unity-shader-artist

Pass

Audited by Gen Agent Trust Hub on Jul 22, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the dynamic context injection syntax (!command) in SKILL.md to load shared protocols and configuration files, such as skills/_shared/game-visual-foundations.md and .production-grade.yaml, using the cat command. These operations are used for environment grounding and do not involve sensitive data access or network communication.
  • [COMMAND_EXECUTION]: The LITE.md file contains instructions for the agent to execute shell commands like grep and find to discover the project's active render pipeline and index shader assets. These are legitimate discovery tools within the context of Unity development.
  • [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection by ingesting data from project-level files like Packages/manifest.json and .production-grade.yaml.
  • Ingestion points: .production-grade.yaml (via SKILL.md) and Packages/manifest.json (via LITE.md).
  • Boundary markers: No specific delimiters or "ignore instructions" warnings are present around these inputs.
  • Capability inventory: The skill uses file reading (cat), file searching (find, grep), and Unity-specific asset modification tools (assets-material-create, object-modify).
  • Sanitization: No escaping or validation of external content was observed.
  • Note: This represents a baseline attack surface for skills interacting with project files, but no exploitable capabilities or malicious intents were identified.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 22, 2026, 08:29 AM
Security Audit — agent-trust-hub — unity-shader-artist