gamedev-shipping
Pass
Audited by Gen Agent Trust Hub on Aug 6, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill includes numerous shell command examples for game building and signing, such as Godot headless exports, Unity batch mode builds, and standard platform utilities like
codesign,notarytool,keytool, andsigntool. These commands are standard for game distribution workflows and are used as intended for legitimate software packaging. - [EXTERNAL_DOWNLOADS]: Reference is made to established community-maintained CI/CD tools in GitHub Actions examples, including the
game-ci/unity-builderaction and thebarichello/godot-ciDocker image. These are well-known resources in the game development ecosystem. - [SAFE]: The skill explicitly promotes security best practices, specifically advising users to manage signing certificates, keystores, and API keys through environment variables and encrypted secrets rather than hardcoding them or committing them to version control. No malicious patterns such as prompt injection, data exfiltration, or obfuscation were identified.
Audit Metadata