unity-rendering-weapon

Pass

Audited by Gen Agent Trust Hub on Jul 25, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill functions as a static analysis and guidance tool for Unity URP setup. Evaluation of its instructions and guides shows no evidence of malicious patterns, such as data exfiltration, command execution, or obfuscation. Its operations are restricted to reading project configuration and generating markdown reports.\n- [PROMPT_INJECTION]: The skill has a surface for indirect prompt injection as it processes local project files (manifests and C# source code). Mandatory Evidence Chain: 1. Ingestion points: Reads Packages/manifest.json and script files like GrayBoxVisuals.cs. 2. Boundary markers: No explicit delimiters or ignore-instructions are used when processing these files. 3. Capability inventory: The skill is restricted to writing markdown reports; it has no access to shell commands, network requests, or dynamic code evaluation. 4. Sanitization: No sanitization of ingested content is performed. Given the limited capabilities, the risk of instruction override leading to harm is minimal.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 25, 2026, 03:23 AM
Security Audit — agent-trust-hub — unity-rendering-weapon