cli-anything-sbox

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructions specify the installation of the cli-anything-sbox harness via pip from the vendor's repository at github.com/HKUDS/CLI-Anything.git.- [DYNAMIC_EXECUTION]: The codegen command group allows the agent to generate and write C# code (.cs), Razor components (.razor), and stylesheets (.razor.scss) directly into the project directory for later compilation and execution within the game engine.- [INDIRECT_PROMPT_INJECTION]: The skill exhibits a surface for indirect instructions through project file processing.- Ingestion points: The skill reads project-defined configuration and asset data from .scene, .prefab, .vmat, .sound, and .json files via subcommands in the scene, prefab, material, sound, and asset groups.- Boundary markers: No specific delimiters or instructions to treat data as untrusted are provided when the agent processes the output of these commands.- Capability inventory: The skill allows for writing new C# files (codegen), modifying existing scene/asset JSON files (scene, prefab, material, etc.), moving or renaming assets (asset), and launching the editor or server (launch, server).- Sanitization: The documentation does not describe any sanitization of the content extracted from project files before it is returned to the agent context.- [COMMAND_EXECUTION]: The skill executes various CLI subcommands to interact with the local filesystem and the s&box game engine environment, facilitating project management and asset manipulation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 05:21 PM
Security Audit — agent-trust-hub — cli-anything-sbox