPT_INJECTION]: Instructions define a specific persona and task boundaries without attempting to bypass safety protocols or override system instructions.
- [DATA_EXFILTRATION]: No sensitive file paths (e.g., credentials, SSH keys) are accessed. File access is restricted to generated reports in the
<project>/.unity-review/directory, and no network exfiltration patterns are present. - [REMOTE_CODE_EXECUTION]: The instructions explicitly state that the agent should not run tests or external tools, limiting behavior to observation and commentary.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from local report files. However, the risk is negligible as the agent has no write permissions, network access, or command execution capabilities that could be exploited by malicious content within those files.
Audit Metadata