unity-mcp
Warn
Audited by Gen Agent Trust Hub on Jul 22, 2026
Risk Level: MEDIUMDATA_EXFILTRATIONPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [DATA_EXFILTRATION]: The skill directs the agent to read the user's global MCP configuration file.
- Evidence:
LITE.mdinstructs the agent to executecat ~/.cursor/mcp.json. - Details: This configuration file is a central repository for MCP integrations and frequently contains sensitive environment variables, authentication tokens, and API keys for third-party services. Accessing the entire file exposes these credentials to the agent context.
- [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection through the ingestion of untrusted log data.
- Ingestion points: Uses the
console-get-logstool inSKILL.mdto retrieve output from the Unity Editor. - Boundary markers: No delimiters or warnings are used to prevent the agent from following instructions embedded in log messages.
- Capability inventory: The skill can execute high-privilege operations such as
assets-delete,gameobject-destroy, andpackage-add. - Sanitization: There is no evidence of filtering or validation for the log content before it is processed by the agent.
- [COMMAND_EXECUTION]: Employs shell commands to inspect the local environment and network state.
- Evidence: Uses
ss -tlnpto monitor specific network ports (5000 and 3000) andfindto locate project-specific configuration files like.asmdeformcp-manifest.json.
Audit Metadata