jahro-migration

Pass

Audited by Gen Agent Trust Hub on Mar 19, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is entirely composed of documentation and code transformation examples. It does not contain executable scripts, network operations, or sensitive data access.
  • [DATA_EXPOSURE]: No hardcoded credentials, API keys, or sensitive file paths were detected. The C# code snippets provided are generic templates for Unity development.
  • [REMOTE_CODE_EXECUTION]: The skill does not include any commands for downloading or executing external scripts. All code references are intended for the user to implement within their own Unity project.
  • [PROMPT_INJECTION]: There are no instructions designed to bypass safety filters, reveal system prompts, or override the agent's core instructions.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze user-provided source code (the ingestion point). While this constitutes an attack surface, the instructions focus on structural refactoring (e.g., mapping OnGUI buttons to [JahroCommand] attributes) and do not provide a mechanism for malicious instructions within that data to escalate privileges or exfiltrate data. No boundary markers or sanitization steps are explicitly defined in the prompt instructions, but the capability is limited to text generation for migration plans.
  • [COMMAND_EXECUTION]: No shell commands or subprocess calls are present in the skill instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 19, 2026, 09:26 PM
Security Audit — agent-trust-hub — jahro-migration