gamedev-shipping

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes numerous shell command examples for game building and signing, such as Godot headless exports, Unity batch mode builds, and standard platform utilities like codesign, notarytool, keytool, and signtool. These commands are standard for game distribution workflows and are used as intended for legitimate software packaging.
  • [EXTERNAL_DOWNLOADS]: Reference is made to established community-maintained CI/CD tools in GitHub Actions examples, including the game-ci/unity-builder action and the barichello/godot-ci Docker image. These are well-known resources in the game development ecosystem.
  • [SAFE]: The skill explicitly promotes security best practices, specifically advising users to manage signing certificates, keystores, and API keys through environment variables and encrypted secrets rather than hardcoding them or committing them to version control. No malicious patterns such as prompt injection, data exfiltration, or obfuscation were identified.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 09:37 PM
Security Audit — agent-trust-hub — gamedev-shipping