unity-mcp-weapon

Pass

Audited by Gen Agent Trust Hub on Jul 25, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides detailed guides and examples for executing commands within the Unity Editor using tools such as Unity_ManageScene and Unity_ManageGameObject via the Model Context Protocol. It also references the use of custom Unity menu commands like Drift → Setup Tier 0 Gray Box for deterministic scene assembly.
  • [EXTERNAL_DOWNLOADS]: Documents dependencies on Unity packages including the official com.unity.ai.assistant and the community-supported com.coplaydev.unity-mcp. These are standard components within the Unity development ecosystem. The skill also mentions an example HTTP MCP server https://n8n.voyze.ai/mcp-server/http in a configuration template, which is identified as an unrelated external resource.
  • [PROMPT_INJECTION]: Identifies a potential attack surface where the agent reads Unity console logs via the Unity_ReadConsole tool (referenced in guides/03-driving-the-editor.md). While the skill does not contain malicious instructions, it lacks explicit boundary markers for data ingested from the console. Ingestion point: Unity_ReadConsole. Boundary markers: Absent. Capability inventory: Unity_ManageScene, Unity_ManageGameObject, and custom menu command execution. Sanitization: No specific sanitization or filtering of console output is documented.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 25, 2026, 03:23 AM
Security Audit — agent-trust-hub — unity-mcp-weapon