unity-engineer

Warn

Audited by Gen Agent Trust Hub on Apr 3, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill employs dynamic context injection (using the !command syntax) to execute shell commands at load time. Specifically, it uses cat to read shared protocol files and local project configuration files like .production-grade.yaml and .forgewright/settings.md. While the commands themselves are benign utility calls, they represent an active use of dynamic shell execution at startup to modify the agent's context.
  • [PROMPT_INJECTION]: An indirect prompt injection surface exists because the skill reads external data from the local filesystem, including codebase context and configuration files, and uses that data to guide its actions. 1. Ingestion points: .production-grade.yaml, .forgewright/codebase-context.md, .forgewright/settings.md. 2. Boundary markers: Absent. 3. Capability inventory: Extensive file system writes (creating Unity C# scripts and project structures). 4. Sanitization: No explicit sanitization or validation logic is defined for the content of the configuration files before they are incorporated into the agent's context.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 3, 2026, 03:48 PM
Security Audit — agent-trust-hub — unity-engineer