lighting-design
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill provides legitimate technical documentation and patterns for game lighting across multiple engines (Unity, Unreal, Godot, Three.js). No malicious payloads or harmful instructions were found.
- [DATA_EXFILTRATION]: The skill does not perform network operations, harvest credentials, or access sensitive system files (e.g., .ssh, .env).
- [INDIRECT_PROMPT_INJECTION]: The skill includes an ingestion surface by analyzing external engine configuration files. The risk is minimized by the lack of sensitive execution capabilities and the use of specific regex-based validation logic.
- Ingestion points: Processes files with extensions such as .unity, .uasset, and .tscn via logic defined in references/validations.md.
- Boundary markers: Skill instructions explicitly require the agent to ground all responses in the provided reference materials and correct users based on that data.
- Capability inventory: No subprocess execution, network access, or file-system write permissions are requested or used across any skill files.
- Sanitization: Input is validated against narrow regex patterns targeting lighting-specific parameters (e.g., intensity, shadow bias, lightmap resolution).
Audit Metadata