unity-review-quality

Pass

Audited by Gen Agent Trust Hub on Jul 1, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill is strictly designed for project analysis and reporting. It contains explicit 'Absolute Rules' that prevent the modification, creation, or deletion of any project files, ensuring the tool remains read-only during its operation.
  • [EXTERNAL_DOWNLOADS]: The skill's installation metadata references downloading its own instruction files from a public GitHub repository (github.com/cuozg/oh-my-unity). This is documented neutrally as a standard installation pattern.
  • [PROMPT_INJECTION]: The skill processes untrusted codebase content to perform its analysis, representing a functional surface for indirect prompt injection. This is evaluated as safe given the tool's intended primary purpose and read-only constraints.
  • Ingestion points: Local Unity project files (scripts, assets, and configuration) at the user-specified path.
  • Boundary markers: No specific delimiters are defined to separate code content from agent instructions.
  • Capability inventory: The agent reads local project files and generates a comprehensive HTML report document.
  • Sanitization: No sanitization of the analyzed project content is specified.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 1, 2026, 01:41 AM
Security Audit — agent-trust-hub — unity-review-quality