unity-multiplayer
Pass
Audited by Gen Agent Trust Hub on Jul 22, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes dynamic context injection in SKILL.md to execute shell commands at load time via the !cat syntax. These commands are used to read local documentation and configuration files (e.g., skills/_shared/protocols/ux-protocol.md, .production-grade.yaml) to populate the agent's context. This is a legitimate use of the feature for modularity and does not involve untrusted input or data exfiltration.- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it processes data from the Unity environment (e.g., console logs via console-get-logs) and can act upon it using powerful tools like gameobject-create and tests-run.
- Ingestion points: Reads project console logs and package manifests.
- Boundary markers: No explicit delimiters or instructions are provided to the agent to ignore embedded commands in the data it reads.
- Capability inventory: Tools include GameObject creation, component modification, editor state control, and test execution.
- Sanitization: No input validation or sanitization is specified for external data processing.- [COMMAND_EXECUTION]: The LITE.md file contains diagnostic shell commands (e.g., cat Packages/manifest.json, find Assets/) used to verify project dependencies and structure during the environment grounding phase. These are standard and safe development practices.
Audit Metadata