unity-mcp

Warn

Audited by Gen Agent Trust Hub on Jul 22, 2026

Risk Level: MEDIUMDATA_EXFILTRATIONPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill directs the agent to read the user's global MCP configuration file.
  • Evidence: LITE.md instructs the agent to execute cat ~/.cursor/mcp.json.
  • Details: This configuration file is a central repository for MCP integrations and frequently contains sensitive environment variables, authentication tokens, and API keys for third-party services. Accessing the entire file exposes these credentials to the agent context.
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection through the ingestion of untrusted log data.
  • Ingestion points: Uses the console-get-logs tool in SKILL.md to retrieve output from the Unity Editor.
  • Boundary markers: No delimiters or warnings are used to prevent the agent from following instructions embedded in log messages.
  • Capability inventory: The skill can execute high-privilege operations such as assets-delete, gameobject-destroy, and package-add.
  • Sanitization: There is no evidence of filtering or validation for the log content before it is processed by the agent.
  • [COMMAND_EXECUTION]: Employs shell commands to inspect the local environment and network state.
  • Evidence: Uses ss -tlnp to monitor specific network ports (5000 and 3000) and find to locate project-specific configuration files like .asmdef or mcp-manifest.json.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 22, 2026, 08:30 AM
Security Audit — agent-trust-hub — unity-mcp